Security Platform Engineer at XPT Software Australia Pty Ltd | AU | Rezi

Security Platform Engineer at XPT Software Australia Pty Ltd

Security Platform Engineer

XPT Software Australia Pty Ltd · AU

6 days ago

Security Platform Engineer

XPT Software Australia Pty Ltd · AU

6 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Security Platform Engineer role.

Rezi rewrites your resume against XPT Software Australia Pty Ltd's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Security Platform Engineer posting at XPT Software Australia Pty Ltd — free, in seconds.

About the Role

We are looking for a hands-on Cyber Security Platform Engineer to help deliver a new security product across the Client environment. Working closely with the architect and product/Vendor SME, the successful candidate will drive the technical implementation, coordinate agent deployments, and manage firewall requirements. This role requires someone who can work effectively with stakeholders across Client, taking the product to BAU.

Responsibilities

  • Design and implement the runZero platform operating model, including environments, access, roles, boundaries, sites, asset groups, tags and naming standards.
  • Configure discovery coverage for corporate, data centre, cloud, remote access, network, IoT and relevant OT environments.
  • Design appropriate active scanning, passive discovery and integration patterns for different network zones and operational risk profiles.
  • Establish safe scanning standards, approval gates, maintenance windows and exception processes for sensitive or fragile environments.
  • Configure asset classification, ownership, business context, criticality and lifecycle attributes.
  • Define standards for handling transient, ephemeral, duplicate, decommissioned and unmanaged assets.
  • Develop reusable configuration patterns and templates that can be applied consistently across sites and environments.
  • Maintain a clear separation between production configuration, testing and experimental changes.
  • Integrate runZero with CMDB, ServiceNow, Tenable, EDR, NAC, DNS/DHCP, cloud platforms, identity systems, SIEM, SOAR and relevant infrastructure tools.
  • Implement API-based ingestion and egress patterns using secure service identities and least-privilege access.
  • Automate asset reconciliation, deduplication, enrichment, ownership mapping and data-quality checks.
  • Ensure downstream systems receive consistent, useful and appropriately scoped data rather than uncontrolled asset or alert noise.
  • Define integration contracts, schemas, field mappings, ownership, error handling, retry behaviour and support expectations.
  • Build mechanisms to detect integration drift, stale credentials, failed synchronisation and unexpected data-volume changes.
  • Automate platform onboarding, configuration validation, scan scheduling, asset tagging, reporting and operational housekeeping.
  • Automate the routing of actionable exposures to the correct security, infrastructure, network, cloud or application owners.
  • Implement event-driven workflows for newly discovered assets, exposed services, control gaps, unauthorised devices and material changes.
  • Design idempotent automation that can be safely re-run without creating duplicate records, tickets or configuration drift.
  • Use APIs, webhooks, scripts and workflow platforms to reduce manual administration and improve response times.
  • Introduce approval controls for high-impact or potentially disruptive actions.
  • Create automated lifecycle handling for assets that are retired, renamed, moved, rebuilt or short-lived.
  • Treat runZero configuration and operational processes as code wherever possible.
  • Establish version control, peer review, automated testing, release controls and rollback procedures for platform changes.
  • Define service-level indicators and objectives for discovery coverage, data freshness, integration health, scan success, alert delivery and remediation workflow reliability.
  • Implement dashboards and alerts that detect platform degradation before it affects consumers.
  • Create operational runbooks for common failures, including collector or explorer issues, scan failures, integration errors, data-quality problems and access failures.
  • Design backup, recovery, disaster-recovery and business-continuity procedures appropriate to the service.
  • Conduct capacity, performance and scale assessments as coverage expands across Client environments.
  • Manage credentials through approved enterprise secrets-management capabilities; do not embed secrets in scripts, repositories or configuration files.
  • Implement role-based access control, privileged-access controls, administrative separation and auditable change history.
  • Support security reviews, architecture reviews, privacy assessments, risk assessments and control assurance activities.
  • Ensure platform data handling, logging, retention, residency and third-party access align with Optus security and regulatory requirements.

Requirements

  • Experience with a comparable product to runZero if direct experience is not available.

Skills

  • runZero experience
  • Cyber Security Platform Engineering
  • Technical implementation
  • Agent deployments
  • Firewall management
  • SSO implementation
  • MFA implementation
  • Platform engineering
  • Configuration
  • Discovery coverage configuration
  • Active scanning
  • Passive discovery
  • Integration patterns
  • Asset classification
  • Automation
  • Workflow engineering
  • API integration
  • ServiceNow integration
  • Tenable integration
  • EDR integration
  • NAC integration
  • DNS/DHCP integration
  • Cloud platform integration
  • Identity system integration
  • SIEM integration
  • SOAR integration
  • Infrastructure tool integration
  • API-based ingestion
  • API-based egress
  • Secure service identities
  • Least-privilege access
  • Asset reconciliation
  • Data deduplication
  • Data enrichment
  • Ownership mapping
  • Data quality checks
  • Integration contracts
  • Schema definition
  • Field mapping
  • Error handling
  • Retry behaviour
  • Integration drift detection
  • Credential management
  • Failed synchronisation detection
  • Unexpected data volume change detection
  • Platform onboarding automation
  • Configuration validation automation
  • Scan scheduling automation
  • Asset tagging automation
  • Reporting automation
  • Operational housekeeping automation
  • Actionable exposure routing automation
  • Event-driven workflows
  • Idempotent automation
  • Webhooks
  • Scripting
  • Workflow platforms
  • Approval controls
  • Automated lifecycle handling
  • Configuration as code
  • Operational processes as code
  • Version control
  • Peer review
  • Automated testing
  • Release controls
  • Rollback procedures
  • Service-level indicators (SLIs)
  • Service-level objectives (SLOs)
  • Dashboards
  • Alerting
  • Operational runbooks
  • Backup procedures
  • Recovery procedures
  • Disaster recovery procedures
  • Business continuity procedures
  • Capacity assessment
  • Performance assessment
  • Scale assessment
  • Secrets management
  • Role-based access control (RBAC)
  • Privileged access controls
  • Administrative separation
  • Auditable change history
  • Security reviews
  • Architecture reviews
  • Privacy assessments
  • Risk assessments
  • Control assurance activities
  • Data handling
  • Logging
  • Data retention
  • Data residency
  • Third-party access management

About the Company

  • runZero product