At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.
We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.
Job DescriptionWe are seeking a Security Analyst for an initial short-term contract engagement running from October through December 2026 with possible extensions in Sydney.
In this specialist technical role, you will be responsible for analyzing raw discovery data across our internet-facing infrastructure to build a validated, risk-actionable External Exposure Baseline. You will bridge technical discovery with risk governance—consolidating complex datasets, establishing asset ownership, prioritizing vulnerabilities, and embedding findings into our ongoing Exposure Management function.
Key Responsibilities
Attack Surface Data Analysis: Analyze large-scale external exposure datasets (IP addresses, domains, subdomains, VPN assets, cloud services, and edge infrastructure) to establish an authoritative external attack surface baseline.
Asset Discovery & Normalization: Consolidate, normalize, and de-duplicate asset discovery data from multiple internal and external discovery engines into a single source of truth.
Inventory Reconciliation & Ownership Mapping: Reconcile discovered external assets against internal registers to identify ownership gaps, rogue non-production environments, and unmanaged services.
Stakeholder Engagement: Collaborate across application, infrastructure, and business teams to validate technical relationships, business criticality, and operational status.
Risk Assessment & Prioritization: Evaluate findings to identify systemic control gaps, orphaned assets, and security risks—prioritizing remediation based on threat posture, business impact, and effort.
Treatment & Remediation Planning: Define clear treatment recommendations, including remediation actions, ownership assignment, risk acceptance, or asset decommissioning.
Documentation & Governance: Maintain audit-ready records of findings, decision rationale, ownership records, and evidence to support handover to ongoing operational teams.
Executive Reporting: Deliver clear reporting and insights on exposure trends, remediation progress, and systemic control issues for senior cybersecurity leadership.
Cyber Security & Exposure Analysis: Proven track record as a Security Analyst focusing on External Attack Surface Management (EASM), threat exposure, or vulnerability risk analysis.
Data Manipulation & Reconciliation: Strong capability to consolidate, query, and de-duplicate large, complex technical datasets from multiple security scanning platforms.
Asset & Risk Governance: Deep understanding of enterprise inventory management, asset discovery lifecycle, and threat modeling frameworks.
Network & Infrastructure Security: Technical knowledge of IP routing, DNS, domain management, SSL/TLS, VPN architectures, and public cloud infrastructure (GCP/AWS/Azure).
Stakeholder Influence: Excellent communication skills to coordinate with technical owners, drive asset attribution, and negotiate remediation actions.
Availability & Location: Sydney-based and available to commence the engagement in October 2026.
Why NCS?
This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own. We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.
Ready to make extraordinary happen?
We'd love to hear from you.
We celebrate diversity and inclusion
We value different perspectives, experiences and strengths our people bring. We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.
Important information
Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.
Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.
Skills Required
- Proven experience as a Security Analyst focused on External Attack Surface Management, threat exposure, or vulnerability risk analysis
- Ability to consolidate, query, and deduplicate large technical datasets from multiple security scanning platforms
- Understanding of enterprise inventory management, asset discovery lifecycle, and threat modeling frameworks
- Technical knowledge of IP routing, DNS, domain management, SSL/TLS, VPN architectures, and public cloud infrastructure
- Excellent communication skills for coordinating with technical owners and negotiating remediation actions
- Sydney-based and available to start in October 2026
- Valid Australian work rights
What We Do
NCS in Australia is reinventing technology services from the inside out. We provide advisory, design, build and managed services to our clients, with unrivalled service, attention and understanding every step of the way. We understand day 1001 is just an important as day 1, and we collaborate with clients, striving to provide adaptive approaches, outcomes and thinking by keeping our eye on tomorrow and the days after tomorrow. Our diverse workforce of around 1,300 people has delivered a wealth of large-scale, mission-critical, and multi-platform outcomes for governments and businesses nationally. We are the Australian arm of the pan-APAC technology leader NCS Group, a subsidiary of Singtel Group. Combining the experience and expertise of its 13,000-strong team across 57 specialisations, NCS provides differentiated and end-to-end technology services to clients with its capabilities in digital, data, cloud and platforms, as well as core offerings in application, infrastructure, engineering and cybersecurity. NCS also believes in building a strong partner ecosystem with leading technology players, research institutions and start-ups to support open innovation and co-creation. For more information about NCS Australia, visit ncs.co/en-au or contact our team today. To learn more about NCS Group, visit ncs.co.









