Senior Vulnerability Management Specialist (Tenable)

Posted 13 Hours Ago
Be an Early Applicant
Sydney, New South Wales, AUS
Hybrid
Senior level
Artificial Intelligence • Cloud • Information Technology • Consulting • Cybersecurity • Big Data Analytics
Extraordinary Together
The Role
Operate and improve Tenable vulnerability management across a large hybrid environment. Manage scanning, asset coverage, data quality, risk prioritization, remediation tracking, zero-day response, exceptions, reporting, compliance evidence, and integrations with ITSM, CMDB, SIEM, and patching tools. Drive remediation across infrastructure, cloud, network, and application teams while automating workflows and coaching analysts.
Summary Generated by Built In
Company Description

At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.

We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.

Job Description

We are looking for a senior vulnerability management specialist to run and uplift vulnerability management operations for one of our major clients, a large Australian enterprise based in Sydney. Tenable is the core platform, and you will own it day to day: scan coverage, data quality, prioritisation, remediation tracking and reporting across a large hybrid estate.

This is a hands-on operational role with real accountability. You will be the Tenable subject matter expert on the engagement, and the person infrastructure teams, service owners and security leadership rely on for a clear view of exposure and what to fix first.

What you'll do

  • Operate and tune the Tenable platform day to day: scan policies and schedules, credentialed and agent-based scanning, scanner and agent health, asset tagging and access controls
  • Own scan coverage and data quality by reconciling Tenable against the CMDB, cloud inventories and endpoint tooling, then closing blind spots and authentication failures
  • Triage and prioritise findings on risk (VPR, CVSS, EPSS, known exploited vulnerabilities, asset criticality and internet exposure) rather than raw severity counts
  • Drive remediation with infrastructure, cloud, network and application teams: raise and track work through the ITSM tool, agree treatment plans, hold owners to SLAs and verify fixes by rescan
  • Lead the response to critical and zero-day vulnerabilities, from rapid exposure assessment and targeted scans through to confirmed closure
  • Manage false positives, exceptions and risk acceptances with proper evidence, approval and expiry
  • Build dashboards and reporting for operational teams and executives covering coverage, SLA performance, ageing and risk trend, including evidence for Essential Eight and audit requirements
  • Automate and integrate using the Tenable API with Python or PowerShell, connecting vulnerability data to ITSM, CMDB, SIEM and patching tools
  • Document runbooks and operating procedures, and coach analysts and support teams so the capability outlasts the contract

Qualifications

  • ​​​​Strong demonstrable experience in cyber security or infrastructure operations, with at least 4 years hands-on in vulnerability management
  • Proven operational experience running Tenable in a large, complex organisation (tens of thousands of assets): Tenable One Vulnerability Management (formerly Tenable.io) and/or Tenable Security Center (formerly Tenable.sc). You have operated the platform day to day, not just consumed its reports
  • Deep working knowledge of Nessus scanners and agents, credentialed scanning, scan policy tuning, asset tagging, VPR, dashboards, and recast and accept rules
  • Exposure to the wider Tenable One platform, such as web application scanning, cloud, identity or attack surface management
  • A track record of driving remediation at scale across multiple technology teams, with measurable reduction in ageing and critical exposure
  • Strong grounding in Windows, Linux, networking and cloud (AWS or Azure), enough to discuss root cause and fixes credibly with engineers
  • Experience integrating vulnerability data with ITSM and CMDB platforms such as ServiceNow, and scripting in Python or PowerShell against APIs
  • Working knowledge of the Essential Eight patching requirements and how to evidence compliance
  • Clear written and verbal communication, with the confidence to brief a CISO and to hold a service owner to a deadline
  • Full Australian work rights, and availability to work on site in Sydney

Nice to have:

  • Experience with ServiceNow Vulnerability Response or similar remediation workflow tooling
  • Experience with other vulnerability management platforms such as Qualys, Rapid7 or Microsoft Defender Vulnerability Management
  • Prior consulting, systems integrator or managed services delivery experience
  • Experience in regulated industries such as telco, financial services, government or critical infrastructure
  • Tenable product certification, or CISSP, CISM, GIAC or equivalent

Additional Information

Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career.  Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own.  We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We'd love to hear from you.

We celebrate diversity and inclusion

We value different perspectives, experiences and strengths our people bring.  We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

Skills Required

  • At least 4 years of hands-on vulnerability management experience
  • Operational experience running Tenable One Vulnerability Management and/or Tenable Security Center in a large, complex organization
  • Strong knowledge of Nessus scanners and agents, credentialed scanning, scan policy tuning, asset tagging, VPR, dashboards, recast rules, and accept rules
  • Experience driving remediation at scale across multiple technology teams
  • Working knowledge of Windows, Linux, networking, and AWS or Azure cloud environments
  • Experience integrating vulnerability data with ITSM and CMDB platforms such as ServiceNow
  • Python or PowerShell scripting experience against APIs
  • Working knowledge of Essential Eight patching requirements and compliance evidence
  • Strong written and verbal communication skills, including briefing a CISO and managing service-owner deadlines
  • Full Australian work rights and availability to work on site in Sydney
  • Experience with ServiceNow Vulnerability Response or similar remediation workflow tooling
  • Experience with Qualys, Rapid7, or Microsoft Defender Vulnerability Management
  • Prior consulting, systems integrator, or managed services delivery experience
  • Experience in regulated industries such as telecommunications, financial services, government, or critical infrastructure
  • Tenable product certification, CISSP, CISM, GIAC, or equivalent
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Thiruvalla
1,358 Employees
Year Founded: 2001

What We Do

NCS in Australia is reinventing technology services from the inside out. We provide advisory, design, build and managed services to our clients, with unrivalled service, attention and understanding every step of the way. We understand day 1001 is just an important as day 1, and we collaborate with clients, striving to provide adaptive approaches, outcomes and thinking by keeping our eye on tomorrow and the days after tomorrow. Our diverse workforce of around 1,300 people has delivered a wealth of large-scale, mission-critical, and multi-platform outcomes for governments and businesses nationally. We are the Australian arm of the pan-APAC technology leader NCS Group, a subsidiary of Singtel Group. Combining the experience and expertise of its 13,000-strong team across 57 specialisations, NCS provides differentiated and end-to-end technology services to clients with its capabilities in digital, data, cloud and platforms, as well as core offerings in application, infrastructure, engineering and cybersecurity. NCS also believes in building a strong partner ecosystem with leading technology players, research institutions and start-ups to support open innovation and co-creation. For more information about NCS Australia, visit ncs.co/en-au or contact our team today. To learn more about NCS Group, visit ncs.co.

Similar Jobs

Takeda Logo Takeda

Senior Manager, Study Site Engagement

Healthtech • Software • Analytics • Biotech • Pharmaceutical • Manufacturing
Hybrid
Sydney, New South Wales, AUS
50000 Employees

Takeda Logo Takeda

Campaign Activation Lead

Healthtech • Software • Analytics • Biotech • Pharmaceutical • Manufacturing
Hybrid
Sydney, New South Wales, AUS
50000 Employees

Airwallex Logo Airwallex

GTM Partnerships Manager, AU, SME & Growth

Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
In-Office
2 Locations
2300 Employees

BlackRock Logo BlackRock

Business Development Manager

Fintech • Information Technology • Financial Services
In-Office
Sydney, New South Wales, AUS
25000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account