14 дней назад
Senior Cyber Exposure Specialist (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Cyber Exposure Specialist (Cybersecurity): Leading continuous threat exposure and vulnerability management across external attack surfaces and internal enterprise environments with an accent on attack-surface discovery, risk-based prioritisation, and remediation coordination. Focus on validating exposures through attack-path analysis and safe exploitation, managing zero-day incidents, and converting findings into actionable detections and security controls.
Location: NSW, Australia; hybrid arrangement with three days in the office and two days remote or from home
Company
is a telecommunications company delivering technology products and services while protecting customers, networks, and critical infrastructure from cyber threats.
What you will do
- Lead continuous threat exposure management across the external attack surface and internal vulnerability landscape.
- Discover, investigate, and manage internet-facing assets, exposed services, APIs, cloud resources, certificates, shadow IT, and third-party dependencies.
- Drive the vulnerability management lifecycle from scanning and triage through prioritisation, remediation tracking, and verification.
- Prioritise exposures using exploitability, business impact, attack-path reachability, and threat intelligence.
- Manage zero-day vulnerabilities, mass exploitation events, and software supply chain compromises, coordinating rapid assessment and remediation.
- Partner with infrastructure, cloud, engineering, application, threat hunting, detection engineering, and incident response teams to improve cyber resilience.
Requirements
- Extensive experience in exposure management, vulnerability management, attack surface management, offensive security, or a related cybersecurity discipline.
- Hands-on experience managing the exposure lifecycle from discovery through remediation and risk reduction.
- Strong understanding of enterprise cloud platforms, infrastructure, applications, containers, APIs, CI/CD pipelines, and identity systems.
- Experience with vulnerability, attack surface, and exposure management platforms, plus proficiency in KQL, SPL, SQL, or XQL and scripting for automation.
- Knowledge of vulnerability exploitation, attack-path analysis, threat intelligence, and MITRE ATT&CK frameworks.
- Qualifications in cybersecurity, information technology, computer science, or equivalent experience, with strong stakeholder engagement and communication skills.
Nice to have
- OSCP, CISSP, GCIH, GWAPT, or vendor certifications from Tenable, Qualys, or Rapid7.
Culture & Benefits
- Flexible hybrid working with three office days and two remote or home-working days.
- Competitive remuneration, employee discounts, and an $80 monthly credit.
- Additional Connected leave days, inclusive paid parental leave of up to 16 weeks, and support for carers.
- Professional development through U micro-credentials developed with La Trobe and Macquarie Universities.
- Access to employee networks, diversity initiatives, and 24/7 counselling and wellbeing support.
- Office campus with cafes, a gym, medical services, childcare, and other onsite facilities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →