06 Aug
|
RONIN Dynamics
|
Sydney
06 Aug
RONIN Dynamics
Sydney
Network Segmentation Engineer
Postmortem: INC-000000
Status: Did Not Happen
Foothold: one compromised laptop, general office subnet
Lateral move: attempted, hop 1
Blast radius: one workstation
Containment: n/a — there was nothing left to contain
Root cause: a segmentation policy that assumed the breach already happened, instead of trying to stop it at the door.
The honest version of this ad
That's the incident report nobody has to write, because the network was built to assume a breach rather than pretend one won't happen. In most corporate networks, one phished laptop is a free tour of everything else on the subnet. This role exists to make sure that stops being true.
You'd be joining a large, nationally significant infrastructure and services organisation that is building an enterprise microsegmentation capability from scratch. Not administering someone else's finished platform. Building it.
What you'd actually be doing
- Drawing the actual map: working out what really talks to what across the environment, then building least-privilege policy around it instead of guessing
- Wiring it into everything else: feeding segmentation telemetry into the SIEM so policy violations and lateral movement attempts show up as signal, not noise
- Making Zero Trust real, not a slide:
partnering with network and architecture teams so segmentation actually lines up with the Zero Trust strategy on paper
- Building the plumbing: automation for flow mapping, policy generation and validation, plus CI/CD pipelines so policy deploys like code, not like a change ticket
- Being in the room during a live incident: using policy analysis to help contain something for real, not just in a tabletop exercise
What you'd bring
- Hands-on time with a real microsegmentation platform in a production setting, not a lab
- Genuine Zero Trust fluency: least-privilege, workload isolation, and why "trust but verify" was always half a sentence
- Comfort reading network and application traffic flows well enough to spot what a policy will break before it ships
- Scripting chops (Python or Bash) and enough CI/CD or config-as-code experience to industrialise the work, not hand-craft every policy
- 5+ years somewhere in network security, workload security, or platform engineering
What you won't be doing Maintaining a platform someone else already finished and walked away from. This capability doesn't exist yet. You'd be one of the people who builds it.
The practical bit
Permanent role, hybrid working. Based in Sydney. If the postmortem at the top of this ad made you smile rather than roll your eyes, get in touch.
📌 Network Segmentation Engineer (Sydney)
🏢 RONIN Dynamics
📍 Sydney