06 Aug
|
XPT Software
|
Melbourne
06 Aug
XPT Software
Melbourne
XPT SoftwareAustralia PTY Ltd, incorporated in ****, is a Software Services company
XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
We have 120+technocrats in Australia working at our clientlocations.
XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Role Summary
The Cyber Security Engineer isresponsible for supporting NIST CSF / NIST 800 assessments, triagingpenetration test findings, and driving remediation activities acrossapplication, infrastructure, network security, and monitoring platforms.
The role is hands-on and deliveryfocused, working closely with architects, platform owners, SOC, andinfrastructure/application teams to translate security findings into actionablefixes, validate control effectiveness, and support audit‐ready evidence forregulated/government environments.
Key Responsibilities
NIST Assessment Support (CSF / NIST 800Series)
SupportNIST CSF / NIST ************************ assessments through:
Controlevidence collection
Gapanalysis support
Mappingtooling controls to NIST requirements
Assistarchitects and governance teams in preparing:
Controlimplementation summaries
Toolcapability mapping
Evidencepacks for audits and client reviews
Trackand manage security gaps, risks, and remediation actions in line withagreed timelines
Supportcontinuous improvement initiatives driven by assessment outcomes
Penetration Test Findings &Remediation;
Triageand analyse application, infrastructure, and network penetration testfindings
Workwith platform and application teams to:
Prioritiseremediation based on risk and exploitability
Executeor support remediation actions such as:
Controlenablement or enhancement
Trackremediation status and provide explicit closure evidence for governance andaudit forums
Activitiesinclude:
Policytuning and baseline hardening
Coverageand health checks
Supportingremediation of vulnerabilities and misconfigurations
Support security controls across:
Ciscosecurity platforms
Imperva
MicrosoftGSA / related network security controls
Responsibilities include:
Supportingfirewall / network security rule reviews and clean‐ups
Assistingwith remediation of network‐related pen test findings
Supportingchange validation and post‐implementation checks
Workingwith network teams to ensure security controls align with NIST and secure‐by‐designprinciples
SupportSIEM and monitoring platforms:
Splunk
MicrosoftSentinel
Assistwith:
Detection coverage checks related to NIST andpen test scenarios
Validation that remediated controls generateexpected telemetry
SupportSOC teams with investigation data where required
Remediationactions
Controlchanges
Evidencerequired for audits and MSSR / governance reviews
Incident and problem reviews (P1 / P2 support)
Root cause analysis where control gaps areidentified
Followstructured change and release processes (CAB, validation, rollback awareness)
Skills &Experience;
5 years experience in security engineering / SecOps / blue teamroles
Exposure to NIST CSF or NIST 800 frameworks
Hands‐on experience supporting remediation across:
Endpoint / infrastructuresecurity tools
Vulnerability managementplatforms
Network security controls
Experience working with penetration test reports and remediationtracking
Familiarity with SIEM platforms (Splunk and/or Sentinel)
#J-*****-Ljbffr
📌 Soc Analyst (Melbourne)
🏢 XPT Software
📍 Melbourne