About the Company
Our client is one of Australia's largest general insurers. This position sits within Cyber Operations for Group Technology; this is a hands-on lead role for an experienced security engineer who wants to own and mature an enterprise vulnerability management program. You'll be the subject matter expert on the organisation's Palo Alto Cortex Vulnerability Management platform, driving detection, prioritisation and remediation across hybrid and cloud environments.
Key Responsibilities
- Administer and maintain the vulnerability management platform, ensuring scan coverage, asset visibility and data accuracy across the attack surface
- Build remediation workflows that automate ticketing, SLA tracking and owner assignment, integrated with ITSM platforms
- Define and manage scanning schedules, credentialed scan policies and asset group configurations across on-prem, cloud and hybrid environments
- Triage and prioritise vulnerabilities using risk-based scoring, incorporating threat intelligence, asset criticality and exploitability context
- Engage product owners and asset custodians to drive timely remediation, tracking SLAs and escalating aged or critical findings through governance channels
- Develop and maintain reporting — executive dashboards, operational metrics and trend analysis — tailored to different audiences
- Define and maintain vulnerability management policy, standards and exception handling processes aligned to organisational risk appetite and compliance frameworks
- Mentor and upskill other engineers through documentation, training and informal support
- Coordinate the threat intelligence program, enriching vulnerability data with known exploitation activity, adversary TTPs and emerging advisories
- Develop SOPs, support documentation and automation scripts to ensure consistent,
high-quality operations
- Support penetration testing and red team activities with vulnerability context and remediation status
- Evaluate and implement improvements to scan architecture, including authenticated scanning, agent-based deployment, and API integrations with CMDB, ITSM and SOAR platforms
About You
- Hands-on experience with security platforms such as Palo Alto Cortex Vulnerability Management, ideally within a regulated financial services environment
- Solid understanding of vulnerability management practices — CVSS, remediation workflows, risk prioritisation, and governance reporting
- Solid experience with Microsoft Entra and/or Active Directory
- Automation skills in PowerShell, Python or similar for API integration and task automation
- Experience incorporating threat intelligence into vulnerability management processes
- Proven track record running business-critical security technology 24×7, including change, incident and problem management (ITIL or similar)
- Ability to read and produce design documents, sequence diagrams, and conduct structured testing
- Knowledge of APRA CPS 234, PCI-DSS or equivalent compliance frameworks highly regarded
You'll also bring:
- A strong passion for cybersecurity operations and design thinking
- The ability to adapt quickly to changing priorities and evolving requirements
- Excellent communication skills and the ability to build rapport across technical and non-technical stakeholders
- Critical thinking and the confidence to constructively challenge ideas
- A pragmatic, business-minded and results-oriented approach
- A collaborative, can-do attitude with the initiative to help the team deliver
- Comfort working independently and within dispersed/distributed teams
Please send your CV to
[email protected] or speak to Matthew Nicholas.
📌 Senior Cyber Security Engineer (Sydney)
🏢 Lanson Partners
📍 Sydney