20 Sep
|
Whizdom
|
New South Wales
20 Sep
Whizdom
New South Wales
Job Description
Security Engineer, runZero Platform
n
Location: Sydney
n
Contract: 6 Months + Highly Likely Extensions
n
About the Opportunity
n
A leading technology consultancy is seeking an experienced Security Engineer to design, implement and operate an enterprise asset-discovery capability using runZero.
n
This is a hands‐on engineering role combining platform configuration, security automation, systems integration and site reliability engineering. You will help establish a scalable operating model that delivers accurate asset visibility across corporate, data‐centre, cloud, remote‐access, network, IoT and relevant operational technology environments.
n
Key Responsibilities
n
n
Design and implement the runZero operating model, including environments, access controls, roles, sites, asset groups, tags and naming standards.
n
Configure discovery coverage across corporate, cloud, data‐centre, remote‐access, network, IoT and relevant OT environments.
n
Develop active‐scanning, passive‐discovery and integration patterns suited to different network zones and operational risk profiles.
n
Establish appropriate scanning standards, approval controls, maintenance windows and exception processes.
n
Configure asset classification, ownership, business context, criticality and lifecycle information.
n
Develop reusable configuration patterns and maintain separation between production, testing and experimental changes.
n
Integrate runZero with enterprise platforms such as CMDB, ServiceNow, Tenable, EDR, NAC, DNS/DHCP, cloud services, identity systems, SIEM and SOAR.
n
Implement secure API‐based data ingestion and egress using service identities and least‐privilege access.
n
Automate asset reconciliation, deduplication, enrichment,
ownership mapping and data‐quality validation.
n
Define integration contracts, schemas, field mappings, error handling, retry behaviour and support expectations.
n
Build automated workflows for newly discovered assets, exposed services, control gaps, unauthorised devices and material changes.
n
Use APIs, webhooks, scripts and workflow platforms to streamline administration and improve response times.
n
Automate scan scheduling, configuration validation, asset tagging, reporting and lifecycle management.
n
Design safe, repeatable automation that avoids duplicate records, tickets and configuration drift.
n
Apply version control, peer review, automated testing, release controls and rollback procedures to platform changes.
n
Establish service indicators, dashboards and alerts covering discovery coverage, data freshness, integration health, scanning and workflow reliability.
n
Develop operational runbooks and support backup, recovery, disaster‐recovery and business‐continuity planning.
n
Implement role‐based access, privileged‐access controls, administrative separation and auditable change history.
n
Support architecture, security, privacy, risk and control‐assurance reviews.
n
n
Required Skills and Experience
n
n
Strong experience engineering and operating enterprise security or asset‐discovery platforms.
n
Practical expertise with runZero or a comparable asset‐discovery and attack‐surface visibility platform.
n
Strong knowledge of active scanning, passive discovery and network‐zone risk management.
n
Experience integrating security platforms with CMDB, ServiceNow, vulnerability‐management, endpoint, network, cloud, identity and SIEM/SOAR technologies.
n
Demonstrated API, webhook, scripting and workflow‐automation capability.
n
Experience with asset reconciliation, deduplication, enrichment and data‐quality controls.
n
Sound understanding of least‐privilege access, service identities, secrets management and role‐based access control.
n
Experience applying infrastructure‐as‐code or configuration‐as‐code practices, version control, testing and controlled releases.
n
Robust operational knowledge across monitoring, alerting, incident runbooks, recovery, performance and capacity management.
n
n
Desirable Experience
n
n
Experience supporting asset discovery across cloud, IoT or operational technology environments.
n
Knowledge of ServiceNow, Tenable, EDR, NAC, DNS/DHCP, SIEM and SOAR integrations.
n
Experience designing event‐driven and idempotent automation.
n
Familiarity with security architecture reviews, privacy assessments, risk assessments and regulatory control requirements.
n
n
What's on Offer
n
n
A technically challenging role with significant ownership of an enterprise security platform.
n
The opportunity to build scalable discovery, integration and automation capabilities.
n
Broad collaboration across security, infrastructure, network, cloud and application teams.
n
A role spanning engineering delivery, automation, operational resilience and security governance.
n
📌 Security Platform Engineer (New South Wales)
🏢 Whizdom
📍 New South Wales