30 Sep
|
Software At Scale
|
Sydney
30 Sep
Software At Scale
Sydney
Our black belt specialists are leaders in their domains, serving as digital champions, delivery focused experts, top tier security professionals, AI thought leaders, and engineering best practice advocates.
As 1 of Australias fastest growing software businesses, Software at Scale delivers cutting edge technology solutions that power mission critical platforms. We solve complex engineering challenges at scale, driving quality, performance, and resilience through the strength of our people.
The Role and The Challenge
We are seeking an exceptional and highly proactive Vulnerability Control and Governance Lead to operate at the critical intersection of cyber control governance and technical implementation. This is not a passive, paper-pushing compliance role. You will partner directly with our control squads and engineering platforms to establish comprehensive vulnerability visibility, uplift CMDB asset integrity, and formalise robust end to end vulnerability management operating procedures. You will bridge governance policies with operational technical practices, defining enterprise reporting frameworks across asset discovery, exception handling, and remediation tracking.
Access to AI Tooling: We believe in removing friction so you can focus on solving hard problems. You will have full access to enterprise AI tooling, including Claude Code, to assist you and your teams in accelerating governance documentation, script automation, and vulnerability telemetry analysis.
Key Responsibilities
- Vulnerability Scanning and Asset Visibility: Define and maintain baseline technical requirements for scan coverage reporting, tracking target infrastructure estates against actively scanned assets while overseeing telemetry ingestion from tools like Qualys and Wiz into ServiceNow.
- CMDB Integrity and Asset Classification:
Collaborate with engineering and configuration teams to remediate and refine CMDB data structures, ensuring comprehensive mapping across diverse asset classes, network hardware, and operational environments to enable accurate risk reporting.
- Reporting and Analytics Delivery: Translate control and audit requirements into functional specifications for ServiceNow and Tableau dashboards, facilitating continuous refinement of operational risk metrics and remediation tracking.
- Process Architecture and Governance Documentation: Author, standardise, and maintain operational guides and standard operating procedures governing the complete vulnerability management lifecycle, including documentation for unscannable legacy systems and compensating controls.
- RACI Framework Alignment: Review and align the enterprise RACI matrix to embed security ownership cleanly into operational support plans across cross functional engineering and risk stakeholders.
What You Bring (Attitude and Mindset)
- Thrives in Ambiguity: You are exceptionally comfortable walking into complex and ambiguous governance environments, taking the initiative to rapidly distill requirements and map out clear operational paths.
- Fearless Continuous Learner: When faced with an unfamiliar technical gap or a complex regulatory constraint, you do not freeze. You lean in, rapidly upskill, bridge the divide, and master the domain needed to get the job done.
- The Desire for a Challenge:
You actively seek out difficult security and governance constraints and thrive when securing high scale enterprise estates.
- Radical Communication and Ownership: You communicate transparently, collaborate openly with engineering squads, challenge security blind spots early, and take uncompromising personal accountability for risk outcomes.
What You Bring (Technically)
- Enterprise Security Experience: Minimum 5 years operating within enterprise cyber security, IT risk, or systems governance environments, with direct hands on exposure to vulnerability management lifecycles.
- Platforms and Tooling Mastery: Hands on experience with vulnerability management platforms such as Qualys and Wiz, ServiceNow VR or SecOps modules, and Tableau reporting ecosystems.
- Data and Architecture Acumen: Proven capability in CMDB data remediation, infrastructure discovery patterns, and asset classification across complex enterprise estates.
- Governance and Standards Execution: Demonstrated experience authoring enterprise grade technical documentation, user guides, and RACI matrices tied to operational risk management.
- Tooling Fluency: A practical and delivery focused mindset on how to leverage up-to-date AI tools like Claude Code to assist in governance documentation and data analysis.
What We Offer
- The chance to work for 1 of Australias fastest growing and most innovative software businesses.
- Access to the latest AI tooling to assist you in achieving your technical goals.
- Meaningful and high impact security governance work across complex enterprise platforms.
- Clear growth pathways from Lead to Senior Manager and beyond.
- A low ceremony and delivery focused environment that values professionals who own outcomes.
- Competitive remuneration and benefits.
📌 Vulnerability Control and Governance Lead (Sydney)
🏢 Software At Scale
📍 Sydney