Skip to content
← Back to job listings

Senior Consultant - Exposure Management & Asset Visibility

NCS Australia · Sydney, NSW, Australia

Banking & Financial ServicesExternal listingfull-timeabout 2 hours ago

About The Role

We are delivering an enterprise exposure management and asset visibility capability for a major Australian client with a converged IT, OT and IoT estate. You will lead the technical design, deployment and operational handover of the platform, and turn raw asset discovery data into a risk picture the client’s security leadership can act on.

This is a hands-on delivery role with significant client exposure. You will work alongside the practice lead and a senior consultant, and you will be the technical authority on the engagement.

What you’ll do

  • Design and deploy an agentless asset discovery and exposure management platform across corporate IT, cloud, OT and unmanaged device estates
  • Plan and execute safe active scanning in fragile environments, including production OT and legacy embedded systems, without operational disruption
  • Build and tune asset fingerprinting, classification and ownership models across a large, heterogeneous estate
  • Integrate discovery data with the client’s existing CMDB, vulnerability management, EDR and SIEM tooling via API
  • Develop risk prioritisation logic, dashboards and executive reporting that map findings to NIST CSF, the Essential Eight and the client’s regulatory obligations
  • Identify unmanaged, unagentable and end-of-life assets, and drive remediation plans with asset owners
  • Validate network segmentation integrity and map attack paths across IT and OT boundaries
  • Produce operational runbooks and transition the capability to the client’s BAU security team
  • Seven or more years in cyber security, with at least three in asset visibility, exposure management or vulnerability management delivery
  • Hands-on experience with one or more CAASM or asset intelligence platforms — for example Armis, Claroty xDome, Forescout, Nozomi Networks, Axonius, Sevco, JupiterOne, Lansweeper or Tenable OT Security
  • Strong practical networking: TCP/IP, routing and switching, VLANs, network segmentation, and the ability to read a packet capture
  • Working knowledge of OT and industrial protocols (Modbus, DNP3, BACnet, EtherNet/IP) and the operational sensitivities of scanning production control systems
  • Experience integrating security tooling via REST APIs, with scripting in Python or PowerShell for data enrichment and reporting
  • Familiarity with vulnerability management platforms such as Tenable, Qualys or Rapid7, and how asset context improves their output
  • Ability to write clearly for both engineers and executives, and to hold your own in a room with a CISO
  • Australian work rights; ability to obtain a Baseline or NV1 clearance is advantageous

Nice to have

  • Exposure to Purdue model architectures and IEC 62443
  • Prior consulting or systems integrator delivery experience
  • Certifications such as GICSP, GRID, CISSP, OSCP, or vendor-specific asset platform accreditations
  • Experience in regulated industries — utilities, telecommunications, financial services, or critical infrastructure under the SOCI Act

Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen.

You’ll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career.

Whether you want to deepen your expertise, explore something new or take your career in a different direction, there’s room to make it your own.

We value Adventure, Excellence, Integrity, Ownership and Unity — bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We’d love to hear from you.

We celebrate diversity and inclusion

We value the different perspectives, experiences and strengths our people bring. We’re committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing