NCS Australia logo

Senior Vulnerability Management Specialist (Tenable)

Hiring from
Australia
Work type
Hybrid
Posted
Oct 1, 2026
Is this job info correct?

At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.

We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.

We are looking for a senior vulnerability management specialist to run and uplift vulnerability management operations for one of our major clients, a large Australian enterprise based in Sydney. Tenable is the core platform, and you will own it day to day: scan coverage, data quality, prioritisation, remediation tracking and reporting across a large hybrid estate.

This is a hands-on operational role with real accountability. You will be the Tenable subject matter expert on the engagement, and the person infrastructure teams, service owners and security leadership rely on for a clear view of exposure and what to fix first.

What you'll do

  • Operate and tune the Tenable platform day to day: scan policies and schedules, credentialed and agent-based scanning, scanner and agent health, asset tagging and access controls
  • Own scan coverage and data quality by reconciling Tenable against the CMDB, cloud inventories and endpoint tooling, then closing blind spots and authentication failures
  • Triage and prioritise findings on risk (VPR, CVSS, EPSS, known exploited vulnerabilities, asset criticality and internet exposure) rather than raw severity counts
  • Drive remediation with infrastructure, cloud, network and application teams: raise and track work through the ITSM tool, agree treatment plans, hold owners to SLAs and verify fixes by rescan
  • Lead the response to critical and zero-day vulnerabilities, from rapid exposure assessment and targeted scans through to confirmed closure
  • Manage false positives, exceptions and risk acceptances with proper evidence, approval and expiry
  • Build dashboards and reporting for operational teams and executives covering coverage, SLA performance, ageing and risk trend, including evidence for Essential Eight and audit requirements
  • Automate and integrate using the Tenable API with Python or PowerShell, connecting vulnerability data to ITSM, CMDB, SIEM and patching tools
  • Document runbooks and operating procedures, and coach analysts and support teams so the capability outlasts the contract
  • ​​​​Strong demonstrable experience in cyber security or infrastructure operations, with at least 4 years hands-on in vulnerability management
  • Proven operational experience running Tenable in a large, complex organisation (tens of thousands of assets): Tenable One Vulnerability Management (formerly Tenable.io) and/or Tenable Security Center (formerly Tenable.sc). You have operated the platform day to day, not just consumed its reports
  • Deep working knowledge of Nessus scanners and agents, credentialed scanning, scan policy tuning, asset tagging, VPR, dashboards, and recast and accept rules
  • Exposure to the wider Tenable One platform, such as web application scanning, cloud, identity or attack surface management
  • A track record of driving remediation at scale across multiple technology teams, with measurable reduction in ageing and critical exposure
  • Strong grounding in Windows, Linux, networking and cloud (AWS or Azure), enough to discuss root cause and fixes credibly with engineers
  • Experience integrating vulnerability data with ITSM and CMDB platforms such as ServiceNow, and scripting in Python or PowerShell against APIs
  • Working knowledge of the Essential Eight patching requirements and how to evidence compliance
  • Clear written and verbal communication, with the confidence to brief a CISO and to hold a service owner to a deadline
  • Full Australian work rights, and availability to work on site in Sydney

Nice to have:

  • Experience with ServiceNow Vulnerability Response or similar remediation workflow tooling
  • Experience with other vulnerability management platforms such as Qualys, Rapid7 or Microsoft Defender Vulnerability Management
  • Prior consulting, systems integrator or managed services delivery experience
  • Experience in regulated industries such as telco, financial services, government or critical infrastructure
  • Tenable product certification, or CISSP, CISM, GIAC or equivalent

Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own. We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We'd love to hear from you.

We celebrate diversity and inclusion

We value different perspectives, experiences and strengths our people bring. We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

Similar jobs

Apply for this job