Senior Consultant - Exposure Management & Asset Visibility
- Lead the design and deployment of an asset visibility platform.
- Integrate discovery data with existing security tools and develop risk prioritization logic.
- Produce operational run books and transition capabilities to the client's security team.
Our client is delivering an enterprise exposure management and asset visibility capability across a converged IT, OT and IoT estate. We're recruiting on their behalf for a senior technical consultant to lead the design, deployment and operational handover of this platform, turning raw asset discovery data into a risk picture the client's security leadership can act on.
This is a hands-on delivery role with significant client exposure. You'll work alongside a practice lead and a senior consultant, and you will be the technical authority on the engagement.
- Design and deploy an agentless asset discovery and exposure management platform across corporate IT, cloud, OT and unmanaged device estates
- Plan and execute safe active scanning in fragile environments, including production OT and legacy embedded systems, without operational disruption
- Build and tune asset fingerprinting, classification and ownership models across a large, heterogeneous estate
- Integrate discovery data with the client's existing CMDB, vulnerability management, EDR and SIEM tooling via API
- Develop risk prioritization logic, dashboards and executive reporting mapped to NIST CSF, the Essential Eight and relevant regulatory obligations
- Identify unmanaged, unagentable and end-of-life assets, and drive remediation plans with asset owners
- Validate network segmentation integrity and map attack paths across IT/OT boundaries
- Produce operational run books and transition the capability to the client's BAU security team
What we're looking for
- 7+ years in cyber security, including 3+ years in asset visibility, exposure management or vulnerability management delivery
- Hands-on experience with a CAASM or asset intelligence platform, e.g. Armis, Claroty xDome, Forescout, Nozomi Networks, Axonius, Sevco, JupiterOne, Lansweeper or Tenable OT Security
- Strong practical networking fundamentals: TCP/IP, routing and switching, VLANs, network segmentation, and the ability to read a packet capture
- Working knowledge of OT/industrial protocols (Modbus, DNP3, BACnet, EtherNet/IP) and the operational sensitivities of scanning production control systems
- Experience integrating security tooling via REST APIs, with scripting in Python or PowerShell for data enrichment and reporting
- Familiarity with vulnerability management platforms such as Tenable, Qualys or Rapid7, and how asset context improves their output
- Strong written and verbal communication, able to write for both engineers and executives, and hold your own in a room with a CISO
- Australian work rights; ability to obtain a Baseline or NV1 security clearance is advantageous
We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.