Skip to main content
AfterDuty

Security Engineer

Whizdom · Melbourne, Victoria

Type
Contract
Posted
7 days ago

Overview

Your investigative mindset and methodical approach to evidence handling transfer to vulnerability assessment and control validation.

About this role

Security Controls Validation Engineer

Melbourne | Contract Opportunity

About the Company

Our client is a leading technology and consulting organisation delivering security and digital transformation services to major Australian enterprises. They partner with large, complex organisations to strengthen cyber security capabilities, improve risk management practices, and enhance operational resilience.

About the End Client

You will be supporting a highly recognised enterprise operating critical technology environments across Australia. The organisation is investing heavily in cyber security, vulnerability management, and security control effectiveness initiatives.

The Opportunity

We are seeking an experienced Security Controls Validation Engineer to join a high-performing cyber security team based in Melbourne. This is a hands-on role focused on assessing security controls, identifying vulnerabilities, validating remediation activities, and working closely with infrastructure, endpoint, cloud, and application teams to improve the organisation's security posture.

The successful candidate will bring strong experience in vulnerability management, security control assessment, and enterprise security technologies, along with a practical approach to risk-based security recommendations.

Key Responsibilities

  • Conduct vulnerability assessments across servers, endpoints, and infrastructure environments.
  • Analyse security gaps and assess risk exposure across enterprise environments.
  • Validate the effectiveness of existing security controls and identify areas for improvement.
  • Work closely with infrastructure, endpoint security, cloud, and application teams to support remediation activities.
  • Re-test and validate remediation actions to ensure successful closure of security findings.
  • Support control validation exercises, attack simulations, and audit-related security assessments.
  • Deliver clear reporting and recommendations to technical and stakeholder audiences.
  • Contribute to vulnerability management lifecycle activities including prioritisation, tracking, and validation.

Required Skills & Experience

  • 5-10 years of relevant cyber security experience.
  • Strong experience in vulnerability management and security control validation.
  • Sound understanding of enterprise security controls, endpoint security, and infrastructure security principles.
  • Experience analysing vulnerability data and prioritising remediation activities based on risk.
  • Working knowledge of security frameworks including NIST and Essential Eight. ,
  • Strong stakeholder engagement, reporting, and communication skills.
  • Ability to work effectively across multiple technical teams.

Technical Environment

Experience with any of the following technologies will be highly regarded:

  • Microsoft Defender for Endpoint (MDE)
  • Rapid7 InsightVM or similar vulnerability management platforms
  • Trellix ePO / Application Control (AWL)
  • Enterprise endpoint security technologies
  • Windows and Linux server environments
  • Splunk or similar SIEM platforms (advantageous)

Desirable Experience

  • Experience working within large enterprise environments.
  • Exposure to cloud security and hybrid infrastructure environments.
  • Scripting or automation skills using PowerShell, Python, or Bash.
  • Security operations or incident response exposure.

What's on Offer

  • Opportunity to work on large-scale enterprise security initiatives.
  • Exposure to modern cyber security tools and frameworks.
  • Collaborative and highly skilled technical environment.
  • Contract opportunity with a strong focus on security outcomes and continuous improvement.

How to Apply

If you have strong experience in vulnerability management, security control validation, and enterprise security operations, we'd love to hear from you.

Farbar Siddiq

📧 farbars@whizdom.com.au

📱 0489 922 211

Please submit your CV for immediate consideration.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Melbourne →

Why this fits a police background

  • Incident command & response
  • Security operations

More cyber security & digital forensics jobs for ex-police

  • Control Manager Vulnerability Management

    Commonwealth Bank · Melbourne

    Full-time

    Control Manager, Vulnerability Management Do you thrive at the intersection of cyber security, technology, and stakeholder engagement? Help drive vulnerability remediation, shape governance practices, and make a real impact across the organisation.

    Posted 7 days ago

  • Information Security & Risk Analyst

    The Royal Australian College of General Practitioners (RACGP) · Melbourne

    Full-time

    Your incident command and threat assessment experience maps directly to security risk and resilience work.

    Posted 9 days ago

  • Cyber Security Assurance Analyst

    Kinetic · Melbourne

    Contract

    Your experience with evidence handling and regulatory compliance maps directly to security assurance and vendor risk assessment.

    Posted 9 days ago

  • Cloud Security Engineer

    IFM Investors · Melbourne

    Full-time

    About Us JOB DESCRIPTION IFM Investors is a global asset manager, founded and owned by pension funds, with capabilities in infrastructure equity and debt, private equity, private credit, real estate and listed equities.

    Posted 14 days ago