Skip to main content
AfterDuty

Senior Analyst Vulnerability Management

Transport for NSW · Sydney, New South Wales

Salary
A$141,678 – A$158,677Estimated
Type
Full-time
Posted
2 days ago

Overview

Your experience in incident response and threat assessment from policing gives you a foundation for understanding vulnerability lifecycles and risk prioritisation. However, this role demands hands-on technical expertise with tools like Qualys and Tenable, plus formal cyber security qualifications, which most ex-officers would need significant retraining to acquire.

About this role

Organisation/Entity: Transport For NSW

Job category: Projects

Job location

Macquarie Park, NSW, AU, 2113

#job-location.job-location-inline { display: inline; }

Employment type: Permanent Full-Time

.buttontext84e7fa5614fe8498 a{ border: 1px solid transparent; } .buttontext84e7fa5614fe8498 a: focus{ border: 1px dashed #0085b3 !important; outline: none !important; }

You’re someone who wants to create outcomes that have a real impact on the people of NSW.

You bring structure, mitigation and education to our organisation. Our records and datasets are vast and varied. This is your opportunity to safeguard critical infrastructure, order and protect sensitive data, and defend against emerging cyber threats. You'll be part of an expert team who protect against thousands of threats every day.

In this role, you'll

Work closely with the Senior Manager, Vulnerability Management, you will play a key role in building and supporting a centralised vulnerability management function that helps reduce cyber risk, strengthen operational resilience, and improve security outcomes across Transport's technology landscape.

Conduct vulnerability scanning, validation and analysis using tools such as Qualys, Tenable, Rapid7 and other security platforms.

Identify, prioritise and assess vulnerabilities, including exploitability and business impact.

Partner with operational, engineering and incident response teams to coordinate remediation activities and drive timely resolution of security risks.

Support patch management and remediation workflows across diverse technology environments.

Please view the role description and Information Pack for more information.

About you

You are a hands-on cyber security professional with experience in vulnerability management, remediation, and operational security. You have strong analytical skills and can effectively communicate technical findings to a range of stakeholders.

Experience working with vulnerability management and security scanning tools (Qualys, Tenable, Rapid7 or similar)

Knowledge of vulnerability lifecycles, remediation processes, patch management and secure configuration principles

Experience collaborating with technology and operational teams to reduce cyber risk and improve security outcomes

Strong reporting, stakeholder engagement and problem-solving capabilities

A passion for continuous improvement and strengthening organisational cyber resilience

Degree qualifications in Cyber Security, Information Technology or a related discipline (Security+ or CySA+ certifications desirable)

This role is based in Macquarie Park (Hybrid Working Model)

Who we are

Transport for NSW provides a safe, integrated, and efficient transport system. We connect people, communities and industry every day.

Join us

Our workforce is as diverse as the community we serve. If you’d like further information on our inclusion and diversity initiatives, visit Transport careers.

Flexible work options may be available. Learn more via Flexible work options and policy

Apply today

Applications close 11:59 PM Tuesday 18 August 2026

For more information about this role, please contact SHANKAR.SAPKOTA@TRANSPORT.NSW.GOV.AU.

Aboriginal people and people living with disability are supported throughout the recruitment process and at work, and we encourage you to apply. Visit Supporting Aboriginal People or Supporting People with Disability for more information or speak to your talent team member to arrange any adjustments to how you interact with us.

Learn more about how to apply via Our recruitment process | Transport for NSW

#LI-Hybrid

Job Segment: Cyber Security, Developer, Engineer, Manager, Web Design, Security, Technology, Engineering, Management, Creative

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Sydney

Why this fits a police background

  • Incident command & response

More cyber security & digital forensics jobs for ex-police

  • Your background running operational units and coordinating multi-agency responses maps directly onto leading national support functions and ensuring consistent, secure operations across multiple sites. You're used to setting clear accountabilities, managing risk, and driving continuous improvement, which is exactly what this role requires. Your experience with compliance and governance, from PACE to internal procedures, means you can bring structure and discipline from day one.

    Posted 2 days ago

  • Full-time

    Your experience working to strict regulatory frameworks like PACE and CPIA gives you a natural grounding in compliance and assurance, which is exactly what this cyber security GRC role demands. You've spent years maintaining accurate records, managing risk registers, and engaging with diverse stakeholders under pressure, so coordinating audits and driving adherence to standards like ISO 27001 will feel familiar. The role is a development opportunity, so your proven attention to detail and process-oriented mindset will let you build the specific cyber security knowledge on the job.

    Posted 5 days ago

  • Integrity and Security Analyst

    NSW Government · Sydney

    Full-time

    A$133,348 – A$146,945Estimated

    This role directly leverages your operational intelligence experience from policing — you'll produce intelligence products that identify security risks and inform frontline decisions, just as you did under the National Intelligence Model. Your ability to assess threats, manage multi-agency coordination, and apply legislative frameworks like PACE or RIPA is exactly what the NSW Electoral Commission needs to safeguard election integrity. The requirement for 10+ years in law enforcement confirms this is a role built for your background, not a sideways move into a completely new field.

    Posted 5 days ago

  • Full-time

    Your investigative experience from policing—evidence handling, chain of custody, case file management, and conducting structured interviews—maps directly onto the core responsibilities of this insider threat role. You are used to working with sensitive information, maintaining confidentiality, and producing defensible reports for multiple stakeholders, which is exactly what this position demands. The analytical and risk-assessment skills you developed through intelligence-led policing and managing complex investigations will let you hit the ground running in identifying and mitigating insider

    Posted 7 days ago