Security Analyst - Contract

NCS Group Australia

Sydney

On-site

AUD 90,000 - 120,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NCS Australia is seeking a Security Analyst for a short-term contract engagement in Sydney, running from October through December 2026 with possible extensions. You will analyze external exposure data, consolidate asset information, and collaborate with cross-functional teams to drive risk-based remediation.

The role focuses on building a validated external baseline, prioritizing vulnerabilities, and delivering executive insights on exposure trends for cybersecurity leadership.

Qualifications

  • Proven track record as Security Analyst in External Attack Surface Management (EASM).
  • Ability to consolidate and de-duplicate large security datasets from multiple sources.
  • Understanding of asset discovery lifecycle and threat modeling frameworks.
  • Knowledge of IP routing, DNS, SSL/TLS, VPN architectures and cloud (GCP/AWS/Azure).
  • Strong communication skills to coordinate with technical owners and remediation actions.
  • Sydney-based and available to commence October 2026.

Responsibilities

  • Analyze external exposure data to establish an authoritative baseline.
  • Consolidate, normalize, and de-duplicate asset discovery data from multiple engines.
  • Reconcile discovered assets against internal registers to identify ownership gaps.
  • Collaborate with application, infrastructure, and business teams to validate relationships.
  • Evaluate findings to identify risks and prioritize remediation actions.
  • Define clear treatment recommendations including ownership and decommissioning.
  • Maintain audit-ready records of findings and evidence for handover.
  • Deliver reporting on exposure trends and remediation progress to leadership.

Skills

EASM experience
Data reconciliation
Asset management
Network security
Stakeholder engagement
Sydney-based

Tools

Security scanners

Job description

At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.

We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.

Job Description

We are seeking a Security Analyst for an initial short-term contract engagement running from October through December 2026 with possible extensions in Sydney.

In this specialist technical role, you will be responsible for analyzing raw discovery data across our internet-facing infrastructure to build a validated, risk-actionable External Exposure Baseline. You will bridge technical discovery with risk governance—consolidating complex datasets, establishing asset ownership, prioritising vulnerabilities, and embedding findings into our ongoing Exposure Management function.

Key Responsibilities
  • Attack Surface Data Analysis: Analyze large-scale external exposure datasets (IP addresses, domains, subdomains, VPN assets, cloud services, and edge infrastructure) to establish an authoritative external attack surface baseline.
  • Asset Discovery & Normalization: Consolidate, normalize, and de‑duplicate asset discovery data from multiple internal and external discovery engines into a single source of truth.
  • Inventory Reconciliation & Ownership Mapping: Reconcile discovered external assets against internal registers to identify ownership gaps, rogue non-production environments, and unmanaged services.
  • Stakeholder Engagement: Collaborate across application, infrastructure, and business teams to validate technical relationships, business criticality, and operational status.
  • Risk Assessment & Prioritization: Evaluate findings to identify systemic control gaps, orphaned assets, and security risks—prioritising remediation based on threat posture, business impact, and effort.
  • Treatment & Remediation Planning: Define clear treatment recommendations, including remediation actions, ownership assignment, risk acceptance, or asset decommissioning.
  • Documentation & Governance: Maintain audit-ready records of findings, decision rationale, ownership records, and evidence to support handover to ongoing operational teams.
  • Executive Reporting: Deliver clear reporting and insights on exposure trends, remediation progress, and systemic control issues for senior cybersecurity leadership.
Qualifications
  • Cyber Security & Exposure Analysis: Proven track record as a Security Analyst focusing on External Attack Surface Management (EASM), threat exposure, or vulnerability risk analysis.
  • Data Manipulation & Reconciliation: Strong capability to consolidate, query, and de‑duplicate large, complex technical datasets from multiple security scanning platforms.
  • Asset & Risk Governance: Deep understanding of enterprise inventory management, asset discovery lifecycle, and threat modeling frameworks.
  • Network & Infrastructure Security: Technical knowledge of IP routing, DNS, domain management, SSL/TLS, VPN architectures, and public cloud infrastructure (GCP/AWS/Azure).
  • Stakeholder Influence: Excellent communication skills to coordinate with technical owners, drive asset attribution, and negotiate remediation actions.
  • Availability & Location: Sydney-based and available to commence the engagement in October 2026.
Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own. We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We'd love to hear from you.

We celebrate diversity and inclusion

We value different perspectives, experiences and strengths our people bring. We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies:

NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst - Contract
Security Analyst - Contract

NCS • Sydney

On-site
AUD 120,000 - 150,000
Senior Consultant - Exposure Management & Asset Visibility
Senior Consultant - Exposure Management & Asset Visibility

NCS Australia • City of Melbourne

On-site
AUD 140,000 - 190,000
Senior Consultant - Exposure Management & Asset Visibility
Senior Consultant - Exposure Management & Asset Visibility

NCS • City of Melbourne

On-site
AUD 150,000 - 190,000
Technical Business Analyst (DevSecOps) - Contract
Technical Business Analyst (DevSecOps) - Contract

NCS Group Australia • Sydney

On-site
AUD 120,000 - 180,000
Senior Consultant - Exposure Management & Asset Visibility
Senior Consultant - Exposure Management & Asset Visibility

NCS • Sydney

On-site
AUD 140,000 - 180,000
Senior Consultant - Exposure Management & Asset Visibility
Senior Consultant - Exposure Management & Asset Visibility

NCS Group Australia • City of Melbourne

On-site
AUD 170,000 - 210,000
Technical Business Analyst (DevSecOps) - Contract
Technical Business Analyst (DevSecOps) - Contract

NCS • Sydney

On-site
AUD 110,000 - 140,000
Senior Consultant - Exposure Management & Asset Visibility
Senior Consultant - Exposure Management & Asset Visibility

NCS Group Australia • Sydney

On-site
AUD 180,000 - 240,000
DevSecOps SME - Contract
DevSecOps SME - Contract

NCS Australia • City of Melbourne

On-site
AUD 120,000 - 180,000
DevSecOps SME - Contract
DevSecOps SME - Contract

NCS Group • City of Melbourne

On-site
AUD 150,000 - 185,000