About the team
The Cyber Threat and Vulnerability Management Section sits within Cyber Security and Networks Branch, Information Management and Technology Division. The Section is responsible for identifying and managing cyber threats and vulnerabilities that may impact global ICT environment and diplomatic operations. The successful candidate will work closely with cyber security operations, application delivery teams, infrastructure teams, and external partners to reduce cyber risk and uplift secure by design practices across the department.
Job details
The Cyber Threat and Vulnerability Management Section within the Cyber Security, Cloud and Networks Branch of Information Management and Technology Division has a requirement to fill the role Cyber Vulnerability Specialist to support the departments Vulnerability Management.The objective of this engagement is to provide specialist cyber security capability to identify, assess, prioritise, and communicate risk associated with vulnerabilities across ICT environment, including infrastructure, applications, and secure development pipelines.
The Cyber Vulnerability Specialist will provide contextualised, specific vulnerability assessments to support informed, risk‑based decision‑making and to protect the department’s diplomatic, operational, and mission‑critical functions in a rapidly evolving cyber threat landscape.
Key duties and responsibilities
The Cyber Vulnerability Specialist is responsible for identifying, analysing, and prioritising cyber security vulnerabilities across systems, applications, and development pipelines, and for providing actionable, risk‑based advice to stakeholders.
Technical skills
Relevant tertiary qualification in Cyber Security, Information Technology, Computer Science, or a related discipline, or equivalent demonstrated experience. / Industry certifications such as CISSP, GIAC, OSCP, or equivalent are desirable.
Essential criteria
- Demonstrated experience in cyber vulnerability management, including assessment and prioritisation of CVEs in complex enterprise environments.
- Proven ability to conduct risk based vulnerability assessments and provide actionable security advice.
- Demonstrated proficiency with Tenable (specifically on-premises Tenable platforms) for vulnerability scanning, validation, and management.
- Demonstrated proficiency with Splunk for log analysis (including query scripting), event correlation, and cyber security investigations.
- Strong written and verbal communication skills, with the ability to translate technical cyber security issues into clear, decision ready advice.
- Experience working within Australian Government or highly regulated environments.
- Experience in application security (AppSec), including secure development pipelines and application layer vulnerabilities.
- Experience assessing software supply chain and open source dependency risks.
- Familiarity with secure CI/CD pipelines and DevSecOps practices.
- Experience engaging with senior stakeholders and contributing to cyber security governance processes.
Contract: 12 Months Contract with 2 x 12 month extensions
Security Required: NV1 Security Clearance required
Location - Canberra
How to Apply - Please upload your resume to apply. Candidates will need to be willing to undergo pre-employment screening checks which may include, ID and work rights, security clearance verification and any other client requested checks
Closing date: Wednesday 12 August by 9am
Call Joanne Finchett on 0480 002454 or email Joanne@whizdom.com.au for any further information


