Location: Sydney
Contract: 6 Months + Highly Likely Extensions
About the Opportunity
A leading technology consultancy is seeking an experienced Security Engineer to design, implement and operate an enterprise asset-discovery capability using runZero.
This is a hands-on engineering role combining platform configuration, security automation, systems integration and site reliability engineering. You will help establish a scalable operating model that delivers accurate asset visibility across corporate, data-centre, cloud, remote-access, network, IoT and relevant operational technology environments.
Key Responsibilities
- Design and implement the runZero operating model, including environments, access controls, roles, sites, asset groups, tags and naming standards.
- Configure discovery coverage across corporate, cloud, data-centre, remote-access, network, IoT and relevant OT environments.
- Develop active-scanning, passive-discovery and integration patterns suited to different network zones and operational risk profiles.
- Establish appropriate scanning standards, approval controls, maintenance windows and exception processes.
- Configure asset classification, ownership, business context, criticality and lifecycle information.
- Develop reusable configuration patterns and maintain separation between production, testing and experimental changes.
- Integrate runZero with enterprise platforms such as CMDB, ServiceNow, Tenable, EDR, NAC, DNS/DHCP, cloud services, identity systems, SIEM and SOAR.
- Implement secure API-based data ingestion and egress using service identities and least-privilege access.
- Automate asset reconciliation, deduplication, enrichment, ownership mapping and data-quality validation.
- Define integration contracts, schemas, field mappings, error handling, retry behaviour and support expectations.
- Build automated workflows for newly discovered assets, exposed services, control gaps, unauthorised devices and material changes.
- Use APIs, webhooks, scripts and workflow platforms to streamline administration and improve response times.
- Automate scan scheduling, configuration validation, asset tagging, reporting and lifecycle management.
- Design safe, repeatable automation that avoids duplicate records, tickets and configuration drift.
- Apply version control, peer review, automated testing, release controls and rollback procedures to platform changes.
- Establish service indicators, dashboards and alerts covering discovery coverage, data freshness, integration health, scanning and workflow reliability.
- Develop operational runbooks and support backup, recovery, disaster-recovery and business-continuity planning.
- Implement role-based access, privileged-access controls, administrative separation and auditable change history.
- Support architecture, security, privacy, risk and control-assurance reviews.
- Strong experience engineering and operating enterprise security or asset-discovery platforms.
- Practical expertise with runZero or a comparable asset-discovery and attack-surface visibility platform.
- Strong knowledge of active scanning, passive discovery and network-zone risk management.
- Experience integrating security platforms with CMDB, ServiceNow, vulnerability-management, endpoint, network, cloud, identity and SIEM/SOAR technologies.
- Demonstrated API, webhook, scripting and workflow-automation capability.
- Experience with asset reconciliation, deduplication, enrichment and data-quality controls.
- Sound understanding of least-privilege access, service identities, secrets management and role-based access control.
- Experience applying infrastructure-as-code or configuration-as-code practices, version control, testing and controlled releases.
- Strong operational knowledge across monitoring, alerting, incident runbooks, recovery, performance and capacity management.
- Experience supporting asset discovery across cloud, IoT or operational technology environments.
- Knowledge of ServiceNow, Tenable, EDR, NAC, DNS/DHCP, SIEM and SOAR integrations.
- Experience designing event-driven and idempotent automation.
- Familiarity with security architecture reviews, privacy assessments, risk assessments and regulatory control requirements.
- A technically challenging role with significant ownership of an enterprise security platform.
- The opportunity to build scalable discovery, integration and automation capabilities.
- Broad collaboration across security, infrastructure, network, cloud and application teams.
- A role spanning engineering delivery, automation, operational resilience and security governance.
If you are an experienced Security Engineer with strong asset-discovery, integration and automation capabilities, please apply with your latest CV or contact:
Farbar Siddiq
Recruitment Consultant
Email: farbars@whizdom.com.au
Phone: 0489 922 211


