Logo-of-Xpt-Software-Australia-Pty-hiring-for-jobs-in-Australia-on-GrabJobs

Security Platform Engineer

Job Description - Security Platform Engineer

We are
looking for a hands on Cyber Security Platform Engineer to help deliver a new
security product across the Client environment.

Working
closely with the architect and product/Vendor SME, the successful candidate
will drive the technical implementation, coordinate agent deployments, and
manage firewall requirements, and work with various technology and cyber teams
to implement controls such as SSO, MFA etc. This role requires someone who can
work effectively with stakeholders across Client, taking the product to BAU.

 

Please see
attached JD.

Note:
 JD mentions runZero product – will be great if candidate has runZero
experience, if not we need the candidate to have experience with a comparable
product.

 

Platform engineering and configuration

  • Design and implement the runZero platform
    operating model, including environments, access, roles, boundaries, sites,
    asset groups, tags and naming standards.

  • Configure discovery coverage for corporate, data
    centre, cloud, remote access, network, IoT and relevant OT environments.

  • Design appropriate active scanning, passive
    discovery and integration patterns for different network zones and
    operational risk profiles.

  • Establish safe scanning standards, approval
    gates, maintenance windows and exception processes for sensitive or
    fragile environments.

  • Configure asset classification, ownership,
    business context, criticality and lifecycle attributes.

  • Define standards for handling transient,
    ephemeral, duplicate, decommissioned and unmanaged assets.

  • Develop reusable configuration patterns and
    templates that can be applied consistently across sites and environments.

  • Maintain a clear separation between production
    configuration, testing and experimental changes.

Integrations and data engineering

  • Integrate runZero with CMDB, ServiceNow, Tenable,
    EDR, NAC, DNS/DHCP, cloud platforms, identity systems, SIEM, SOAR and
    relevant infrastructure tools.

  • Implement API-based ingestion and egress patterns
    using secure service identities and least-privilege access.

  • Automate asset reconciliation, deduplication,
    enrichment, ownership mapping and data-quality checks.

  • Ensure downstream systems receive consistent,
    useful and appropriately scoped data rather than uncontrolled asset or
    alert noise.

  • Define integration contracts, schemas, field
    mappings, ownership, error handling, retry behaviour and support
    expectations.

  • Build mechanisms to detect integration drift,
    stale credentials, failed synchronisation and unexpected data-volume changes.

Automation and workflow engineering

  • Automate platform onboarding, configuration
    validation, scan scheduling, asset tagging, reporting and operational
    housekeeping.

  • Automate the routing of actionable exposures to
    the correct security, infrastructure, network, cloud or application
    owners.

  • Implement event-driven workflows for newly
    discovered assets, exposed services, control gaps, unauthorised devices
    and material changes.

  • Design idempotent automation that can be safely
    re-run without creating duplicate records, tickets or configuration drift.

  • Use APIs, webhooks, scripts and workflow
    platforms to reduce manual administration and improve response times.

  • Introduce approval controls for high-impact or
    potentially disruptive actions.

  • Create automated lifecycle handling for assets
    that are retired, renamed, moved, rebuilt or short-lived.

 

SRE and operations

  • Treat runZero configuration and operational
    processes as code wherever possible.

  • Establish version control, peer review, automated
    testing, release controls and rollback procedures for platform changes.

  • Define service-level indicators and objectives
    for discovery coverage, data freshness, integration health, scan success,
    alert delivery and remediation workflow reliability.

  • Implement dashboards and alerts that detect
    platform degradation before it affects consumers.

  • Create operational runbooks for common failures,
    including collector or explorer issues, scan failures, integration errors,
    data-quality problems and access failures.

  • Design backup, recovery, disaster-recovery and
    business-continuity procedures appropriate to the service.

  • Conduct capacity, performance and scale
    assessments as coverage expands across Client environments.

  • Manage credentials through approved enterprise
    secrets-management capabilities; do not embed secrets in scripts,
    repositories or configuration files.

  • Implement role-based access control,
    privileged-access controls, administrative separation and auditable change
    history.

  • Support security reviews, architecture reviews,
    privacy assessments, risk assessments and control assurance activities.

  • Ensure platform data handling, logging,
    retention, residency and third-party access align with client security and
    regulatory requirements.



Original job Security Platform Engineer posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar Security Platform Engineer Jobs in Australia

GrabJobs is the no1 job portal in Australia, connecting you to thousands of jobs fast! Find the best jobs in Australia, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.