686,059open jobs
39,814companies
97,494added this week
Browse all
Salary
$82k – $210k per year (Estimated)
Location
Remote/Hybrid (Sydney, Australia)
Seniority
Senior
Employment
Contractor
Overview
Company
Impact
Profile match
NCS Australia is the Australian arm of the Singapore technology services group NCS, itself owned by Singtel, and it was assembled from 2021 onwards through the acquisitions of ARQ Group, Eighty20 Solutions, Riley and several other local firms. It delivers cloud and platform engineering, data and artificial intelligence, cybersecurity, application development and managed services to Australian government agencies, banks, telecommunications operators and utilities. Headquartered in Sydney with offices across the eastern states, it employs several thousand people and competes against the global integrators for federal and state government work.

At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.

We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.

We are seeking a Security Analyst for an initial short-term contract engagement running from October through December 2026 with possible extensions in Sydney.

In this specialist technical role, you will be responsible for analyzing raw discovery data across our internet-facing infrastructure to build a validated, risk-actionable External Exposure Baseline. You will bridge technical discovery with risk governance-consolidating complex datasets, establishing asset ownership, prioritizing vulnerabilities, and embedding findings into our ongoing Exposure Management function.

Key Responsibilities

  • Attack Surface Data Analysis: Analyze large-scale external exposure datasets (IP addresses, domains, subdomains, VPN assets, cloud services, and edge infrastructure) to establish an authoritative external attack surface baseline.

  • Asset Discovery & Normalization: Consolidate, normalize, and de-duplicate asset discovery data from multiple internal and external discovery engines into a single source of truth.

  • Inventory Reconciliation & Ownership Mapping: Reconcile discovered external assets against internal registers to identify ownership gaps, rogue non-production environments, and unmanaged services.

  • Stakeholder Engagement: Collaborate across application, infrastructure, and business teams to validate technical relationships, business criticality, and operational status.

  • Risk Assessment & Prioritization: Evaluate findings to identify systemic control gaps, orphaned assets, and security risks-prioritizing remediation based on threat posture, business impact, and effort.

  • Treatment & Remediation Planning: Define clear treatment recommendations, including remediation actions, ownership assignment, risk acceptance, or asset decommissioning.

  • Documentation & Governance: Maintain audit-ready records of findings, decision rationale, ownership records, and evidence to support handover to ongoing operational teams.

  • Executive Reporting: Deliver clear reporting and insights on exposure trends, remediation progress, and systemic control issues for senior cybersecurity leadership.

  • Cyber Security & Exposure Analysis: Proven track record as a Security Analyst focusing on External Attack Surface Management (EASM), threat exposure, or vulnerability risk analysis.

  • Data Manipulation & Reconciliation: Strong capability to consolidate, query, and de-duplicate large, complex technical datasets from multiple security scanning platforms.

  • Asset & Risk Governance: Deep understanding of enterprise inventory management, asset discovery lifecycle, and threat modeling frameworks.

  • Network & Infrastructure Security: Technical knowledge of IP routing, DNS, domain management, SSL/TLS, VPN architectures, and public cloud infrastructure (GCP/AWS/Azure).

  • Stakeholder Influence: Excellent communication skills to coordinate with technical owners, drive asset attribution, and negotiate remediation actions.

  • Availability & Location: Sydney-based and available to commence the engagement in October 2026.

Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own. We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We'd love to hear from you.

We celebrate diversity and inclusion

We value different perspectives, experiences and strengths our people bring. We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
686,059 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sydney
$22k – $57k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Gurgaon • Chennai • Bengaluru
Python
Java
C++
C++
TensorFlow C++
PyTorch C++
Databases
Pinecone
FAISS
AI/ML
LangChain
Vertex AI
Fine-tuning
Embeddings
NLP
AWS Bedrock
Transformers
TensorFlow
PyTorch
RAG
OpenAI
Hugging Face
Amazon SageMaker
DevOps
GCP
GitHub Actions
Azure
CI/CD
Jenkins
Git
AWS
Docker
Kubernetes
AWS Lambda
Vector
Apply
$17k – $39k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Pune
Java
SQL
Java
Maven
Spring Boot
Hibernate
Gradle
Databases
MySQL
Oracle
Cassandra
DevOps
Rest API
GCP
Azure DevOps
New Relic
Azure
CI/CD
Jenkins
Git
AWS
Docker
Kubernetes
AppDynamics
API Gateway
Management
Jira
Agile
Scrum
Apply
$142k – $213k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Jersey City
Python
Java
SQL
Java
Spring Framework
Spring Boot
Spring Cloud
Databases
Snowflake
Databricks
Apache Iceberg
Delta Lake
Apache Kafka
AI/ML
Flink
DevOps
GCP
Azure
AWS
Docker
Kubernetes
Management
Agile
Apply
$86k – $221k per year (Estimated) • In office • Internship • Bachelor's Degree • Overland Park
SQL
DevOps
CloudFormation
Azure
AWS
Cybersecurity
HIPAA
Apply
$97k – $226k per year (Estimated) • In office • Full-Time • 5+ years exp • Singapore
AI/ML
Red Teaming
DevOps
Azure
AWS
SLI/SLO/SLA
Cybersecurity
Microsoft Sentinel
ISO 27001
MITRE ATT&CK
NIST CSF
Apply
$93k – $180k per year (Estimated) • Remote/Hybrid • Contractor • Melbourne
DevOps
Rest API
Azure
CI/CD
Apply
$98k – $222k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Sydney
Management
Agile
Apply
$79k – $203k per year (Estimated) • In office • Contractor • Sydney
DevOps
CI/CD
Shift-Left
Cybersecurity
OWASP Top 10
Shift-Left Security
Management
Agile
Scrum
Apply
$82k – $208k per year (Estimated) • Remote/Hybrid • Contractor • Melbourne
Python
AI/ML
LLM
LLM Guardrails
NIST AI RMF
Agentic Workflows
DevOps
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Shift-Left
Cybersecurity
OWASP Top 10
Shift-Left Security
Threat Modeling
Apply
$80k – $206k per year (Estimated) • Remote/Hybrid • Contractor • Sydney
Python
AI/ML
LLM
LLM Guardrails
NIST AI RMF
Agentic Workflows
DevOps
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Shift-Left
Cybersecurity
OWASP Top 10
Shift-Left Security
Threat Modeling
Apply
In office • Full-Time • 4+ years exp • Sydney • Melbourne
Apply
$81k – $177k per year (Estimated) • In office • Full-Time • 5+ years exp • Sydney
Apply
$37k – $81k per year (Estimated) • Remote/Hybrid • 2+ years exp • Bachelor's Degree • Sydney
Apply
Remote/Hybrid • Full-Time • Sydney
AI/ML
AI Agents
Design
Canva
Apply
$78k – $155k per year (Estimated) • Remote/Hybrid • Sydney
Apply
See all jobs
This is one of many
686,059 more open roles from verified company boards, updated every day.