Security Engineer - Controls & Validation

Whizdom ·whizdom.shazamme.com

Location Melbourne, Victoria, Australia
Type Full time
Level Mid
Source Shazamme
Information & Communication Technology (ICT)
Apply direct
Security Controls Validation Engineer

Melbourne | Contract Opportunity

About the Company

Our client is a leading technology and consulting organisation delivering security and digital transformation services to major Australian enterprises. They partner with large, complex organisations to strengthen cyber security capabilities, improve risk management practices, and enhance operational resilience.

About the End Client

You will be supporting a highly recognised enterprise operating critical technology environments across Australia. The organisation is investing heavily in cyber security, vulnerability management, and security control effectiveness initiatives.

The Opportunity

We are seeking an experienced Security Controls Validation Engineer to join a high-performing cyber security team based in Melbourne. This is a hands-on role focused on assessing security controls, identifying vulnerabilities, validating remediation activities, and working closely with infrastructure, endpoint, cloud, and application teams to improve the organisation's security posture.

The successful candidate will bring strong experience in vulnerability management, security control assessment, and enterprise security technologies, along with a practical approach to risk-based security recommendations.

Key Responsibilities

  • Conduct vulnerability assessments across servers, endpoints, and infrastructure environments.
  • Analyse security gaps and assess risk exposure across enterprise environments.
  • Validate the effectiveness of existing security controls and identify areas for improvement.
  • Work closely with infrastructure, endpoint security, cloud, and application teams to support remediation activities.
  • Re-test and validate remediation actions to ensure successful closure of security findings.
  • Support control validation exercises, attack simulations, and audit-related security assessments.
  • Deliver clear reporting and recommendations to technical and stakeholder audiences.
  • Contribute to vulnerability management lifecycle activities including prioritisation, tracking, and validation.
Required Skills & Experience

  • 5-10 years of relevant cyber security experience.
  • Strong experience in vulnerability management and security control validation.
  • Sound understanding of enterprise security controls, endpoint security, and infrastructure security principles.
  • Experience analysing vulnerability data and prioritising remediation activities based on risk.
  • Working knowledge of security frameworks including NIST and Essential Eight. ,
  • Strong stakeholder engagement, reporting, and communication skills.
  • Ability to work effectively across multiple technical teams.
Technical Environment

Experience with any of the following technologies will be highly regarded:

  • Microsoft Defender for Endpoint (MDE)
  • Rapid7 InsightVM or similar vulnerability management platforms
  • Trellix ePO / Application Control (AWL)
  • Enterprise endpoint security technologies
  • Windows and Linux server environments
  • Splunk or similar SIEM platforms (advantageous)
Desirable Experience

  • Experience working within large enterprise environments.
  • Exposure to cloud security and hybrid infrastructure environments.
  • Scripting or automation skills using PowerShell, Python, or Bash.
  • Security operations or incident response exposure.
What's on Offer

  • Opportunity to work on large-scale enterprise security initiatives.
  • Exposure to modern cyber security tools and frameworks.
  • Collaborative and highly skilled technical environment.
  • Contract opportunity with a strong focus on security outcomes and continuous improvement.
How to Apply

If you have strong experience in vulnerability management, security control validation, and enterprise security operations, we'd love to hear from you.

Farbar Siddiq
๐Ÿ“ง farbars@whizdom.com.au
๐Ÿ“ฑ 0489 922 211

Please submit your CV for immediate consideration.

Frequently asked questions

Who is hiring for the Security Engineer - Controls & Validation role?
Whizdom is hiring for the Security Engineer - Controls & Validation position, a Shazamme client. Apply directly on the employer's career site.
Where is the Security Engineer - Controls & Validation job located?
The Security Engineer - Controls & Validation role with Whizdom is based in Melbourne, VIC, AU.
Is the Security Engineer - Controls & Validation role full-time or contract?
This is a full time position at Whizdom.
What experience level is the Security Engineer - Controls & Validation role?
The Security Engineer - Controls & Validation position is aimed at mid-level candidates.
How do I apply for the Security Engineer - Controls & Validation role at Whizdom?
Apply directly on Whizdom's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS โ€” no third-party form, no resume database.
Apply direct