Vulnerability Management Specialist

Decipher Bureau

Date: 6 days ago
City: Sydney, New South Wales
Salary: A$155,000 - A$175,000 / yr
Contract type: Full time

Vulnerability Management Specialist

Sydney | Permanent

We're working with a technology-led organisation looking for a Vulnerability Management Specialist to join their Cyber Security team.

This is an opportunity to work at the intersection of application security and engineering, helping teams understand which vulnerabilities pose genuine risk and where remediation efforts should be focused. Rather than relying solely on CVSS scores, you'll assess vulnerabilities in the context of the organisation's environment and provide practical, risk-based guidance to engineering teams.

Key Responsibilities

  • Research, triage and prioritise CVEs across applications, containers and software dependencies.
  • Assess exploitability using factors such as asset criticality, network exposure, dependency reachability and available exploits.
  • Provide practical remediation advice and support risk-based decision making.
  • Work with vulnerability scanning and Software Composition Analysis (SCA) tools across CI/CD pipelines.
  • Leverage GitHub Enterprise and GitHub Advanced Security tools, including Dependabot, CodeQL and Secret Scanning.
  • Help improve secure development practices by embedding security into engineering workflows.

Key Skills and Experience

We're looking for someone with experience in Vulnerability Management, Application Security or Product Security, along with:

  • Hands-on experience triaging CVEs across modern application environments.
  • Knowledge of dependency management across Java, npm, Go or Python.
  • Experience with Kubernetes, containers and cloud-native technologies.
  • Familiarity with CI/CD pipelines and developer security tooling such as GitHub Advanced Security.
  • The ability to communicate technical security risks clearly to both engineering and business stakeholders.

Nice to Have

  • Experience with software supply chain security or SBOMs.
  • Scripting skills in Python, Go or Bash.
  • Knowledge of Secure SDLC or threat modelling.

Why Join?

You'll be joining a collaborative cyber security team where you'll have the opportunity to influence how vulnerabilities are identified, prioritised and remediated across a modern technology environment. If you enjoy solving technical security challenges and working closely with engineering teams, we'd love to hear from you!

How to apply

Click Apply or reach out to for a confidential, informal conversation.

For employers only

Is this your company's job post? Verify ownership to manage this listing and receive applications directly.

Claim this listing

Looking to apply for this job? Use the Apply button above.