Expoint - all jobs in one place

Finding the best job has never been easier

Limitless High-tech career opportunities - Expoint

EY Threat Exposure Management Senior Manager 
Australia, Victoria, Melbourne 
515168364

02.12.2024

Threat Exposure Management Senior Manager

We bring together extraordinary people, like you, to build a better working world.

As a Senior Manager in our cybersecurity practice you will lead on client engagements, ensure effective stakeholder engagement and team management to deliver exceptional client experience. As an expert in threat exposure management, you will be able to speak with authority in the security industry and use that voice to drive practice growth.

Your key responsibilities

  • Lead and develop EY’s threat exposure management offerings.
  • Help clients reduce cyber risk by providing solutions for proactively monitoring for internal and external threats and vulnerabilities and advising on mitigating them.
  • Be the expert in threat intelligence, vulnerability intelligence, vulnerability management, threat hunting and threat analytics.
  • Establish and help clients operate a prioritization framework for vulnerability management and governance.
  • Lead engagements to ensure a rapid response to high-risk vulnerabilities.
  • Provide consultation on projects to improve the data quality of asset management tools.
  • Continually improve the vulnerability management offering, process and procedures and direct others as needed.

What we’re looking for

Here’s our ‘wish list’ but don’t worry if you don’t tick all the boxes. We’re interested in your strengths, what you want to learn, and how far you want to go.

  • Proven experience developing and managing a vulnerability management program or threat exposure management program at one or more organizations

  • Ability to deliver successful Cyber Security engagements both as an individual contributor and leader
  • Proven experience as a Cyber Security practitioner with the knowledge to provide industry best-practice advice to clients in the areas of threat detection, incident response, threat hunting and purple teaming
  • Experience with Information Security domains - in particular one or more of the following: Threat exposure management, Threat Detection & Response, and Breach Support. This experience should include both advisory and implementation experience.
  • Experience leading implementation and operations capability for security operations centres
  • Strong program / project delivery on major security uplift programs.
  • 7+ years’ experience in cybersecurity.
  • 3+ years leading vulnerability management or threat exposure management functions.
  • Experience in complex networks related to software patching and processes.
  • Experience in translating threat intelligence into business risk indicators.
  • Familiarity with modern technologies and security approaches i.e., cloud security.
  • Experience with leading and implementing vulnerability scanning and risk-based vulnerability management platforms.
  • Practical experience with security technologies such as firewalls, web and mail gateway filtering, AV, IDS/IPS, WAF, SIEM, FIM, IDAM, security monitoring, threat intelligence and security analytics.
  • Basic understanding of secure software development and related guidelines / standards (e.g., OWASP Top 10).
  • Ability to execute within an agile or waterfall project environment.

What we can offer you

  • Explore how a career at EY is yours to build at

  • Discover how, when and where you can work at

  • Learn about our commitment to DE&I at

  • Discover the various ways our benefits can cater to your needs, across wellness, financial wellbeing, and family-friendly policies which include 26 weeks gender neutral paid parental leave at

  • We offer a competitive salary which is open to negotiation pending on skills and experience.

Apply now… we’re over 9,000 perspectives in Australia and we’re ready to welcome yours.

Our preferred applicant will be required to undertake employment screening by EY or our external third-party provider.