Senior Security Analyst (Exposure Management) - South Bank, QLD
Job no: 531757
Work type: Full time
Location: Queensland
Categories: Digital and Technology

At Flight Centre Travel Group (FCTG) our purpose is to 'open up the world for those who want to see'. Every day, we give people all around the world the opportunity to experience something amazing – travel!
Are you passionate about transforming how organisations understand, prioritise, and reduce cyber risk?
As a Senior Security Analyst – Exposure Management, you will play a critical role in advancing FCTG’s vulnerability, attack surface, and technical exposure management capability. Working within the Security Posture & Intelligence team, you will drive the evolution of our security exposure programme, helping to align technical risk with business priorities and supporting strategic security outcomes.
This is an exciting opportunity to own and mature key security programmes while influencing enterprise-wide cyber resilience.
Day to day:
- Manage FCTG’s end-to-end exposure management programme
- Define vulnerability scanning scope and work with Security Engineering to ensure complete coverage, including external attack surface
- Review vulnerability scan outputs for quality, accuracy, and contextual risk relevance
- Enrich vulnerability findings with threat intelligence to improve prioritisation and remediation outcomes.
- Manage the vulnerability exception process using a consistent risk-based methodology.
- Escalate high-risk exceptions and significant exposures to senior security leadership.
- Perform root cause analysis to reduce recurring vulnerabilities and improve security posture.
- Maintain vulnerability management metrics, reporting, and trend analysis.
- Collaborate with technical teams to reduce vulnerabilities and improve security outcomes.
- Champion the transition to a Continuous Threat Exposure Management (CTEM) framework.
- Act as the primary operational liaison with FCTG’s Managed Security Service Provider (MSSP), monitoring performance and ensuring delivery against contractual obligations.
- Develop, maintain, and improve policies, standards, and procedures relating to exposure management.
- Produce technical exposure reporting for senior leadership, including the CISO and Board.
- Support internal and external penetration testing programmes.
- Contribute to cyber threat intelligence activities through analysis and reporting of emerging threats.
- Assist with risk management, mitigation, awareness, and training activities.
You'll be perfect for the role if you have:
- Degree in Computer Science, Information Security, or a related technical discipline, or equivalent practical experience
- 5–8 years of experience across vulnerability management, exposure management, or related security disciplines
- Demonstrated experience operating or governing an enterprise-scale vulnerability management programme
- Experience with attack surface management programmes and tooling
- Awareness of SAST and DAST tooling and application security findings
- Experience working with Managed Security Service Providers (MSSPs)
- Familiarity with MITRE ATT&CK and threat-informed security practices
- Tenable Certified Professional certification or equivalent vulnerability management certification
- Strong communication, stakeholder engagement, leadership, problem-solving, and analytical skills
What you'll enjoy:

#LI-KC1#LI#hybrid
Advertised: E. Australia Standard Time
Application close:
Apply now