Haystack
← Back to Jobs
Full time
Administrative

Senior Security Analyst (Exposure Management) - South Bank, QLD

StudentUniverseBrisbane, Queensland🇦🇺AustraliaPosted 24 Jul 2026

Quick Overview

Work Type
Hybrid
Schedule
Full Time
Level
Mid Senior

Job Description

Overview

Flight Centre Travel Group (FCTG) is looking for a Senior Security Analyst - Exposure Management to advance the organisations vulnerability, attack surface and technical exposure management capability. You will drive the evolution of the security exposure programme, align technical risk with business priorities, and support strategic security outcomes within the Security Posture & Intelligence team. This is an opportunity to own and mature key security programmes and influence enterprise-wide cyber resilience.

Responsibilities
  • Manage FCTG's end-to-end exposure management programme
  • Define vulnerability scanning scope and work with Security Engineering to ensure complete coverage, including external attack surface
  • Review vulnerability scan outputs for quality, accuracy, and contextual risk relevance
  • Enrich vulnerability findings with threat intelligence to improve prioritisation and remediation outcomes
  • Manage the vulnerability exception process using a consistent risk-based methodology
  • Escalate high-risk exceptions and significant exposures to senior security leadership
  • Perform root cause analysis to reduce recurring vulnerabilities and improve security posture
  • Maintain vulnerability management metrics, reporting, and trend analysis
  • Collaborate with technical teams to reduce vulnerabilities and improve security outcomes
  • Champion the transition to a Continuous Threat Exposure Management (CTEM) framework
  • Act as the primary operational liaison with FCTG's Managed Security Service Provider (MSSP), monitoring performance and ensuring delivery against contractual obligations
  • Develop, maintain, and improve policies, standards, and procedures relating to exposure management
  • Produce technical exposure reporting for senior leadership, including the CISO and Board
  • Support internal and external penetration testing programmes
  • Contribute to cyber threat intelligence activities through analysis and reporting of emerging threats
  • Assist with risk management, mitigation, awareness, and training activities
What you'll bring
  • Degree in Computer Science, Information Security, or a related technical discipline, or equivalent practical experience
  • 5-8 years of experience across vulnerability management, exposure management, or related security disciplines
  • Experience operating or governing an enterprise-scale vulnerability management programme
  • Experience with attack surface management programmes and tooling
  • Awareness of SAST and DAST tooling and application security findings
  • Experience working with Managed Security Service Providers (MSSPs)
  • Familiarity with MITRE ATT&CK and threat-informed security practices
  • Tenable Certified Professional certification or equivalent vulnerability management certification
  • Strong communication, stakeholder engagement, leadership, problem-solving, and analytical skills
What you'll enjoy
  • Culture: inclusive company with a supportive team environment
  • Equal Opportunity Employer; encouraging applicants from Aboriginal and Torres Strait Islander peoples and other minority groups
  • Individualised Learning & Development pathway options
  • Access to LinkedIn Learning for ongoing skills development
  • Exclusive staff discounts with Australia's leading retailers
  • Travel discounts for family and friends
  • Career opportunities across a network of brands and businesses
  • Health discount programs and employee assistance resources
  • Regular social events and opportunities to attend industry conferences
  • Corporate social responsibility programs and paid parental leave
  • Sustainability initiatives and commitment to reconciliation through the Reconciliation Action Plan
Applications

Applications close: (date not specified)

Similar jobs