Engineer - Application Security, Vulnerability Management & Automation

Date:  3 Sept 2026
Location: 

Sydney, NSW, AU

Department:  Enabling Areas
Description: 

Job Requisition ID: 41843 

  • Take the next step in accelerating your career at Deloitte
  • Whether you're looking for a new role in your current Business Unit, a different BU or a move interstate, Pathways — our internal mobility program — can provide the framework to support you
  • This is an opportunity to use and further develop your automation and vulnerability management skills

 

What will your typical day look like?

Working across vulnerability management and application security, you'll guide initiatives that improve how risks are identified, prioritised and addressed across servers, workstations and applications. That could mean designing automation that removes manual effort, improving remediation workflows, or helping teams make better decisions through clearer reporting and triage.

A big part of the role is finding practical ways to apply AI in security operations. From exploring LLM and agent-based use cases to improving prioritisation, orchestration and decision support, you'll help turn emerging capability into meaningful operational uplift for security teams and platform owners.

Success in this role comes through coordination as much as technical capability. You'll work closely with security teams, platform owners and business stakeholders to keep initiatives moving, lift service maturity, and strengthen governance, metrics and continuous improvement across the function.

 

About the team

ITS Security helps protect Deloitte's internal technology environment so our people can do their best work with confidence. The team works across cyber operations, vulnerability management, application security and risk reduction, focusing on practical, scalable controls that strengthen resilience across the enterprise. It's a space where technical depth, good judgment and strong stakeholder collaboration come together to solve real security challenges.

 

Enough about us, let's talk about you

You may have all or some of the following skills/experiences:

  • Strong scripting and automation capability, including hands-on experience with Python and PowerShell
  • Experience improving security operations, vulnerability management, or application security processes
  • Knowledge of AI concepts, including LLMs, AI agents, and their practical use in operational environments
  • Familiarity with tools such as Qualys, Nessus, Checkmarx and Prisma
  • Understanding of development tools including version control systems (GitHub) and CI/CD pipelines (GitHub Action workflows).
  • Confidence working with stakeholders across security, platform and business teams to influence outcomes
  • Strong communication skills and the ability to guide initiatives, coordinate delivery, and drive continuous improvement
  • Experience with risk-based prioritisation, remediation workflows, reporting, or service governance would be highly regarded

 

Why consider internal opportunities?

  • To apply for an internal opportunity, you need to have worked with us on a permanent or fixed term basis for a minimum of one year
  • Ensure you have a conversation with your Career Coach before applying to any internal opportunities
  • You will also need a minimum rating of "On Track" in your most recent Year Ahead conversation

Recruitment Process

If shortlisted, a member of the Talent Acquisition team will be in touch to conduct an initial phone screening. Following this, you may be progressed through behavioural-based interviews which may include a case study.

 

Next Steps

Sound like the sort of role for you? Apply now!

 

#LI-Hybrid

#Linkedin

 

 

 

By applying for this job, you’ll be assessed against the Deloitte Talent Standards. We’ve designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.