Point your AI agent at freehire and let it find you a job.

Get the CLI →

Slattery Auctions

NewBe an early applicant

Lead Cybersecurity Analyst

Posted Updated
Discussion

Summary

Standalone security lead for Australia's largest family-owned auction company: owns day-to-day security operations (EDR, email security, DLP, firewalls, vulnerability and incident management), drives the ISO 27001:2022 programme and client/bank security assessments, and advises the business on risk and new tech. Hands-on with Microsoft 365/Entra, Fortinet, Bitdefender, Proofpoint, Forcepoint and A

About us

Slattery Grays Auctions is proudly Australia's largest national family-owned auction company, a leading auction and valuation practice. With over 15 sites across Australia, we specialise in automotive, road transport, earthmoving, mining, marine, and aviation asset advisory and disposal services. Our diversity, flexibility, and specialist experience set us apart, and clients appreciate our transparency, honesty, and integrity.

Slattery Grays is revolutionising how assets are sold with great success and is a strong leader in eCommerce which continues to grow. Our results are achieved through our great team - with the mantra Leave it with Us, we are invested in working together to make things happen.

About the role

This is the security role for the business. You will not be one analyst in a SOC working a queue; you will be the person who owns security day to day, reporting to the Head of IT, with the scope and visibility that comes with that.

The work splits roughly three ways. You will run our security operations, the tooling, the monitoring, the vulnerabilities, the incidents. You will drive our compliance and assurance obligations, including maintaining our ISO 27001:2022 programme and the client security assessments that underpin our banking relationships. You will advise the business, bringing security into decisions about new systems, new suppliers and new technology before those decisions are made rather than after.

The role suits someone who has outgrown a purely operational security position and wants ownership, but who still wants to stay hands-on with the technology.

What you'll do

Security operations

  • Own and operate our security tooling day to day: endpoint protection and EDR, email security, DLP, and firewall estate
  • Tune policies, manage exclusions and quarantines, and close coverage gaps
  • Run vulnerability and network scanning across servers, endpoints and our external attack surface, and drive remediation to agreed SLAs by severity
  • Own patch management and track compliance
  • Coordinate annual penetration testing and manage findings through to closure

Incident response

  • Own the incident response process end to end: detection, containment, eradication, recovery
  • Establish and maintain IR playbooks, and run tabletop exercises
  • Conduct root cause analysis and produce incident reports for management and, where required, clients
  • Understand and operationalise Australian reporting obligations, including ransomware payment reporting under the Cyber Security Act 2024 and notifiable data breach obligations under the Privacy Act

Compliance and assurance

  • Act as the principal contributor to our ISO 27001:2022 programme, working alongside control owners across the business
  • Maintain the risk register, Statement of Applicability, and corrective actions
  • Prepare for and support surveillance, recertification and internal audits, including gathering evidence from teams across the business
  • Own the security policy set: review cycle, versioning, approval and communication
  • Establish and maintain data classification across customer, bidder and payment data, and the handling rules that follow from it
  • Complete client and partner security assessments, including bank third-party reviews and industry questionnaires, and maintain a standing evidence pack.

Risk and third-party security

  • Maintain the cyber risk register, assess risk on new systems and projects, and propose treatment plans
  • Present risk to the business with options and consequences clearly articulated risk acceptance decisions sit with the business, and your role is to inform them
  • Monitor, review and assess suppliers and service providers for security and data protection risk
  • Conduct pre-contract due diligence and periodic reassessment on a risk-based cycle
  • Input to security terms in supplier contracts, and manage supplier offboarding
  • Support cyber insurance renewals, including completing insurer questionnaires and evidencing the controls insurers require

Identity and access

  • Own identity security across Microsoft Entra: MFA, conditional access, privileged access
  • Run periodic user and privileged access reviews

Resilience

  • Contribute to business continuity and disaster recovery planning, testing and evidence
  • Assure the security of our backup estate, including immutability, access controls and restore testing
  • Work with the business to define and validate recovery objectives

Governance and reporting

  • Set the agenda for the monthly Security Review meeting, chaired by the Head of IT, and drive actions through to closure
  • Produce monthly security metrics and commentary that feed management and board reporting
  • Report on risk posture, programme delivery and compliance status

Advisory and horizon scanning

  • Provide security input into projects, new systems, integrations and architecture decisions, including our platform unification programme
  • Evaluate emerging security technologies, build the business case, and make objective recommendations
  • Track regulatory and standards developments relevant to our business and bring them to the business proactively
  • Support secure development practices with our internal engineering teams
  • Contribute to AI governance as our internal AI capability grows

Security awareness

  • Own our security awareness programme, including training and phishing simulation
  • Target interventions where the human risk data shows they are needed

Your first 90 days

First 30 days.

Get to know the estate, the tooling and the people. Understand where our controls genuinely stand versus where the documentation says they stand and meet the teams across the business whose evidence and cooperation you'll rely on.

By 60 days.

Have your own view of our risk position, backed by a gap assessment you've run rather than inherited. Take ownership of the risk register and the supplier assurance cycle.

By 90 days.

Be running the Security Review agenda, producing the monthly reporting pack, and leading a client security assessment end to end. Have a prioritised remediation plan in front of the executive with your recommendations on it.

What you'll bring

Essential

  • 5+ years in a cyber security role, with demonstrable ownership of security operations rather than tier-one alert handling
  • Hands-on experience with ISO 27001, including audit preparation, evidence collection and working with control owners outside your own team
  • Practical experience across endpoint protection/EDR, email security, DLP and firewalls
  • Vulnerability management, scanning, prioritisation and driving remediation through other teams
  • Incident response experience, including running an investigation and writing it up for a non-technical audience
  • Microsoft 365 and Entra security conditional access, MFA, privileged identity
  • Strong written communication. You will write policies, incident reports, audit responses and board material
  • Comfort working autonomously. This is a standalone role in a small IT team; you will need to prioritise your own work and see projects through without close supervision

Highly desirable

  • Experience responding to third-party security assessments from banks or financial institutions
  • AWS security IAM, posture management, secrets and key management
  • Familiarity with the current Australian regulatory landscape: Privacy Act (including the automated decision-making transparency obligations commencing 10 December 2026), the Cyber Security Act 2024, the Essential Eight, target maturity level 2, and the security expectations flowing down from APRA-regulated clients under CPS 234 and CPS 230
  • Exposure to PCI DSS
  • Exposure to a SIEM solution. Logging and detection engineering.
  • Relevant certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISSP or CISM, not required, but a bonus
  • Experience with our stack: Fortinet, Bitdefender, Proofpoint, Forcepoint, Salesforce, Meraki, Kaseya
  • Experience in a multi-site business with warehouse, yard or non-office environments
  • Interest in AI governance and emerging standards such as ISO 42001

What we're not asking for

You do not need to have done every one of the above. We would rather hire someone strong across security operations, ISO compliance and stakeholder communication who is willing to grow into the rest, than someone who ticks every box on paper.

Why this role

  1. Genuine ownership. You will set the security agenda here, not inherit someone else's.
  2. Visibility. Your work is directly visible to our executive and to some of Australia's largest financial institutions.
  3. Breadth. Compliance, operations, cloud, architecture and advisory in one role — rare at this level.
  4. Investment. We are actively spending on security uplift, with executive support behind it.

To apply

Please submit your CV and a short covering note telling us about a security programme or project you have owned end to end — what you inherited, what you changed, and how you knew it worked.

Slattery Grays is an equal opportunity employer. We welcome applications from candidates of all backgrounds.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available