Information Security Specialist - Cybersecurity Posture Assurance
Job Description
Help protect one of Aotearoa's largest banks by strengthening how we manage security across our technology environment. Join a growing team where your expertise, ideas, and recommendations genuinely shape how we operate.
At ASB, we're a purpose-led organisation helping New Zealanders get one step ahead. Our cyber security teams play a critical role in keeping our customers, people, and systems safe. We're looking for an Information Security Specialist to join our Cyber Posture Assurance team in Auckland.
Mō te tīma About the Team
The Cybersecurity Posture Assurance (CPA) team sits within ASB's Cyber Security Practice and plays a key role in keeping our technology environment safe, resilient, and trusted. Formed as a dedicated squad out of the broader Cyber Assurance capability, the team focuses on how secure we are as an organisation overall, not just at an individual system level.
Our core focus is vulnerability management and secure configuration management across cloud, on-premises, and SaaS environments. This goes well beyond traditional server infrastructure - we cover containers, APIs, cloud resources, and more. The team owns and manages the security posture management tooling that platform teams across ASB rely on to understand and act on their findings.
You'll be joining a collaborative, diverse team that's still growing and shaping how it operates. Your recommendations are genuinely valued, and you'll have the opportunity to challenge the status quo and contribute to something meaningful.
Mō te Tūranga About the Role
As an Information Security Specialist in the CPA team, you'll be hands-on with security posture management tooling, assessing vulnerabilities and findings across ASB's technology environment. You'll investigate trends, triage issues, and work with teams across the business to drive findings through to resolution. The role is a mix of day-to-day operations and involvement in cyber uplift initiatives and projects, giving you broad exposure to different technologies and challenges.
Key responsibilities:
Assess and investigate vulnerability and security posture findings across cloud, on-premises, and SaaS environments
Monitor drift detection and security metrics, identifying and explaining changes in vulnerability trends
Triage findings to determine ownership and coordinate with platform and engineering teams to drive resolution
Follow through on findings end to end, maintaining visibility and accountability until issues are closed out
Respond to inquiries from across the business on vulnerability management, posture management, and secure configuration
Support secure configuration management and hardening across servers (Windows, Linux), containers, and cloud resources
Contribute to cyber uplift initiatives that strengthen ASB's vulnerability management and secure configuration controls
Collaborate with platform engineering, security advisory, and other technology teams on policy and settings changes
Support the onboarding of new systems and platforms to security posture management tooling
Ō Pūkenga About You
You're a security professional with solid hands-on experience in vulnerability management and a genuine interest in how organisations manage their security posture at scale. You're comfortable working across different technology environments and can move between cloud, on-premises, and SaaS with confidence. You enjoy investigating issues, working through complexity, and seeing things through to resolution.
You communicate clearly, build strong working relationships, and take ownership of your work. You're curious, open to new ideas, and keen to contribute to a team that values continuous improvement.
Key skills and experience:
Strong experience in vulnerability management across a range of environments, not limited to traditional server infrastructure
Understanding of security posture management concepts, including cloud security posture management (CSPM) and SaaS security posture management (SSPM)
Knowledge of secure configuration management and system hardening practices (Windows, Linux)
Familiarity with security posture management tooling and the ability to assess and interpret findings
Experience working across cloud and on-premises environments
Strong analytical skills with the ability to investigate, triage, and prioritise security findings
Clear communication skills and the ability to collaborate effectively with platform and engineering teams
A proactive mindset with a focus on continuous improvement
The following would be a strong advantage:
Experience with container security (e.g. Kubernetes, Docker)
Exposure to API security concepts and vulnerability triaging for APIs
Experience contributing to or leading cyber uplift initiatives
Te mahi ki ASB Working for ASB\
