Talent.com
XPT Software Australia Pty Ltd
Security Testing Lead SpecialistXPT Software Australia Pty Ltd • Melbourne, VIC, au
Security Testing Lead Specialist

Security Testing Lead Specialist

XPT Software Australia Pty Ltd • Melbourne, VIC, au
11 days ago
Job type
  • Quick Apply
Job description
Job Description

Security Testing Lead Specialist

Key Accountabilities Include

· Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

· Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

· Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

· Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

· Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.

· Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

· Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

· Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.

· Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

· Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

· Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

· Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.

Additional Information

· Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

· Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

· Develop and deliver training for junior team members and the broader community to uplift security capability.

· Promote shift-left practices to enable the delivery of secure, high-quality code at speed.

· Provide guidance on application security architecture and secure design considerations.

· Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

· Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

· Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

· Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

· Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.

· Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

· Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.

Qualifications / Experiences

Essential

· A minimum of 8 years’ experience in a Security Testing role

· Experience and exposure to a variety of software delivery models, including DevOps and Waterfall

· Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment

· Significant experience in implementing automated security assessment tools into CI/CD pipelines

· Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.

· Ability to review and provide guidance and feedback on security assessment reports

· Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring.

· Experience in training and developing people

· Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline

· Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.

Highly Desirable

· Prior experience as a developer / software engineer is a significant advantage.

· Experience in developing security policy, standards, and development guidelines

· Significant experience in other domain areas of Cyber Security

· A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.

· Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP

· Experience in managing engagements with external security vendors

· Demonstrable history of developing exploits and zero-day discovery




Requirements
Security Testing Lead Specialist Key Accountabilities Include • Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development. • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities. • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience. • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately. • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation. • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function. • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction. • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity. • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations. • Provide mentorship and technical guidance to uplift capability across both senior and junior team members. • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints. • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements. Additional Information • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements. • Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans. • Develop and deliver training for junior team members and the broader community to uplift security capability. • Promote shift-left practices to enable the delivery of secure, high-quality code at speed. • Provide guidance on application security architecture and secure design considerations. • Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities. • Refine and define engagement processes, secure code artefacts, security criteria, and use cases. • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices. • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards. • Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations. • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations. Qualifications / Experiences Essential • A minimum of 8 years’ experience in a Security Testing role • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment • Significant experience in implementing automated security assessment tools into CI/CD pipelines • Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools. • Ability to review and provide guidance and feedback on security assessment reports • Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring. • Experience in training and developing people • Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline • Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.
Create a job alert for this search

Security Testing Lead Specialist • Melbourne, VIC, au

Similar jobs

Cyber Security Consultant

Nova GroupMelbourne, VIC, AU

Voted #8 in Best Places to Work 2024 .Australian owned and operated .Location – Melbourne or Adelaide .An opportunity now exists for a highly motivated and skilled.Professional Services & Advis... Show more

Looking For Part-Time Work? - Deliver with Uber Eats

Uber eatsBroadford, VIC, AU

Start Delivering with Uber Eats.Delivering with Uber Eats is an alternative to a part-time or full-time job and you can get your earnings weekly.Delivering with Uber Eats allows you to earn quick c... Show more

 • Promoted

Cyber Security Risk Manager

Beyond Bank AustraliaMelbourne, VIC, AU

Full time (75 hours per fortnight).Be part of Beyond Bank-a bank that is for and with you.We are one of Australia's largest, 100% member owned mutual banks with a credit union heritage.With more th... Show more

Senior Acurity Developer

UniSuperMelbourne, VIC, AU

At UniSuper, we’re here to deliver strong retirement outcomes for our members.As one of Australia’s largest super funds, we combine long term thinking with a focus on innovation, performance and co... Show more

Electronic Security Technician

1305 Chubb Fire & Security Pty LtdDingley Village, VIC, AU

Electronic Security Technician.Due to continued growth and market presence Chubb Security has a current opening for an Electronic Security Technician within the Services area of the business.This i... Show more

Capture Lead

TESSERENTMelbourne, VIC, AU

At Thales, we know technology has the ability to make our world more secure, sustainable, and inclusive – and that it’s all driven by human intelligence.Because it takes human intelligence to build... Show more

Training & Development Lead

Brotherhood of St LaurenceFrankston, VIC, AU

Training & Development Lead.An exciting full-time opportunity in Frankston for someone ready to support capability, compliance and drive high-quality learning across Community Care.Salary packa... Show more

Remote Game Tester

BabkiFrankston, Victoria, Australia
Remote

Become a Professional Game Tester.We're looking for passionate gamers to join our elite team of mobile game testers.Get paid to play and test the latest games before they launch.This opportunity is... Show more

 • Promoted

Test Lead

MECCA Brands Pty LtdRichmond, VIC, AU

As MECCA continues to grow and evolve our Core Technology landscape, we’re looking for an experienced Test Lead to join our team based at our Support Centre in Richmond, Victoria.This role plays a ... Show more

OT Security Engineer

JemenaMelbourne, VIC, AU

Help Protect the Technology That Powers Essential Energy Services.As our reliance on connected technology continues to grow, so does the importance of keeping critical systems secure, resilient and... Show more

Security Leader, Global Proserve Security

AmazonMelbourne, VIC, AU

Are you a security focused professional who loves working with others on helping them understand, assess and uplift their security capabilities? Are you excited about assisting others implement se... Show more

Deloitte Global | Penetration Tester

DeloitteMelbourne, VIC, AU

Exciting role as part of the Deloitte Global Technology team.Work within a forward thinking, dynamic and innovative business environment.Mentoring, coaching and leadership programs to help you make... Show more

Senior AWS Devops Engineer-Terraform, Security, Cloud delivery

Bluefin ResourcesMelbourne, VIC, AU

Newly created role to build a portfolio forecasting capability from the ground up!.Partner with Risk, Finance and senior leaders to influence lending strategy and growth.Forecast portfolio performa... Show more

Documentation/Quality Specialist

Evolve ScientificBraeside, VIC, AU

Well-established pharmaceutical company seeking a Documentation/Quality Specialist to join their team.Onsite, full-time hours (Mon-Fri).Based in South Eastern suburbs.Develop and evaluate quality a... Show more

Security Installation Technician

SECUREcorpMulgrave, VIC, AU

Securecorp Electronics is a leading provider of advanced electronic security solutions, protecting businesses, institutions, and residential properties across Australia.Known for our cutting-edge t... Show more

Market Research Associate - No Experience

Clubshop | USWallan, Victoria

Discover The System Surveoo That’s Helping Newbies Earn Daily.Turn your free time into daily earnings by answering simple surveys.No product or tech skills needed.Join For Free And Start Earn... Show more

Risk Lead

AGLMelbourne, VIC, AU

We've been proudly Aussie since 1837, always finding new ways to innovate in energy and essential services.Now, we're moving towards a sustainable future through electrification and investing in re... Show more

Cyber Security Specialist

Bega CheesePort Melbourne, VIC, AU

If you are curious & creative, invested in not only your own success but also the growth of others, and believe in building the Great Australian Food Company, then you might be the one for us!.... Show more

Security Technician

AustcorpMelbourne, VIC, AU

National leading business with an exciting opportunity to join a close knit team as an Electronic Security Technician.We have various roles available - Service, Install, Projects all available.They... Show more

Team Lead

GentrackMelbourne, VIC, AU

As the SE – Team Lead, you will be responsible for outcomes of delivery/engineering for the team.You are a leader, comfortable with managing software development and delivery, continually reviewing... Show more