Talent.com
XPT Software Australia Pty Ltd
Security Testing Lead SpecialistXPT Software Australia Pty Ltd • Sydney, VIC, au
Security Testing Lead Specialist

Security Testing Lead Specialist

XPT Software Australia Pty Ltd • Sydney, VIC, au
11 days ago
Job description
Job Description

Security Testing Lead Specialist

Key Accountabilities Include

· Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

· Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

· Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

· Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

· Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.

· Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

· Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

· Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.

· Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

· Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

· Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

· Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.

Additional Information

· Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

· Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

· Develop and deliver training for junior team members and the broader community to uplift security capability.

· Promote shift-left practices to enable the delivery of secure, high-quality code at speed.

· Provide guidance on application security architecture and secure design considerations.

· Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

· Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

· Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

· Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

· Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.

· Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

· Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.

Qualifications / Experiences

Essential

· A minimum of 8 years’ experience in a Security Testing role

· Experience and exposure to a variety of software delivery models, including DevOps and Waterfall

· Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment

· Significant experience in implementing automated security assessment tools into CI/CD pipelines

· Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.

· Ability to review and provide guidance and feedback on security assessment reports

· Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring.

· Experience in training and developing people

· Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline

· Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.

Highly Desirable

· Prior experience as a developer / software engineer is a significant advantage.

· Experience in developing security policy, standards, and development guidelines

· Significant experience in other domain areas of Cyber Security

· A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.

· Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP

· Experience in managing engagements with external security vendors

· Demonstrable history of developing exploits and zero-day discovery




Requirements
Security Testing Lead Specialist Key Accountabilities Include • Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development. • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities. • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience. • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately. • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation. • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function. • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction. • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity. • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations. • Provide mentorship and technical guidance to uplift capability across both senior and junior team members. • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints. • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements. Additional Information • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements. • Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans. • Develop and deliver training for junior team members and the broader community to uplift security capability. • Promote shift-left practices to enable the delivery of secure, high-quality code at speed. • Provide guidance on application security architecture and secure design considerations. • Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities. • Refine and define engagement processes, secure code artefacts, security criteria, and use cases. • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices. • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards. • Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations. • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations. Qualifications / Experiences Essential • A minimum of 8 years’ experience in a Security Testing role • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment • Significant experience in implementing automated security assessment tools into CI/CD pipelines • Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools. • Ability to review and provide guidance and feedback on security assessment reports • Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring. • Experience in training and developing people • Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline • Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.
Create a job alert for this search

Security Testing Lead Specialist • Sydney, VIC, au

Similar jobs

Cyber Security Service Delivery Lead

Tata Consultancy ServicesSydney, AU

Join Tata Consultancy Services, Asia Pacific and be part of an organization committed to sustainable development for our future.TCS follows the Tata group philosophy of building sustainable busines... Show more

 • Promoted

Cyber Engineering Security Specialist

Tpg TelecomBarangaroo, NSW, AU

Bring your ‘you’ to TPG Telecom, and help us build meaningful relationships and support vibrant, connected communities.We’re better and bolder together.TPG Telecom started with a belief that we can... Show more

Cyber Security Operations Lead

Kapital ConsultingSydney, AU

We are partnering with a global financial services organization as they continue to mature and modernise their cyber security operations capability.This newly shaped SOC Lead role will play a criti... Show more

 • Promoted

SAP Security Lead

Infosys LimitedSydney, AU

Flexible working arrangements:.Feel free to connect with your recruiter to learn more.Lead and manage SAP Security activities across S/4HANA implementation, upgrade, and support programs.Design, bu... Show more

 • Promoted

Cyber Security Optimisation Lead - IAM & PAM

AdactinSydney, AU

A leading cybersecurity firm is seeking a Senior Cyber Security Analyst to join their team in New South Wales.The role involves working on Cyber Security Optimisation projects, including Identity A... Show more

 • Promoted

Cyber Security Internal Audit Lead

Macquarie Bank LimitedSydney, AU

Macquarie Bank Limited in Sydney is seeking an Internal Audit Manager specializing in Cyber Security Risk to assess cyber security risk management.You will execute audits to identify risks and desi... Show more

 • Promoted

Test Lead

WhizdomSydney, AU

Whizdom Sydney, New South Wales, Australia.Join or sign in to find your next job.Whizdom Sydney, New South Wales, Australia.This range is provided by Whizdom.Your actual pay will be based on your s... Show more

 • Promoted

Security Sales Specialist

Data#3 LtdNorth Sydney, NSW, AU

Join our high-performing, expanding Security team, trusted by enterprise, government and commercial customers for over 45 years .Own and drive a growth strategy across all facets of our Security IC... Show more

Lead, Enterprise Security & Threat Modeling

black.aiSydney, AU

Security Team Leader to oversee their internal security strategy in Australia, New South Wales.This role requires managing engineering teams, balancing rigorous security protocols with user experie... Show more

 • Promoted

Strategic Security & Compliance Lead (Hybrid)

NSW Department of Customer ServiceSydney, AU

A government department in Australia is seeking a Senior Security and Compliance Analyst to coordinate security risk and compliance activities.This role includes managing the information security m... Show more

 • Promoted

Security Test Lead

Bupa AustraliaSydney, AU

At Bupa, purpose meets possible.Join us and help shape a future where healthcare is more connected, more personal and more human.We are a global healthcare leader trusted by millions and committed ... Show more

 • Promoted

Cyber Security Strategy & Uplift Lead

Inghams Group LimitedSydney, AU

A leading food company in Australia seeks a Senior Manager - Information & Cyber Security to oversee cyber security strategies and operations.The ideal candidate will have over 10 years of experien... Show more

 • Promoted

Senior Product Security Engineer

AirwallexSydney, NSW, AU

Airwallex is the only unified payments and financial platform for global businesses.Powered by our unique combination of proprietary infrastructure and software, we empower over 250,000 businesses ... Show more

Lead Penetration Tester

Decipher BureauSydney, AU

Cyber Security Specialist | AISA NSW Executive Committee | Helping Build Australia's Best Cyber Security Teams.Full-time role with competitive salary.Are you a Pen Tester, looking to be apart of so... Show more

 • Promoted

Deloitte Global | Penetration Tester

DeloitteSydney, NSW, AU

Exciting role as part of the Deloitte Global Technology team.Work within a forward thinking, dynamic and innovative business environment.Mentoring, coaching and leadership programs to help you make... Show more

Senior Specialist - Security Awareness

Woolworths GroupSydney, AU

Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.Develop and lead Woolworths Group's security awareness program.Innovate and deploy creative communicat... Show more

 • Promoted

Security Engineer (Azure AD)

Kaizen Global TechnologiesSydney, AU

Candidates must have the right to work in Australia.Design and implement secure IAM configurations in Microsoft Entra ID (Azure AD), including Conditional Access, MFA, PIM, RBAC, and identity lifec... Show more

 • Promoted

Security Engineer, Detection and Response

OpenAISydney, AU

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products.We are... Show more

 • Promoted

Enterprise Security - Team Lead

CanvaSydney, NSW, AU

The Security Group is responsible for protecting Canva systems and data from information security threats.The group runs programs across Application Security, Risk Management, Enterprise Security, ... Show more

Application Security Engineer: Secure SDLC & Cloud

Universal Music Australia Pty LimitedSydney, AU

Universal Music Australia Pty Limited is seeking a Tech Security Engineer to enhance the security posture of their applications and platforms.This role involves application security assessments and... Show more