Talent.com
XPT Software Australia Pty Ltd
Security Testing Lead SpecialistXPT Software Australia Pty Ltd • Perth, VIC, au
Security Testing Lead Specialist

Security Testing Lead Specialist

XPT Software Australia Pty Ltd • Perth, VIC, au
11 days ago
Job description
Job Description

Security Testing Lead Specialist

Key Accountabilities Include

· Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

· Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

· Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

· Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

· Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.

· Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

· Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

· Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.

· Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

· Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

· Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

· Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.

Additional Information

· Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

· Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

· Develop and deliver training for junior team members and the broader community to uplift security capability.

· Promote shift-left practices to enable the delivery of secure, high-quality code at speed.

· Provide guidance on application security architecture and secure design considerations.

· Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

· Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

· Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

· Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

· Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.

· Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

· Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.

Qualifications / Experiences

Essential

· A minimum of 8 years’ experience in a Security Testing role

· Experience and exposure to a variety of software delivery models, including DevOps and Waterfall

· Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment

· Significant experience in implementing automated security assessment tools into CI/CD pipelines

· Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.

· Ability to review and provide guidance and feedback on security assessment reports

· Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring.

· Experience in training and developing people

· Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline

· Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.

Highly Desirable

· Prior experience as a developer / software engineer is a significant advantage.

· Experience in developing security policy, standards, and development guidelines

· Significant experience in other domain areas of Cyber Security

· A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.

· Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP

· Experience in managing engagements with external security vendors

· Demonstrable history of developing exploits and zero-day discovery




Requirements
Security Testing Lead Specialist Key Accountabilities Include • Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development. • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities. • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience. • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately. • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation. • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function. • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction. • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity. • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations. • Provide mentorship and technical guidance to uplift capability across both senior and junior team members. • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints. • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements. Additional Information • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements. • Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans. • Develop and deliver training for junior team members and the broader community to uplift security capability. • Promote shift-left practices to enable the delivery of secure, high-quality code at speed. • Provide guidance on application security architecture and secure design considerations. • Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities. • Refine and define engagement processes, secure code artefacts, security criteria, and use cases. • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices. • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards. • Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations. • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations. Qualifications / Experiences Essential • A minimum of 8 years’ experience in a Security Testing role • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment • Significant experience in implementing automated security assessment tools into CI/CD pipelines • Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools. • Ability to review and provide guidance and feedback on security assessment reports • Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring. • Experience in training and developing people • Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline • Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.
Create a job alert for this search

Security Testing Lead Specialist • Perth, VIC, au

Similar jobs

Project Control Specialist

AgilitusPerth, AU

We have an exciting opportunity for a Project Controls Specialist to join our Perth team.As our client portfolio grows across the resources, energy and industrial sectors, this position will help s... Show more

 • Promoted

Discreet Cash In Transit Operator | Armed Security

Armaguard GroupPerth, AU

Discreet Services Operator | Cash In Transit | Armed Security | Linfox Armaguard Group.Since 1938, Linfox Armaguard Group has built a trusted legacy in secure logistics and technology solutions.Fol... Show more

 • Promoted

Technical Training Specialist

AurizonPerth, AU

Join or sign in to find your next job.Continue with Google Continue with Google.Be among the first 25 applicants.We are seeking an experienced Technical Training Specialist to develop and implement... Show more

 • Promoted

ISO27001 Compliance & Information Security Analyst

APMPerth, AU

APM is a global health and human services organisation committed to enabling better lives.We are seeking an experienced Compliance Analyst to join our Risk & Compliance function, ensuring our techn... Show more

 • Promoted

Senior Cyber Security Engineer

DeloittePerth, WA, AU

Technical resource to help uplift endpoint security and Essential Eight maturity across Deloitte's enterprise environment, with hands-on influence over controls, tooling and emerging AI risk.Tackle... Show more

Discreet Services Operator | Cash In Transit | Armed Security | Linfox Armaguard Group

Armaguard GroupPerth, AU

Discreet Services Operator | Cash In Transit | Armed Security | Linfox Armaguard Group.Since 1938, Linfox Armaguard Group has built a trusted legacy in secure logistics and technology solutions.Fol... Show more

 • Promoted

Solutions Architect — Cloud, Networking & Security (Hybrid)

Epic ITPerth, AU

A leading IT services provider in Western Australia is seeking a Solutions Engineer to implement cloud environments, manage network hardware, and ensure security compliance.The ideal candidate will... Show more

 • Promoted

Python Automation Test Lead

Zone IT SolutionsPerth, AU

We are seeking an experienced Python Automation Test Lead based in Perth location.The Automation Test Engineer will have an understanding of testing robotics and/or control systems.Hands-on experie... Show more

 • Promoted

Principal Test Engineer: Incident & Integration Lead

Brightstar LotteryPerth, AU

Brightstar Lottery seeks a Principal Test Engineer in Perth to enhance the reliability and performance of complex lottery systems.This hybrid role requires hands-on testing and incident ownership, ... Show more

 • Promoted

Senior Electrical Incident Lead (HV/LV)

Western PowerPerth, AU

Western Power is seeking a Direct Response Network Specialist for Stirling Depot to provide senior on-site technical leadership during high-risk incidents and coordinate with DFES, WA Police and ot... Show more

 • Promoted

Lead Penetration Tester for Cloud & Apps Security

Commonwealth BankPerth, AU

Commonwealth Bank is seeking an experienced security professional to lead penetration testing across modern applications, cloud platforms and infrastructure.You will design, execute and report on h... Show more

 • Promoted

Security Engineer & Penetration Tester - SOC Expert

Red Piranha LimitedPerth, AU

Are you passionate about cybersecurity and penetration testing? Do you have a strong attention to detail and proven track-record of delivering results?.We are looking for a motivated Security Engin... Show more

 • Promoted

Cisco SDA Solution Architect: Migration & Security (Perth)

Pearson CarterPerth, AU

Pearson Carter is seeking an experienced Solution Architect in Perth to lead Cisco SDA migration projects.You will design secure and scalable architectures while providing technical leadership thro... Show more

 • Promoted

Airport Security Operations Lead

Perth Airport PtyPerth, AU

Perth Airport Pty is seeking a Security Operations Specialist in Perth, Tasmania, to oversee airport security operations and compliance.You'll be responsible for daily security activities, incident... Show more

 • Promoted

AI Technical Lead

XPT Software Australia Pty LtdPerth, AU

XPT Software Australia Pty Ltd | Contract.XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company.XPT works with topclients across Australia in Banking, Insurance, Telec... Show more

 • Promoted

Principal Consultant - Examination Security

Department of Education WAPerth, AU

Principal Consultant - Examination Security.Department of Education WA – Cannington WA.This is a nine (9) month fixed term, full-time position commencing ASAP with possible extension and/or permane... Show more

 • Promoted

Examination Security & Logistics Lead — Remote-Friendly

Department of Education WAPerth, AU
Remote

The Department of Education WA is seeking a Principal Consultant - Examination Security for a nine-month fixed term position based in Cannington, WA.This role involves developing and implementing p... Show more

 • Promoted

Penetration Tester / Security Engineer

Red Piranha LimitedPerth, AU

Are you passionate about cybersecurity and penetration testing? Do you have a strong attention to detail and proven track-record of delivering results?.We are looking for a motivated Security Engin... Show more

 • Promoted

TECHNICAL LEAD - NETWORK SECURITY

CyberCXPerth, WA, AU

We’re looking for an experienced Technical Lead – Network Security to join our Managed Security Engineering team.This is a senior, hands-on role suited to someone who enjoys solving complex problem... Show more

Direct Response Network Specialist

Western PowerPerth, AU

Direct Response Network Specialist – Permanent – Stirling Depot.This role provides senior on-site technical leadership during high-risk, multi-agency incidents to keep Western Power’s network opera... Show more