Talent.com
XPT Software Australia Pty Ltd
Security Testing Lead SpecialistXPT Software Australia Pty Ltd • Perth, VIC, au
Security Testing Lead Specialist

Security Testing Lead Specialist

XPT Software Australia Pty Ltd • Perth, VIC, au
11 days ago
Job type
  • Quick Apply
Job description
Job Description

Security Testing Lead Specialist

Key Accountabilities Include

· Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

· Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

· Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

· Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

· Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.

· Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

· Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

· Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.

· Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

· Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

· Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

· Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.

Additional Information

· Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

· Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

· Develop and deliver training for junior team members and the broader community to uplift security capability.

· Promote shift-left practices to enable the delivery of secure, high-quality code at speed.

· Provide guidance on application security architecture and secure design considerations.

· Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

· Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

· Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

· Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

· Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.

· Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

· Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.

Qualifications / Experiences

Essential

· A minimum of 8 years’ experience in a Security Testing role

· Experience and exposure to a variety of software delivery models, including DevOps and Waterfall

· Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment

· Significant experience in implementing automated security assessment tools into CI/CD pipelines

· Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.

· Ability to review and provide guidance and feedback on security assessment reports

· Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring.

· Experience in training and developing people

· Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline

· Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.

Highly Desirable

· Prior experience as a developer / software engineer is a significant advantage.

· Experience in developing security policy, standards, and development guidelines

· Significant experience in other domain areas of Cyber Security

· A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.

· Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP

· Experience in managing engagements with external security vendors

· Demonstrable history of developing exploits and zero-day discovery




Requirements
Security Testing Lead Specialist Key Accountabilities Include • Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development. • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities. • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience. • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately. • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation. • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function. • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction. • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity. • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations. • Provide mentorship and technical guidance to uplift capability across both senior and junior team members. • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints. • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements. Additional Information • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements. • Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans. • Develop and deliver training for junior team members and the broader community to uplift security capability. • Promote shift-left practices to enable the delivery of secure, high-quality code at speed. • Provide guidance on application security architecture and secure design considerations. • Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities. • Refine and define engagement processes, secure code artefacts, security criteria, and use cases. • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices. • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards. • Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations. • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations. Qualifications / Experiences Essential • A minimum of 8 years’ experience in a Security Testing role • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment • Significant experience in implementing automated security assessment tools into CI/CD pipelines • Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools. • Ability to review and provide guidance and feedback on security assessment reports • Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring. • Experience in training and developing people • Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline • Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.
Create a job alert for this search

Security Testing Lead Specialist • Perth, VIC, au

Similar jobs

Expression of Interest - SMG Studio

Dentsu (ANZ) Management Services Pty LtdPerth, WA, AU

At SMG, we turn our patented DAFUZ system to create award winning titles including LEGO.We love building fun first games and we don’t take ourselves too seriously.If you're on top of your game (or ... Show more

Senior Cyber Security Engineer

DeloittePerth, WA, AU

Technical resource to help uplift endpoint security and Essential Eight maturity across Deloitte's enterprise environment, with hands-on influence over controls, tooling and emerging AI risk.Tackle... Show more

CONDITION MONITORING LEAD I PERTH

Bureau VeritasPerth, WA, AU

Created in 1828, Bureau Veritas is a world leader in laboratory testing, inspection and certification services.We have a vital role in maintaining quality, safety and environmental standards of cou... Show more

Veteran Employment - Security Roles on Defence Bases | No Experience Needed

Wilson SecurityPerth, WA, AU

Veteran Employment – Security Roles on Defence Bases | No Experience Needed.Permanent Full-Time Roles | $3,000+ Value | No Experience Needed.Are you a current or former ADF member ready for your ne... Show more

Security / Access Control Officer - Department of Defence - Full‑Time Reliever

Wilson GroupPerth, WA, AU

Security / Access Control Officer – Department of Defence – Full‑Time Reliever.Security / Access Control Officer – Department of Defence – Full‑Time Reliever.Western Australia | Full‑Time Employmen... Show more

Assistant Manager

McGrathNicolPerth, WA, AU

McGrathNicol is an independent professional services firm specialising in Cyber, Deals, Forensic, Performance, Restructuring, and Risk & Compliance.For more than 20 years, we have supported org... Show more

Security Systems Advisor - FTC

Perth AirportPerth Airport, WA, AU

Perth Airport is Australia’s Western Hub connecting the people, businesses and communities of Western Australia with the rest of Australia and the world.Operating 24 hours a day, seven days a week ... Show more

Locksmith

Macro RecruitmentPerth, WA, AU

We are seeking a skilled Locksmith and Security Technician to provide high-quality residential and commercial security solutions for a well-established provider in the security sector.This is a per... Show more

Cyber Security Risk Manager

Beyond Bank AustraliaPerth, WA, AU

Full time (75 hours per fortnight).Be part of Beyond Bank-a bank that is for and with you.We are one of Australia's largest, 100% member owned mutual banks with a credit union heritage.With more th... Show more

Secure Networks Specialist

NEC CorporationPerth, WA, AU

Join a High-Impact Project as Our New Technical Lead.We’re assembling a unique, high-performing team to support a major, large-scale project and we’re looking for a skilled technical lead to play a... Show more

Security Operations Specialist

Perth AirportPerth Airport, WA, AU

Perth Airport is Australia’s Western Hub connecting the people, businesses and communities of Western Australia with the rest of Australia and the world.Operating 24 hours a day, seven days a week ... Show more

Department of Defence - Access Control Security Officer

Wilson GroupPerth, WA, AU

Department of Defence - Access Control Security Officer.Department of Defence - Access Control Security Officer.Western Australia | Full‑Time Employment.Wilson Security is seeking experienced Secur... Show more

Department of Defence - Access Control Security Officer

Wilson SecurityPerth, WA, AU

Department of Defence - Access Control Security Officer.Department of Defence - Access Control Security Officer.Western Australia | Full‑Time Employment.Wilson Security is seeking experienced Secur... Show more

TECHNICAL LEAD - NETWORK SECURITY

CyberCXPerth, WA, AU

We’re looking for an experienced Technical Lead – Network Security to join our Managed Security Engineering team.This is a senior, hands-on role suited to someone who enjoys solving complex problem... Show more

Cyber Security Engineer

AlstomPerth, WA, AU

At Alstom, we build what millions depend on daily - rail transportation systems that can’t afford to fail.We’re more than 85 000 people worldwide creating the industry most diverse portfolio: high-... Show more

Deputy Lead - Nuclear Safety Management System Assurance

AECOM Australia Pty LtdPerth, WA, AU

At AECOM, we're delivering a better world.Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thr... Show more

Security Technician

AustcorpPerth, WA, AU

National leading Security Integrator with an exciting opportunity to join a close knit team as a Security Technician.They are looking for a candidate with proven experience in the security industry... Show more

Software Team Lead

Professional Search GroupPerth, WA, AU

Lead the future of enterprise platforms within a global organisation.We are seeking an experienced Platform Engineering Team Lead to provide both technical and people leadership across a modern ent... Show more

Veteran Employment - Security Roles on Defence Bases | No Experience Needed

Wilson GroupPerth, WA, AU

Veteran Employment – Security Roles on Defence Bases | No Experience Needed.Permanent Full-Time Roles | $3,000+ Value | No Experience Needed.Are you a current or former ADF member ready for your ne... Show more

Security / Access Control Officer - Department of Defence - Full‑Time Reliever

Wilson SecurityPerth, WA, AU

Security / Access Control Officer – Department of Defence – Full‑Time Reliever.Security / Access Control Officer – Department of Defence – Full‑Time Reliever.Western Australia | Full‑Time Employmen... Show more