Talent.com
XPT Software Australia Pty Ltd
Security Testing Lead SpecialistXPT Software Australia Pty Ltd • Canberra, VIC, au
Security Testing Lead Specialist

Security Testing Lead Specialist

XPT Software Australia Pty Ltd • Canberra, VIC, au
11 days ago
Job type
  • Quick Apply
Job description
Job Description

Security Testing Lead Specialist

Key Accountabilities Include

· Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

· Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

· Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

· Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

· Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.

· Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

· Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

· Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.

· Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

· Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

· Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

· Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.

Additional Information

· Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

· Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

· Develop and deliver training for junior team members and the broader community to uplift security capability.

· Promote shift-left practices to enable the delivery of secure, high-quality code at speed.

· Provide guidance on application security architecture and secure design considerations.

· Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

· Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

· Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

· Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

· Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.

· Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

· Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.

Qualifications / Experiences

Essential

· A minimum of 8 years’ experience in a Security Testing role

· Experience and exposure to a variety of software delivery models, including DevOps and Waterfall

· Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment

· Significant experience in implementing automated security assessment tools into CI/CD pipelines

· Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.

· Ability to review and provide guidance and feedback on security assessment reports

· Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring.

· Experience in training and developing people

· Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline

· Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.

Highly Desirable

· Prior experience as a developer / software engineer is a significant advantage.

· Experience in developing security policy, standards, and development guidelines

· Significant experience in other domain areas of Cyber Security

· A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.

· Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP

· Experience in managing engagements with external security vendors

· Demonstrable history of developing exploits and zero-day discovery




Requirements
Security Testing Lead Specialist Key Accountabilities Include • Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development. • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities. • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience. • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately. • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation. • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function. • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction. • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity. • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations. • Provide mentorship and technical guidance to uplift capability across both senior and junior team members. • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints. • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements. Additional Information • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements. • Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans. • Develop and deliver training for junior team members and the broader community to uplift security capability. • Promote shift-left practices to enable the delivery of secure, high-quality code at speed. • Provide guidance on application security architecture and secure design considerations. • Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities. • Refine and define engagement processes, secure code artefacts, security criteria, and use cases. • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices. • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards. • Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations. • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations. Qualifications / Experiences Essential • A minimum of 8 years’ experience in a Security Testing role • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment • Significant experience in implementing automated security assessment tools into CI/CD pipelines • Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools. • Ability to review and provide guidance and feedback on security assessment reports • Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring. • Experience in training and developing people • Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline • Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.
Create a job alert for this search

Security Testing Lead Specialist • Canberra, VIC, au

Similar jobs

1 Lead Security Architect - Strategic Architecture Advisory, Risk Assessments - Fed Govt!

HiTech GroupACT, AU

High-profile Federal Government cyber security program.Initial 12 month contract + 2 year extension options.Rewarding hourly rates $$ supporting critical national security capabilities .We are seek... Show more

Cyber Security Specialists, Analysts & Advisors - Threat Intelligence & Advisory - FED GOVT

HiTech GroupACT, AU

Long term contract delivering national cyber security initiatives.Multiple roles across senior and lead levels.Collaborative, high-performing team environment.A high-profile Federal Government agen... Show more

Cyber Security Architect

Onset GroupACT, AU

You'll work with architects, engineers and project teams to ensure security is embedded into solutions from day one, providing practical guidance across cloud, infrastructure and enterprise platfor... Show more

Lead Cyber Advisor

Infinite ConsultingCanberra, ACT, AU

Long term Contract role – Federal Govt.Australian Citizenship with NV1 Clearance.A high‑performing Federal Government cyber security team is seeking an experienced.You will lead security risk asses... Show more

Enterprise Architect - Cyber Security, Mission Critical - FED GOVT

HiTech GroupACT, AU

Exciting opportunity within a leading Federal Government Agency.A leading Federal Government organisation is seeking an experienced.ICT transformation and cyber uplift program.The successful Enterp... Show more

Lead Cyber Threat Analyst

Infinite ConsultingACT, AU

Long term Contract role – Federal Govt.Australian Citizenship with NV2 Clearance.A high‑profile Federal Government program is seeking multiple experienced.Lead complex research and analysis of cybe... Show more

Security Systems Engineer - Infinite Consulting

Infinite ConsultingACT, AU

Senior Security Systems Engineers– NV1 Cleared.Australian Citizens with current NV1 clearance.Senior Security Systems Engineers.We are seeking a highly skilled Security Systems Engineer to act as a... Show more

Cyber Security Technical Analyst - SIEM / Sentinel - Fed Govt!

HiTech GroupACT, AU

Contribute to a high-profile Federal Government program!.Initial 12 month contract + 1x12 month extensions!.Cyber Security Technical Analyst.Cyber Security Technical Analyst.Cyber Security Operatio... Show more

Senior Cyber Advisor in Cyber Security Risk Assessment

Macro RecruitmentACT, AU

For Cyber Security Analyst, Cyber Security Advisor to deliver critical elements of key projects for a leading federal law enforcement agency.A Contract Full Time role within a prestigious governmen... Show more

ICT Security Operations Lead Mission Software Solutions (Intel)

Mission Software Solutions (Intel)Canberra, ACT, AU

At Leidos, we do work that really matters inspired by our mission to make the world safer, healthier, and more efficient through technology, engineering, and science.With 25 years of local experien... Show more

Security Architect - Cloud Security & Accreditation - FED GOVT!

HiTech GroupACT, AU

Exciting opportunity within a high-profile Federal Government agency!.Long-term contract opportunity (12 months + 2 × 12-month extensions) across ACT.A Federal Government agency is seeking an exper... Show more

3 Senior Security Systems Engineers

Infinite ConsultingACT, AU

Senior Security Systems Engineers– NV1 Cleared.Australian Citizens with current NV1 clearance.Senior Security Systems Engineers.We are seeking a highly skilled Security Systems Engineer to act as a... Show more

Security - Green Light

Green LightACT, AU

Initial six (6) month assignment (possiblity of extensions).Green Light has an exciting opportunity for a high calibre, experienced Cyber Security Consultant (NV2) to join our ACT delivery team.The... Show more

Security - Infinite Consulting

Infinite ConsultingACT, AU

Senior Security Systems Engineers.Australian Citizens with current NV2 clearance.Senior Security Systems Engineers.As the Systems Engineer, you will be a subject matter expert required to provide a... Show more

Lead Security Analyst Cyber Threat Analysts - Intelligence - Fed Govt

HiTech GroupACT, AU

Exciting opportunity within a leading Federal Government Agency.A leading Federal Government organisation is seeking.Lead Security Analyst Cyber Threat Analysts.These roles will play a critical par... Show more

Cyber Security Specialists - GRC - Risk Assessments - Fed Govt!

HiTech GroupACT, AU

The successful Cyber Security Specialist will be responsible for, but not limited to:.Conducting comprehensive risk assessments across IT systems, applications, and third-party vendors.Evaluating a... Show more

Security Leader, Global Proserve Security

AmazonACT, AU

Are you a security focused professional who loves working with others on helping them understand, assess and uplift their security capabilities? Are you excited about assisting others implement se... Show more

Senior Cyber Security Engineer

DeloitteCanberra, ACT, AU

Technical resource to help uplift endpoint security and Essential Eight maturity across Deloitte's enterprise environment, with hands-on influence over controls, tooling and emerging AI risk.Tackle... Show more

One Identity Access Management Test Lead - Azure DevOps, ALM Octane, IAM framework - Fed Govt

HiTech GroupACT, AU

Contribute to a high-profile Federal Government program!.Initial contract until 30 June 2027 + 2x12 month extensions!.Identity and Access Management (IAM) projects.Leading the planning, coordinatio... Show more

Cyber Security Operations Specialist - SOC, SIEM - Federal Govt

HiTech GroupACT, AU

Long term contract supporting national cyber security initiatives!.Flexible hybrid working arrangements - Canberra based.A highly regarded Federal Government department is seeking to engage .Cyber ... Show more