Job description
Job Description
Role:
\n
Security Testing Lead Specialist
\n
Location:
\n
Sydney/Melbourne
\n
Job type:
\n
Permanent
\n
Eligibility:
\n
Australian PRs and Citizens
\n
Key Accountabilities Include:
\n
- \n
- Lead and deliver high-complexity, high-assurance security assessments across customer's systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development. \n
- Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities. \n
- Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience. \n
- Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately. \n
- Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation. \n
- Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function. \n
- Collaborate with the Security Testing - Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction. \n
- Assess existing security controls and practices against expected standards and recommend improvements to address gaps and uplift security maturity. \n
- Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations. \n
- Provide mentorship and technical guidance to uplift capability across both senior and junior team members. \n
- Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints. \n
- Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements. \n
\n
Additional information:
\n
- \n
- Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements. \n
- Provide input into customer's Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans. \n
- Develop and deliver training for junior team members and the broader customer community to uplift security capability. \n
- Promote shift-left practices to enable the delivery of secure, high-quality code at speed. \n
- Provide guidance on application security architecture and secure design considerations. \n
- Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities. \n
- Refine and define engagement processes, secure code artefacts, security criteria, and use cases. \n
- Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices. \n
- Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards. \n
- Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations. \n
- Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. \n
- Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations. \n