Talent.com
XPT Software Australia Pty Ltd
Penetration TesterXPT Software Australia Pty Ltd • Melbourne, VIC, au
Search for other jobs
Penetration Tester

Penetration Tester

XPT Software Australia Pty Ltd • Melbourne, VIC, au
28 days ago
Job type
  • Quick Apply
Job description

Job Description

Requirements

JD – Security Testing - Lead Specialist:

Minimum of 8 years’ experience in a Security Testing role

Must Have:

· Application Security Certification is mandatory.

· Lead and deliver high-complexity, high-assurance security assessments across Customer’s systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

· Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

· Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

· Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

· Translate technical findings into clear, actionable business risk insights, supporting informed decision-making and prioritised remediation.

· Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

· Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

· Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.

· Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

· Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

· Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

· Fulfil Health, Safety, and Environment responsibilities in accordance with organisational policies and regulatory requirements.

Additional information:

· Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

· Provide input into Customer’s Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

· Develop and deliver training for junior team members and the broader Customer community to uplift security capability.

· Promote “shift-left” practices to enable the delivery of secure, high-quality code at speed.

· Provide guidance on application security architecture and secure design considerations.

· Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

· Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

· Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

· Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

· Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations

· Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

· Confidential

· Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.


Current industry certification, including but not limited to:

Offensive Security – OSCP, OSCE3, OSWE

CREST – Certified Level qualifications (CCT, CCSC, CCSAS, CCSAM)

SANS – GPEN, GAWN, GWAPT, GXPN.

(ISC)2 – CISSP, CCSP





Requirements
JD – Security Testing - Lead Specialist: Minimum of 8 years’ experience in a Security Testing role Must Have: • Lead and deliver high-complexity, high-assurance security assessments across Customer’s systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development. • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities. • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience. • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately. • Translate technical findings into clear, actionable business risk insights, supporting informed decision-making and prioritised remediation. • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function. • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction. • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity. • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations. • Provide mentorship and technical guidance to uplift capability across both senior and junior team members. • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints. • Fulfil Health, Safety, and Environment responsibilities in accordance with organisational policies and regulatory requirements. Additional information: • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements. • Provide input into Customer’s Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans. • Develop and deliver training for junior team members and the broader Customer community to uplift security capability. • Promote “shift-left” practices to enable the delivery of secure, high-quality code at speed. • Provide guidance on application security architecture and secure design considerations. • Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities. • Refine and define engagement processes, secure code artefacts, security criteria, and use cases. • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices. • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards. • Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. • Confidential • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations. Current industry certification, including but not limited to: Offensive Security – OSCP, OSCE3, OSWE CREST – Certified Level qualifications (CCT, CCSC, CCSAS, CCSAM) SANS – GPEN, GAWN, GWAPT, GXPN. (ISC)2 – CISSP, CCSP

Create a job alert for this search

Penetration Tester • Melbourne, VIC, au