15 Aug
|
Cliffside Cybersecurity
|
Sydney
15 Aug
Cliffside Cybersecurity
Sydney
Offensive Security Consultant: Build What Penetration Testing Becomes The Honest Version First
We are not hiring a penetration tester. We are hiring the person who will build what our penetration testing practice looks like in five years.
And here is the reasoning: Penetration testing as it is sold today, scoped applications, checklist methodologies, findings ranked by CVSS, is being commoditised from below and made insufficient from above. Scanners and automation are eating the bottom of the market. AI-driven systems, agent architectures, and interconnected business processes are creating attack surfaces the traditional methodology was never designed to test.
The consultancies that keep selling the old model will spend the next five years competing on price. We intend to spend them defining what comes next. That is the job.
About Cliffside
Cliffside Cybersecurity delivers assessment-first security services for Australian organisations that are serious about understanding and reducing real risk. Our work spans web applications, infrastructure, cloud, identity platforms, and increasingly AI-driven systems including chatbots and agent-based architectures.
We are known for cutting through noise and testing what actually matters: how systems behave under real-world abuse, not whether a scanner flags a vulnerability. From regulated industries to high-growth platforms adopting AI, we partner with CIOs and CISOs who want honest answers, not templated reports.
What You Are Actually Signing Up For
Day one, this is hands-on offensive work. You cannot build the future of a practice you cannot deliver today. You will:
- Conduct penetration testing across web applications, APIs, cloud, and identity platforms
- Design and execute attack scenarios, not follow checklists
- Test AI systems and chatbots for abuse risks:
prompt injection, policy bypass, data leakage, and unintended behaviour
- Assess how AI systems handle context, state, and interaction flows under adversarial conditions
- Simulate real-world attackers, chaining vulnerabilities across systems and services
- Validate defensive controls such as WAFs, rate limiting, and bot protections under active exploitation
- Articulate business risk clearly, not just technical findings
But delivery is the floor, not the . The actual mandate is bigger:
- Define how offensive testing works against multi-agent systems, where AI agents interact with APIs, users, and each other
- Build the methodologies, tooling, and delivery standards that our practice will run on
- Design complex attack simulations against AI-driven business processes, not single applications in isolation
- Shape what we sell, how we scope it, and how we prove its value to clients
In other words: the engagements you deliver in year one are the research and development for the practice you build by year three.
Who This Suits
This is not a junior box-ticking role, and it is not a pure architect role either. You need both the hands and the head.
Offensive capability you already have:
- Solid experience across web, API, infrastructure, and cloud penetration testing
- Ability to independently scope, execute, and deliver end-to-end engagements
- Experience with adversary simulation or red teaming
- Comfort in ambiguous environments where the path is not predefined
The forward-looking part:
- Exposure to testing AI systems, chatbots, or LLM-based applications
- Understanding of how AI systems can be manipulated through input, context, or workflow abuse
- Genuine curiosity about how autonomous agents and integrated systems create new attack surfaces
- A view, even a half-formed one, on where this discipline is heading. We would rather hire someone with strong opinions we can argue with than someone waiting to be told the methodology.
The thinking style:
- Attack chains, not isolated vulnerabilities
- Comfort with APIs, authentication flows, and complex application logic
- Willingness to break things that are not obviously broken
- Ability to translate technical issues into business impact for technical and non-technical stakeholders alike
Background:
- Certifications such as OSCP, OSCE, CREST CRT or similar are valued, not worshipped
- Experience in consulting or client-facing delivery environments
- Cybersecurity, computer science, or equivalent practical experience
Why This Role Exists Here and Not at a Big Firm Large firms will eventually build AI-era offensive practices. They will do it by committee, two years late, and the person who builds it will be three management layers below the decision. Here, you are the decision. You will have direct access to the founder, real clients already asking for this work, and the mandate to build the practice rather than inherit one.
We do not sell generic penetration testing, and we are not going to start. If you are still running tools and calling it a day, this is not for you. If you want your name on what penetration testing becomes, this is exactly where you should be.
📌 Penetration Tester (Sydney)
🏢 Cliffside Cybersecurity
📍 Sydney