23 Aug
|
Xpt Software Australia
|
South Australia
23 Aug
Xpt Software Australia
South Australia
XPT Software Australia Pty Ltd | Contract
Security Testing Lead Specialist
Melbourne, Sydney, Brisbane, Canberra, Adelide, Perth, Australia | Posted on 08/14/2026
- State/Province Victoria
- Country Australia
About Us
AboutXPT
- XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
- XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
- We have 120+technocrats in Australia working at our clientlocations.
- XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
- We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Job Description
Security Testing Lead Specialist
Key Accountabilities Include
- Lead and deliverhigh-complexity, high-assurance security assessments across systems, includingadvanced penetration testing, vulnerability assessments, and source codesecurity reviews, focusing on real-world exploitability and attack pathdevelopment.
- Provide authoritative technicalleadership as a subject matter expert in security testing and securedevelopment, acting as the primary escalation point for complexvulnerabilities, assessments, and adversary emulation activities.
- Evaluate the effectiveness ofsystems in protecting organisational data and maintaining intendedfunctionality, and provide strategic recommendations to improve securityposture and resilience.
- Identify and validate criticalvulnerabilities, exploit paths, and attack vectors, including analysing scanoutputs and manual testing results to assess risk and impact accurately.
- Translate technical findingsinto clear, actionable business risk insights, supporting informed decisionmaking and prioritised remediation.
- Drive the evolution of securitytesting strategy, methodologies, and standards, ensuring alignment withindustry best practices and continuous improvement across the function.
- Collaborate with the SecurityTesting – Senior Lead and broader cyber security teams to shape capabilitydevelopment, resourcing, and operational direction.
- Assess existing securitycontrols and practices against expected standards, and recommend improvementsto address gaps and uplift security maturity.
- Ensure delivery of high-qualitysecurity assessment reports, clearly articulating risks, impacts, and recommended mitigations.
- Provide mentorship andtechnical guidance to uplift capability across both senior and junior teammembers.
- Apply a pragmatic, risk-basedapproach to all activities, balancing security requirements with businessobjectives, timelines, and operational constraints.
- Fulfil Health, Safety, andEnvironment (HSE) responsibilities in accordance with organisational policies andregulatory requirements.
Additional Information
- Provide technical leadershipacross the domain, including performing and leading complex assessments acrossmultiple technical domains, and responding to escalated incidents andengagements.
- Provide input into PenetrationTesting, Vulnerability Assessment and Secure Code processes, methodologies,standards, and corresponding roadmaps and enhancement plans.
- Develop and deliver trainingfor junior team members and the broader community to uplift security capability.
- Promote shift-left practices toenable the delivery of secure, high-quality code at speed.
- Provide guidance on applicationsecurity architecture and secure design considerations.
- Develop scripts and contributeto automation initiatives to improve the efficiency and effectiveness ofsecurity testing activities.
- Refine and define engagementprocesses, secure code artefacts, security criteria, and use cases.
- Collaborate with third parties,including vendors and newly acquired entities, to assess and uplift theirsecurity and development practices.
- Conduct quality assurancereviews of deliverables produced within the Secure Code team to ensure hightechnical standards.
- Operate effectively inenvironments with ambiguous or conflicting requirements, consistentlydelivering high-quality outcomes aligned with Cyber Security expectations.
- Translate technicalvulnerabilities into business risk for stakeholders in a timely manner,leveraging insights from the broader Cyber Security function.
- Apply a pragmatic approach tosecurity testing, balancing business objectives, standards alignment, cost,time, and risk considerations.
Qualifications / Experiences
- A minimum of 8 years’experience in a Security Testing role
- Experience and exposure to avariety of software delivery models, including DevOps and Waterfall
- Significant experience inperforming complex security assessments across a range of domain areas in alarge corporate environment
- Significant experience inimplementing automated security assessment tools into CI/CD pipelines
- Exceptional working knowledgeof Security Assessment toolsets, such as Vulnerability Scanners, Static CodeAnalysis and Software Composition Analysis tools.
- Ability to review and provideguidance and feedback on security assessment reports
- Solid understanding ofapplication security architecture principles including transport security,authentication, authorisation, threat modelling, and logging and monitoring.
- Experience in training anddeveloping people
- Tertiary qualifications inElectrical/Electronic, Computer, Network or Software Engineering;Information/Cyber Security; IT or a related discipline
- Demonstratable skillsetexceeding that expected of a person holding OSCE/OSWE or CREST – Certifiedqualifications for domain areas in scope for the position.
Highly Desirable
- Prior experience as a developer/ software engineer is a significant advantage.
- Experience in developingsecurity policy, standards, and development guidelines
- Significant experience in otherdomain areas of Cyber Security
- A strong understanding ofadjacent security dependencies including endpoints, application platforms,databases, network security technologies, development frameworks.
- Current industry certification,including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS,CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP
- Experience in managingengagements with external security vendors
- Demonstrable history ofdeveloping exploits and zero-day discovery
#J-18808-Ljbffr
📌 Security Testing Lead Specialist (South Australia)
🏢 Xpt Software Australia
📍 South Australia