25 Aug
|
Hastha Solutions
|
New South Wales
25 Aug
Hastha Solutions
New South Wales
Job Description
Security Testing Lead Specialist - Contract - Australia
n
Urgentrequirement of Security Testing Lead Specialist - Contract - Australia
n
Requirements
n
Key Accountabilities
n
Include:
n
n
Lead and deliver high-complexity, high-assurance security assessments across customer's systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.
n
Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.
n
Evaluate the eƯ ectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.
n
Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.
n
Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.
n
Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.
n
Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction
n
Assess existing security controls and practices against expected standards and recommend improvements to address gaps and uplift security maturity.
n
Ensure delivery of high-quality security assessment reports, clearly articulating risks, impactsand recommended mitigations.
n
Provide mentorship and technical guidance to uplift capability across both senior and junior team members.
n
Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.
n
Fulfil Health, Safety, and Setting (HSE)
responsibilities in accordance with organisational policies and regulatory requirements.
n
n
Additional information:
n
n
Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.
n
Provide input into customer's Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans
n
Develop and deliver training for junior team members and the broader customer community to uplift security capability.
n
Promote "shift-left" practices to enable the delivery of secure, high-quality code at speed.
n
Provide guidance on application security architecture and secure design considerations.
n
Develop scripts and contribute to automation initiatives to improve the eƯ iciency and eƯ ectiveness of security testing activities.
n
Refine and define engagement processes, secure code artefacts, security criteria, and use cases.
n
Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices
n
Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.
n
Operate eƯ ectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.
n
Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. Confidential
n
Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time,
and risk considerations.
n
A minimum of 8 years' experience in a Security Testing role.
n
Experience and exposure to a variety of software delivery models, including DevOps and Waterfall.
n
Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment.
n
Significant experience in implementing automated security assessment tools into CI/CD pipelines.
n
Excellent working knowledge of Security Assessment tools, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.
n
Ability to review and provide guidance and feedback on security assessment reports.
n
Strong understanding of application security architecture principles, including transport security, authentication, authorisation, threat modelling, and logging and monitoring.
n
Experience in training and developing people.
n
Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline.
n
Demonstrable skillsets exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.
n
n
Highly Desirable
n
n
Prior experience as a developer/software engineer is a significant advantage.
n
Experience in developing security policy, standards, and security guidance.
n
Significant experience in other domain areas of Cyber Security.
n
A strong understanding of adjacent security dependencies including endpoint, application platforms, databases, network security technologies, and deployment frameworks.
n
n
Current industry certification, including but not limited to:
n
n
Offensive Security – OSCP, OSCE, OSWE
n
SANS – GPEN, GAWN, GWAPT, GXPN
n
Experience in managing engagements with external security vendors.
n
Demonstrable history of developing exploits and zero-day discovery.
n
n
Duration: 06 Monthsandpossible extension
n
Eligibility:Australian/NZCitizens/PR Holders only
#J-*****-Ljbffr
📌 Security Testing Lead Specialist - Contract - Australia (New South Wales)
🏢 Hastha Solutions
📍 New South Wales