25 Aug
|
Xpt Software Australia
|
Western Australia
25 Aug
Xpt Software Australia
Western Australia
Job Description
XPT Software Australia Pty Ltd | Contract
n
Security Testing Lead Specialist
n
Melbourne, Sydney, Brisbane, Canberra, Adelide, Perth, Australia | Posted on 08/14/2026
n
n
State/Province Victoria
n
Country Australia
n
n
About Us
n
AboutXPT
n
n
XPT SoftwareAustralia PTY Ltd, incorporated in ****, is a Software Services company
n
XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
n
We have 120+technocrats in Australia working at our clientlocations.
n
XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
n
We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
n
n
Job Description
n
Security Testing Lead Specialist
n
Key Accountabilities Include
n
n
Lead and deliverhigh-complexity, high-assurance security assessments across systems, includingadvanced penetration testing, vulnerability assessments, and source codesecurity reviews, focusing on real-world exploitability and attack pathdevelopment.
n
Provide authoritative technicalleadership as a subject matter expert in security testing and securedevelopment, acting as the primary escalation point for complexvulnerabilities, assessments, and adversary emulation activities.
n
Evaluate the effectiveness ofsystems in protecting organisational data and maintaining intendedfunctionality, and provide strategic recommendations to improve securityposture and resilience.
n
Identify and validate criticalvulnerabilities, exploit paths, and attack vectors, including analysing scanoutputs and manual testing results to assess risk and impact accurately.
n
Translate technical findingsinto clear, actionable business risk insights, supporting informed decisionmaking and prioritised remediation.
n
Drive the evolution of securitytesting strategy, methodologies, and standards, ensuring alignment withindustry best practices and continuous improvement across the function.
n
Collaborate with the SecurityTesting – Senior Lead and broader cyber security teams to shape capabilitydevelopment, resourcing, and operational direction.
n
Assess existing securitycontrols and practices against expected standards, and recommend improvementsto address gaps and uplift security maturity.
n
Ensure delivery of high-qualitysecurity assessment reports, clearly articulating risks, impacts, and recommended mitigations.
n
Provide mentorship andtechnical guidance to uplift capability across both senior and junior teammembers.
n
Apply a pragmatic, risk-basedapproach to all activities, balancing security requirements with businessobjectives, timelines, and operational constraints.
n
Fulfil Health, Safety, andEnvironment (HSE) responsibilities in accordance with organisational policies andregulatory requirements.
n
n
Additional Information
n
n
Provide technical leadershipacross the domain, including performing and leading complex assessments acrossmultiple technical domains, and responding to escalated incidents andengagements.
n
Provide input into PenetrationTesting, Vulnerability Assessment and Secure Code processes, methodologies,standards, and corresponding roadmaps and enhancement plans.
n
Develop and deliver trainingfor junior team members and the broader community to uplift security capability.
n
Promote shift-left practices toenable the delivery of secure, high-quality code at speed.
n
Provide guidance on applicationsecurity architecture and secure design considerations.
n
Develop scripts and contributeto automation initiatives to improve the efficiency and effectiveness ofsecurity testing activities.
n
Refine and define engagementprocesses, secure code artefacts, security criteria, and use cases.
n
Collaborate with third parties,including vendors and newly acquired entities, to assess and uplift theirsecurity and development practices.
n
Conduct quality assurancereviews of deliverables produced within the Secure Code team to ensure hightechnical standards.
n
Operate effectively inenvironments with ambiguous or conflicting requirements, consistentlydelivering high-quality outcomes aligned with Cyber Security expectations.
n
Translate technicalvulnerabilities into business risk for stakeholders in a timely manner,leveraging insights from the broader Cyber Security function.
n
Apply a pragmatic approach tosecurity testing, balancing business objectives, standards alignment, cost,time, and risk considerations.
n
n
Qualifications / Experiences
n
n
A minimum of 8 years'experience in a Security Testing role
n
Experience and exposure to avariety of software delivery models, including DevOps and Waterfall
n
Significant experience inperforming complex security assessments across a range of domain areas in alarge corporate environment
n
Significant experience inimplementing automated security assessment tools into CI/CD pipelines
n
Exceptional working knowledgeof Security Assessment toolsets, such as Vulnerability Scanners, Static CodeAnalysis and Software Composition Analysis tools.
n
Ability to review and provideguidance and feedback on security assessment reports
n
Strong understanding ofapplication security architecture principles including transport security,authentication, authorisation, threat modelling, and logging and monitoring.
n
Experience in training anddeveloping people
n
Tertiary qualifications inElectrical/Electronic, Computer, Network or Software Engineering;Information/Cyber Security; IT or a related discipline
n
Demonstratable skillsetexceeding that expected of a person holding OSCE/OSWE or CREST – Certifiedqualifications for domain areas in scope for the position.
n
n
Highly Desirable
n
n
Prior experience as a developer/ software engineer is a significant advantage.
n
Experience in developingsecurity policy, standards, and development guidelines
n
Significant experience in otherdomain areas of Cyber Security
n
A solid understanding ofadjacent security dependencies including endpoints, application platforms,databases, network security technologies, development frameworks.
n
Current industry certification,including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS,CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP
n
Experience in managingengagements with external security vendors
n
Demonstrable history ofdeveloping exploits and zero-day discovery
n
#J-*****-Ljbffr
📌 Security Testing Lead Specialist (Western Australia)
🏢 Xpt Software Australia
📍 Western Australia