Profectus is seeking experienced Lead Penetration Testers to support the delivery of security testing services within an agency of the Australian Government. The work involves assessing ICT applications, infrastructure and gateway environments to identify configuration weaknesses, vulnerabilities and faults that affect security, then reporting findings and recommending remediation. These are senior roles leading complex testing activity in highly secure, tightly governed environments, working alongside security, engineering and project teams.
Key Responsibilities
- Conduct penetration testing across ICT applications, infrastructure and gateway environments
- Lead and coordinate teams undertaking complex penetration testing activity
- Apply a range of penetration testing techniques, methodologies and commercial and bespoke tools
- Develop test plans, scoping documents and procedures for individual engagements
- Record approaches, techniques and results to support accurate and repeatable reporting
- Produce transparent technical reports detailing findings, risk ratings and recommended solutions
- Recommend technical remediation for identified vulnerabilities and support follow up validation
- Participate in simulated attack exercises and related security assessment activity
- Provide technical guidance and mentoring to less experienced testers
- Engage with system owners and technical stakeholders to explain findings and agreed actions
- Maintain testing documentation, tooling and standards to a consistent quality
Required Experience
- Extensive experience conducting penetration tests against applications, infrastructure and gateway environments
- Proven ability to plan, lead and deliver complex testing engagements without close supervision
- Strong working knowledge of penetration testing methodologies, tools and reporting standards
- Experience identifying, exploiting and documenting vulnerabilities across networks, operating systems and web applications
- Ability to translate technical findings into practical remediation advice for technical and non technical audiences
- Experience working within secure, highly regulated environments
- Strong written reporting skills with attention to accuracy and detail
Desirable Experience
- Relevant certifications such as CREST Certified Tester (Infrastructure or Web Applications), CHECK Team Leader or equivalent
- Experience contributing to simulated attack exercises
- Experience with scripting and automation to support testing activity
- Prior experience delivering security testing services to Australian Government clients
Security Clearance Requirements
- must be an Australian Citizen
- must hold a current Positive Vetting (TSPV) security clearance
Working Arrangements
- onsite
- Canberra
Why Profectus Profectus partners with Australian Government agencies to deliver trusted ICT capability across complex delivery programs. We take a long term, relationship driven approach, supporting our people across the full lifecycle of their engagement while contributing to outcomes of national importance.
📌 Penetration Tester (Canberra)
🏢 Profectus
📍 Canberra
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.