13 Sep
|
Medhealth
|
Melbourne
13 Sep
Medhealth
Melbourne
MedHealth are a purpose-built collection of industry leading health, medical and employment brands.
Our unique and diverse capabilities come together to get the best possible health and employment outcomes for you and the people you support.
We support whole populations to better outcomes, yet never lose sight of the individual we are working with to build a better life through work and health.Job DescriptionWe're looking for an experienced Application Security Technical Lead to own and run application security across MedHealth.This is a hands-on role responsible for operating and continuously improving an established AppSec capability - ensuring security practices, tooling and processes are effectively embedded into development workflows.You will work across multiple applications and development teams, each with varying levels of application security maturity, tailoring your approach to uplift capability while maintaining delivery alignment.Key responsibilitiesOwn and operate application security across the SDLCIdentify and assess application security risks, partnering with Engineering teams on remediationPerform secure code reviews (primarily .NET) and support secure development practicesLead threat modelling and security assessments across applications and automation workflowsAdapt security practices to suit different team maturity levels, balancing uplift, standardisation and delivery needsOwn and optimise AppSec tooling (SAST, DAST, SCA) across CI/CD pipelinesEnsure effective security testing without impacting delivery velocityOwn vulnerability visibility,
prioritisation and reportingDefine and apply secure design and development standardsEstablish Security Champions across development teamsMentor developers and uplift secure coding capability across teamsQualificationsWhat You'll Bring5+ years' experience in software engineering including 2+ in an application security role.Solid experience with DevSecOps and CI/CD environmentsHands-on experience with AppSec tools (SAST, DAST, SCA)Strong experience working in Azure environments and Azure DevOps pipelinesComfortable reviewing code (C#, .NET, web applications)Strong understanding of OWASP Top 10 and secure design principlesExperience working across multiple teams or platforms with varying maturity levelsAble to adapt approach based on risk, complexity and delivery contextSelf-driven, accountable and strong at stakeholder engagementAdditional InformationWhy you'll love it here:Ability to own and run a mature Application Security capabilityWork across a diverse application landscape and multiple engineering teamsWork somewhere serious about cybersecurity done right.A culture that values continuous improvement, learning, and knowledge sharing.Great balance of working from home and office collaboration.You are welcome here.Our fast-growing team of more than 4,000 people around Australia represent a huge array of life experiences, skills and ways of thinking.
We value all these differences.We are an Equal Opportunity Employer, proudly welcoming people with disability including mental health conditions, people from diverse cultural and linguistic backgrounds, people from the LGBTQIA+ community, veterans, carers and Indigenous Australians to our team.We are happy to adjust our recruitment process to support accessibility needs.
#J-*****-Ljbffr
📌 Application Security Technical Lead (Melbourne)
🏢 Medhealth
📍 Melbourne