Senior Penetration Tester/ Offensive Security Consultant (Australia)

Senior Penetration Tester/ Offensive Security Consultant (Australia)

18 Sep
|
Parabellum
|
Australia

18 Sep

Parabellum

Australia

OPEN TO AUSTRALIAN RESIDENTS ONLY

Parabellum's offensive security practice delivers penetration testing and red team engagements to enterprise, government, financial services, healthcare, energy and defence supply chain organisations across Australia.

We're growing, and we're looking for Australian-based senior testers who take pride in their craft and want to work alongside people who do the same. Not warm bodies for a roster, people who can own an engagement end to end.

What you'll be doing A bit of everything. Web app assessment one week, a red team with physical intrusion the next, cloud assumed breach after that. We don't pigeonhole people into a single domain. Engagements span:

- Web applications and APIs. Manual testing, business logic, auth bypass — the things scanners miss.
- Thick client and mobile. iOS, Android, Windows desktop. If it has a client-side component, you know how to pull it apart.
- Cloud. AWS, Azure, GCP. IAM misconfigurations, insecure storage, overly permissive roles, serverless abuse, container escapes.
- Infrastructure. Active Directory attacks, ADCS/SCCM abuse, lateral movement, privilege escalation — foothold to domain admin.
- Red team operations. Full-scope adversary simulation: phishing, vishing, pretexting, covert entry, drop boxes, C2 infrastructure. Real defences, not lab environments.

What we're looking for

- Depth across multiple domains. Demonstrated experience finding and exploiting vulnerabilities across web, API, mobile, thick client, cloud and infrastructure, and the ability to context-switch and pick up unfamiliar tech quickly.
- Large enterprise experience. Our clients run layered controls — identity governance (SailPoint), PAM (CyberArk), formal change and approval processes.



Knowing how these are architected helps you find where they break. You're comfortable in segmented networks, pivoting through bastion hosts into private cloud, and routing traffic out of environments built to prevent exactly that.
- CI/CD and DevOps exploitation. Insecure GitHub Actions and workflow configs, permissive pod security policies, exposed build servers, secrets in build logs, container registry credential harvesting. Supply chain compromise through build infrastructure is one of the most significant attack vectors right now.
- Kubernetes and container security. RBAC abuse, service account token exploitation, container escapes via privileged pods or mounted sockets, etcd access, cloud metadata abuse from within pods. Compromised pod to node and beyond.
- Red team and social engineering. You can plan and run phishing campaigns, pretext calls and physical social engineering, operate covertly, and think through an attack path from initial access to objective. You understand OPSEC.
- Tooling. You live in Burp, know Cobalt Strike, Sliver or Mythic, use BloodHound and Rubeus without a cheat sheet, and have opinions about which C2 is best (even if you're wrong). You script in Python, PowerShell or Bash to automate, write exploits, or build what off-the-shelf can't.
- Written communication. Your reports need to land with a CISO and a sysadmin: articulate risk,



explain impact in business terms, give actionable remediation. The report is the deliverable, and it needs to be good.
- Client-facing confidence. Scoping calls, findings presentations, and sometimes telling people things they don't want to hear — clearly, professionally, without making enemies.
- Interest in AI attack surfaces. LLMs, agents, RAG pipelines and AI-integrated apps are turning up in client environments. You don't need to be an expert, but curiosity goes a long way.

Experience and certifications

5+ years in offensive security roles, including consultancy work delivering engagements to external clients under real scoping, time and deadline pressure. Prior military, government or intelligence community experience is a plus but not required. Multiple certifications from OffSec, GIAC/SANS or CREST are highly regarded.

Security clearance

Eligibility for an Australian Government security clearance (NV1 or above) is highly regarded; holding one already is even better. A lot of our work requires it.

Why Parabellum?

- Work Remotely. From anywhere in Australia
- Autonomy. You run your engagements. We trust your time management and your methodology and empower you to stand by your work.
- Actual red team work. Clients come to us to learn what an attacker would really do, not for a PDF that says "you passed."
- Engaged leadership. Nobody here is three promotions removed from a terminal. We test, we understand the craft, and we'll back you up.
- Access to internally developed tooling. And the chance to contribute to research & new and existing R&D; projects
- Paid Birthday day-off. That one is pretty self explanatory.

📌 Senior Penetration Tester/ Offensive Security Consultant (Australia)
🏢 Parabellum
📍 Australia

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior penetration tester/ offensive security consultant (australia) / australia

Subscribe to this job alert:

Get the latest job offers by email for: senior penetration tester/ offensive security consultant (australia) / australia