22 Sep
|
XPT Software
|
Queensland
22 Sep
XPT Software
Queensland
Job Description
n
XPT SoftwareAustralia PTY Ltd, incorporated in ****, is a Software Services company
n
XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and
Manufacturingdomains.
n
We have 120+technocrats in Australia working at our clientlocations.
n
XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
n
We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
n
n
JD – Security Testing -Lead Specialist:
n
Minimum of 8 years'experience in a Security Testing role
n
MustHave:
n
Leadand deliver high-complexity, high-assurance security assessments across Customer's systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.
n
Provideauthoritative
technical leadership as a subject matter expert in securitytesting and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.
n
Evaluatethe effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.
n
Identifyand validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.
n
Translatetechnical findings into clear, actionable business risk insights, supporting informed decision-making and prioritised remediation.
n
Drivethe evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.
n
Collaboratewith the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.
n
Assessexisting security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.
n
Ensuredelivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.
n
Providementorship and technical guidance to uplift capability across both senior and junior team members.
n
Applya pragmatic, risk-based approach to all activities, balancing
securityrequirements
with business objectives, timelines, and operational constraints.
n
FulfilHealth, Safety, and Workplace responsibilities in accordance with organisational policies and regulatory requirements.
n
Additionalinformation:
n
Providetechnical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.
n
Provideinput into Customer's Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.
n
Developand deliver training for junior team members and the broader Customercommunity to uplift security capability.
n
Promote"shift-left" practices to enable the delivery of secure, high-quality code atspeed.
n
Provideguidance on application security architecture and secure design considerations.
n
Developscripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.
n
Refineand define engagement processes, secure code artefacts, security criteria, and use cases.
n
Collaboratewith third parties, including vendors and newly acquired entities, to assessand uplift their security and development practices.
n
Conductquality assurance reviews of deliverables produced within the Secure Codeteam to ensure high technical standards.
n
Operateeffectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations
n
Translatetechnical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.
n
Applya pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.
n
Currentindustry certification, including but not limited to:
n
OffensiveSecurity – OSCP, OSCE3, OSWE
📌 Penetration Tester (Queensland)
🏢 XPT Software
📍 Queensland