07 Oct
|
XPT Software Australia Pty
|
Melbourne
07 Oct
XPT Software Australia Pty
Melbourne
Job Description
Requirements
n
JD – Security Testing -
n Lead Specialist:
n
Minimum of
8 years
'
n experience in a Security Testing role
n
Must
n Have:
n
· Lead
n and deliver high-complexity, high-assurance security assessments across
n Customer's systems, including advanced penetration testing, vulnerability
n assessments, and source code security reviews, focusing on real-world
n exploitability and attack path development.
n
· Provide
n authoritative technical leadership as a subject matter expert in security
n testing and secure development, acting as the primary escalation point for
n complex vulnerabilities, assessments, and adversary emulation activities.
n
· Evaluate
n the effectiveness of systems in protecting organisational data and
n maintaining intended functionality, and provide strategic recommendations to
n improve security posture and resilience.
n
· Identify
n and validate critical vulnerabilities, exploit paths, and attack vectors,
n including analysing scan outputs and manual testing results to assess risk
n and impact accurately.
n
· Translate
n technical findings into transparent, actionable business risk insights, supporting
n informed decision-making and prioritised remediation.
n
· Drive
n the evolution of security testing strategy, methodologies, and standards,
n ensuring alignment with industry best practices and continuous improvement
n across the function.
n
· Collaborate
n with the Security Testing – Senior Lead and broader cyber security teams to
n shape capability development, resourcing, and operational direction.
n
· Assess
n existing security controls and practices against expected standards, and
n recommend improvements to address gaps and uplift security maturity.
n
· Ensure
n delivery of high-quality security assessment reports, clearly articulating
n risks, impacts, and recommended mitigations.
n
· Provide
n mentorship and technical guidance to uplift capability across both senior and
n junior team members.
n
· Apply
n a pragmatic, risk-based approach to all activities, balancing security
n requirements with business objectives, timelines, and operational
n constraints.
n
· Fulfil
n Health, Safety, and Environment responsibilities in accordance with
n organisational policies and regulatory requirements.
n
Additional
n information:
n
· Provide
n technical leadership across the domain, including performing and leading
n complex assessments across multiple technical domains, and responding to
n escalated incidents and engagements.
n
· Provide
n input into Customer's Penetration Testing, Vulnerability Assessment and
n Secure Code processes, methodologies, standards, and corresponding roadmaps
n and enhancement plans.
n
· Develop
n and deliver training for junior team members and the broader Customer
n community to uplift security capability.
n
· Promote
n "shift-left" practices to enable the delivery of secure, high-quality code at
n speed.
n
· Provide
n guidance on application security architecture and secure design
n considerations.
n
· Develop
n scripts and contribute to automation initiatives to improve the efficiency
n and effectiveness of security testing activities.
n
· Refine
n and define engagement processes, secure code artefacts, security criteria,
n and use cases.
n
· Collaborate
n with third parties, including vendors and newly acquired entities, to assess
n and uplift their security and development practices.
n
· Conduct
n quality assurance reviews of deliverables produced within the Secure Code
n team to ensure high technical standards.
n
· Operate
n effectively in environments with ambiguous or conflicting requirements,
n consistently delivering high-quality outcomes aligned with Cyber Security
n expectations
n
· Translate
n technical vulnerabilities into business risk for stakeholders in a timely
n manner, leveraging insights from the broader Cyber Security function.
n
· Confidential
n
· Apply
n a pragmatic approach to security testing, balancing business objectives,
n standards alignment, cost, time, and risk considerations.
n
n
Current
n industry certification, including but not limited to:
n
Offensive
n Security – OSCP, OSCE3, OSWE
n
CREST
n – Certified Level qualifications (CCT, CCSC, CCSAS, CCSAM)
n
SANS
n – GPEN, GAWN, GWAPT, GXPN.
n
(ISC)2 – CISSP, CCSP
n
n
n
📌 Security Testing Lead (Melbourne)
🏢 XPT Software Australia Pty
📍 Melbourne