07 Oct
|
XPT Software Australia Pty
|
Melbourne
07 Oct
XPT Software Australia Pty
Melbourne
Job Description
Security Testing Lead Specialist
Key Accountabilities Include
n
· Lead and deliver
n high-complexity, high-assurance security assessments across systems, including
n advanced penetration testing, vulnerability assessments, and source code
n security reviews, focusing on real-world exploitability and attack path
n development.
n
· Provide authoritative technical
n leadership as a subject matter expert in security testing and secure
n development, acting as the primary escalation point for complex
n vulnerabilities, assessments, and adversary emulation activities.
n
· Evaluate the effectiveness of
n systems in protecting organisational data and maintaining intended
n functionality, and provide strategic recommendations to improve security
n posture and resilience.
n
· Identify and validate critical
n vulnerabilities, exploit paths, and attack vectors, including analysing scan
n outputs and manual testing results to assess risk and impact accurately.
n
· Translate technical findings
n into clear, actionable business risk insights, supporting informed decision
n making and prioritised remediation.
n
· Drive the evolution of security
n testing strategy, methodologies, and standards, ensuring alignment with
n industry best practices and continuous improvement across the function.
n
· Collaborate with the Security
n Testing – Senior Lead and broader cyber security teams to shape capability
n development, resourcing, and operational direction.
n
· Assess existing security
n controls and practices against expected standards, and recommend improvements
n to address gaps and uplift security maturity.
n
· Ensure delivery of high-quality
n security assessment reports, clearly articulating risks, impacts, and
n recommended mitigations.
n
· Provide mentorship and
n technical guidance to uplift capability across both senior and junior team
n members.
n
· Apply a pragmatic, risk-based
n approach to all activities, balancing security requirements with business
n objectives, timelines, and operational constraints.
n
· Fulfil Health, Safety, and
n Environment (HSE)
responsibilities in accordance with organisational policies and
n regulatory requirements.
Additional Information
n
· Provide technical leadership
n across the domain, including performing and leading complex assessments across
n multiple technical domains, and responding to escalated incidents and
n engagements.
n
· Provide input into Penetration
n Testing, Vulnerability Assessment and Secure Code processes, methodologies,
n standards, and corresponding roadmaps and enhancement plans.
n
· Develop and deliver training
n for junior team members and the broader community to uplift security capability.
n
· Promote shift-left practices to
n enable the delivery of secure, high-quality code at speed.
n
· Provide guidance on application
n security architecture and secure design considerations.
n
· Develop scripts and contribute
n to automation initiatives to improve the efficiency and effectiveness of
n security testing activities.
n
· Refine and define engagement
n processes, secure code artefacts, security criteria, and use cases.
n
· Collaborate with third parties,
n including vendors and newly acquired entities, to assess and uplift their
n security and development practices.
n
· Conduct quality assurance
n reviews of deliverables produced within the Secure Code team to ensure high
n technical standards.
n
· Operate effectively in
n environments with ambiguous or conflicting requirements, consistently
n delivering high-quality outcomes aligned with Cyber Security expectations.
n
· Translate technical
n vulnerabilities into business risk for stakeholders in a timely manner,
n leveraging insights from the broader Cyber Security function.
n
· Apply a pragmatic approach to
n security testing, balancing business objectives, standards alignment, cost,
n time, and risk considerations.
Qualifications / Experiences
Essential
n
· A minimum of 8 years'
n experience in a Security Testing role
n
· Experience and exposure to a
n variety of software delivery models, including DevOps and Waterfall
n
· Significant experience in
n performing complex security assessments across a range of domain areas in a
n large corporate workplace
n
· Significant experience in
n implementing automated security assessment tools into CI/CD pipelines
n
· Exceptional working knowledge
n of Security Assessment toolsets, such as Vulnerability Scanners, Static Code
n Analysis and Software Composition Analysis tools.
n
· Ability to review and provide
n guidance and feedback on security assessment reports
n
· Strong understanding of
n application security architecture principles including transport security,
n authentication, authorisation, threat modelling, and logging and monitoring.
n
· Experience in training and
n developing people
n
· Tertiary qualifications in
n
Electrical/Electronic,
Computer, Network or Software Engineering;
n Information/Cyber Security; IT or a related discipline
n
· Demonstratable skillset
n exceeding that expected of a person holding OSCE/OSWE or CREST – Certified
n qualifications for domain areas in scope for the position.
Highly Desirable
n
· Prior experience as a developer
n / software engineer is a significant advantage.
n
· Experience in developing
n security policy, standards, and development guidelines
n
· Significant experience in other
n domain areas of Cyber Security
n
· A strong understanding of
n adjacent security dependencies including endpoints, application platforms,
n databases, network security technologies, development frameworks.
n
· Current industry certification,
n including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS,
n CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP
n
· Experience in managing
n engagements with external security vendors
n
· Demonstrable history of
n developing exploits and zero-day discovery
n
📌 Security Testing Lead Specialist (Melbourne)
🏢 XPT Software Australia Pty
📍 Melbourne