JD – Security Testing -
Lead Specialist:
Minimum of 8 years’
experience in a Security Testing role
Must
Have:
· Application Security Certification
is mandatory.
· Lead
and deliver high-complexity, high-assurance security assessments across
Customer’s systems, including advanced penetration testing, vulnerability assessments,
and source code security reviews, focusing on real-world exploitability and
attack path development.
· Provide
authoritative technical leadership as a subject matter expert in security
testing and secure development, acting as the primary escalation point for
complex vulnerabilities, assessments, and adversary emulation activities.
· Evaluate
the effectiveness of systems in protecting organisational data and
maintaining intended functionality, and provide strategic recommendations to
improve security posture and resilience.
· Identify
and validate critical vulnerabilities, exploit paths, and attack vectors,
including analysing scan outputs and manual testing results to assess risk
and impact accurately.
· Translate
technical findings into clear, actionable business risk insights, supporting
informed decision-making and prioritised remediation.
· Drive
the evolution of security testing strategy, methodologies, and standards,
ensuring alignment with industry best practices and continuous improvement
across the function.
· Collaborate
with the Security Testing – Senior Lead and broader cyber security teams to
shape capability development, resourcing, and operational direction.
· Assess
existing security controls and practices against expected standards, and
recommend improvements to address gaps and uplift security maturity.
· Ensure
delivery of high-quality security assessment reports, clearly articulating
risks, impacts, and recommended mitigations.
· Provide
mentorship and technical guidance to uplift capability across both senior and
junior team members.
· Apply
a pragmatic, risk-based approach to all activities, balancing security
requirements with business objectives, timelines, and operational
constraints.
· Fulfil
Health, Safety, and Environment responsibilities in accordance with
organisational policies and regulatory requirements.
Additional
information:
· Provide
technical leadership across the domain, including performing and leading
complex assessments across multiple technical domains, and responding to
escalated incidents and engagements.
· Provide
input into Customer’s Penetration Testing, Vulnerability Assessment and
Secure Code processes, methodologies, standards, and corresponding roadmaps
and enhancement plans.
· Develop
and deliver training for junior team members and the broader Customer
community to uplift security capability.
· Promote
“shift-left” practices to enable the delivery of secure, high-quality code at
speed.
· Provide
guidance on application security architecture and secure design
considerations.
· Develop
scripts and contribute to automation initiatives to improve the efficiency
and effectiveness of security testing activities.
· Refine
and define engagement processes, secure code artefacts, security criteria,
and use cases.
· Collaborate
with third parties, including vendors and newly acquired entities, to assess
and uplift their security and development practices.
· Conduct
quality assurance reviews of deliverables produced within the Secure Code
team to ensure high technical standards.
· Operate
effectively in environments with ambiguous or conflicting requirements,
consistently delivering high-quality outcomes aligned with Cyber Security
expectations
· Translate
technical vulnerabilities into business risk for stakeholders in a timely
manner, leveraging insights from the broader Cyber Security function.
· Confidential
· Apply
a pragmatic approach to security testing, balancing business objectives,
standards alignment, cost, time, and risk considerations.
Current
industry certification, including but not limited to:
Offensive
Security – OSCP, OSCE3, OSWE
CREST
– Certified Level qualifications (CCT, CCSC, CCSAS, CCSAM)
SANS
– GPEN, GAWN, GWAPT, GXPN.
(ISC)2 – CISSP, CCSP
Skills Required
- At least 8 years of experience in a security testing role
- Current application security certification
- Experience leading complex, high-assurance penetration tests and security assessments
- Experience conducting vulnerability assessments and source code security reviews
- Experience with adversary emulation, exploit path development, and attack vector analysis
- Experience translating technical vulnerabilities into business risk and remediation recommendations
- Experience developing security testing methodologies, standards, processes, and roadmaps
- Experience providing technical leadership, mentorship, and training
- Experience with application security architecture and secure design practices
- Experience developing scripts and contributing to security testing automation
- OSCP, OSCE3, or OSWE certification
- CREST Certified Level qualification, including CCT, CCSC, CCSAS, or CCSAM
- SANS GPEN, GAWN, GWAPT, or GXPN certification
- CISSP or CCSP certification
What We Do
XPT Software Australia Pty Ltd is a technology consulting and software services company serving clients across banking, financial services and insurance, telecommunications, mining, retail, energy, and manufacturing. It provides software development, IT management consulting, business analysis, project and program management, infrastructure support, and offshore development through onsite-offshore delivery. The company also works with cloud computing, big data, mobile applications, UI/UX, algorithms, and IoT.


.png)





