Penetration Testing Manager

Posted 6 Hours Ago
Be an Early Applicant
Office, Lilongwe, Central Region, MWI
In-Office
Senior level
Blockchain • Fintech • Payments • Software • Financial Services • Cryptocurrency
The Role
Lead and coordinate ASX's penetration testing program including annual planning, vendor management, Red/Purple Team coordination, scope and rules of engagement, execution governance, reporting, remediation follow-up, and integration of AI/automated testing. Ensure readiness, oversee live testing escalation, drive stakeholder accountability, and communicate outcomes to technical and non-technical audiences.
Summary Generated by Built In
ASX: Powering Australia's financial marketsWhy join the ASX?

When you join ASX, you’re joining a company with a strong purpose – to power a stronger economic future by enabling a fair and dynamic marketplace for all.

In your new role, you’ll be part of a leading global securities exchange with a strong brand. We are known for being a trusted market operator and an exciting data hub. 

Want to know why we are a great place to work, click on the link to learn more.

www.asx.com.au/about/careers/a-great-place-to-work

We are more than a securities exchange!

The ASX team brings together talented people from a diverse range of disciplines. 

We run critical market infrastructure, with 1 in 3 people employed within technology.  Yet we have a unique complexity of roles across a range of disciplines such as operations, program delivery, financial products, investor engagement, risk and compliance.

We’re proud to foster a workplace where diversity is celebrated and inclusion is part of our everyday culture. Our employee-led networks champion LGBTIQ+ inclusion, promote gender equality, accessibility and wellbeing, inspire giving and volunteering, and celebrate cultural and religious events, creating a sense of belonging for all. As an AWEI Bronze employer and member of the Champions of Change Coalition for gender equality, we’re committed to a fair and inclusive workplace where everyone can thrive.

Your Team

The Cyber Architecture and Assurance team provides independent assurance over ASX’s cyber control environment, helping protect the integrity, availability and resilience of market-critical services.

The team works across Cyber Security, Technology and business stakeholders to establish assurance standards, govern testing activity, coordinate specialist external providers, drive accountability for remediation, and provide evidence over the effectiveness of controls across penetration testing, Red/Purple Team coordination, control validation and risk-based security assessment activities.

Coordinate ASX’s end-to-end penetration testing program, including annual planning, project-based testing, engagement governance, vendor delivery, reporting, closure and remediation follow-up.

  • Coordinate Red Team and Purple Team activities, ensuring exercises are appropriately scoped, governed, safely executed and translated into actionable control improvement opportunities.

  • Own the scope definition and rules of engagement for penetration testing, ensuring coverage is risk-based, complete, agreed by accountable system and project owners, and aligned to system criticality, project risk, technology change and threat exposure.

  • Manage relationships with external penetration testing providers, ensuring engagements are appropriately planned, governed, delivered and assessed against agreed quality expectations.

  • Support budget allocation, forecasting and tracking for penetration testing and related assurance activities, including provider spend, planned testing demand and delivery risks.

  • Drive internal readiness for regular and project-based penetration tests, holding project, system and platform owners accountable for providing testable environments, required access, approved connectivity, stakeholder support, test windows and safe execution constraints.

  • Establish and manage engagement governance, including readiness criteria, go/no-go decision points, escalation paths, daily status reporting, issue management, SOW coordination and closure criteria.

  • Act as the central escalation and decision point during live testing, removing blockers, coordinating rapid issue resolution, tracking coverage against agreed scope, and ensuring high or critical findings are communicated promptly.

  • Hold technology, application, cloud, infrastructure, business and vendor teams accountable for triaging findings, agreeing remediation actions, tracking closure and escalating material risks where obligations are not being met.

  • Evaluate, pilot and integrate AI-enabled or automated penetration testing capabilities into the broader cyber assurance and security testing strategy.

  • Communicate testing outcomes, themes, delivery risks and risk insights clearly to technical teams, senior stakeholders and non-technical audiences.

Your experience and qualifications

Must have:

  • Background in information security, penetration testing principles, vulnerability assessment and risk-based security assurance.

  • Exposure to the delivery lifecycle for security testing or assurance engagements, including planning, scope governance, readiness management, execution oversight, reporting or remediation follow-up.

  • Experience working with external security vendors or penetration testing service providers, including delivery coordination, quality review or performance follow-up.

  • Ability to translate project, system and control risk into clear testing objectives, rules of engagement, readiness expectations and remediation priorities.

  • Exposure to penetration testing across complex technology environments, such as applications, APIs, infrastructure, cloud platforms and critical business systems.

  • Ability to influence stakeholders and drive accountability across technology, project, application, infrastructure, cloud, business and vendor teams.

  • Working knowledge of engagement governance, including roles and responsibilities, readiness criteria, escalation paths, reporting cadence and quality expectations.

  • Working knowledge of contemporary security testing methodologies, common vulnerability classes and relevant cyber security frameworks or regulatory expectations.

Nice to have:

  • Hands-on penetration testing experience, noting ASX primarily uses a panel of specialised providers for delivery.

  • Experience with Red Team or Purple Team exercises, including exercise planning, coordination, debriefs and translation of outcomes into control improvements.

  • Experience with AI-driven, automated or continuous security testing tools, including safe adoption, governance and integration into assurance workflows.

  • Relevant security certifications such as OSCP, GPEN, CISSP, CISM or equivalent practical experience in security testing or cyber assurance.

  • Experience working in financial services, critical infrastructure or another highly regulated technology environment. What you need to enjoy and be good at

  • Highly organised, detail-oriented and able to switch context across varied assurance, delivery, stakeholder and operational

  • tasks.

  • Negotiating mutually acceptable outcomes while clearly asserting non-negotiable security, process and control requirements.

  • Building strong relationships with internal and external stakeholders, including technology teams, business owners and specialist security providers.

  • Taking ownership of issues and driving them through to closure, balancing the bigger picture with the ability to dive into detail when required.

  • Communicating clearly in writing and verbally, with a continuous improvement mindset and strong risk focus in an environment where control effectiveness cannot be compromised.

We make hiring decisions based on your skills, capabilities and experience, and how you’ll help us to live our values. We encourage you to apply even if you don’t meet all the criteria of this role.

If you need any adjustments during the application or interview process to help you present your best self, please let us know at [email protected].

At ASX Group, our diverse workforce is essential to build and maintain a fair and dynamic marketplace. We support flexible working and offer hybrid working options. Even if our roles are advertised as full-time, we encourage you to apply if you are interested in part-time or other flexible working arrangements.

We will arrange for successful candidates to have background checks, including reference and police checks, completed as part of the on-boarding process.

To be considered for this position, candidates must be legally authorised to work in Australia on a permanent basis without any restrictions.

Skills Required

  • Background in information security, penetration testing principles, vulnerability assessment and risk-based security assurance
  • Exposure to the delivery lifecycle for security testing or assurance engagements, including planning, scope governance, readiness management, execution oversight, reporting or remediation follow-up
  • Experience working with external security vendors or penetration testing service providers, including delivery coordination, quality review or performance follow-up
  • Ability to translate project, system and control risk into clear testing objectives, rules of engagement, readiness expectations and remediation priorities
  • Exposure to penetration testing across applications, APIs, infrastructure, cloud platforms and critical business systems
  • Ability to influence stakeholders and drive accountability across technology, project, application, infrastructure, cloud, business and vendor teams
  • Working knowledge of engagement governance, including roles and responsibilities, readiness criteria, escalation paths, reporting cadence and quality expectations
  • Working knowledge of contemporary security testing methodologies, common vulnerability classes and relevant cyber security frameworks or regulatory expectations
  • Hands-on penetration testing experience
  • Experience with Red Team or Purple Team exercises, including exercise planning, coordination and debriefs
  • Experience with AI-driven, automated or continuous security testing tools and their governance/integration
  • Relevant security certifications such as OSCP, GPEN, CISSP, CISM or equivalent practical experience
  • Experience working in financial services, critical infrastructure or other highly regulated technology environments
  • Legally authorised to work in Australia on a permanent basis without any restrictions
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sydney, NSW
1,848 Employees
Year Founded: 1987

What We Do

ASX is one of the world’s top ten exchanges. As a full-service exchange, we offer trading, clearing, settlement, market insights, connectivity, and depository services across all major asset classes including equities, derivatives, ETFs, options, and managed funds. With a total market capitalisation of around $1.5 trillion, ASX is home to some of the world’s leading resource, finance, and technology companies. Our $47 trillion interest rate derivatives market is the largest in Asia and among the biggest in the world. ASX’s network and data centre (The Australian Liquidity Centre) provides a world class financial infrastructure and access to Australia’s largest pools of liquidity.

Similar Jobs

ASX Logo ASX

Data Engineer

Blockchain • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office
Office, Lilongwe, Central Region, MWI
1848 Employees
In-Office or Remote
2 Locations
145 Employees

VITALITE Malawi Logo VITALITE Malawi

Full-stack Engineer

Social Impact • Energy • Solar • Renewable Energy
In-Office
Lilongwe, Central Region, MWI
34 Employees

MBH Architects Logo MBH Architects

Project Manager

Professional Services • Real Estate • Retail • Design
Hybrid
Office, Lilongwe, Central Region, MWI
200 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account