Security Testing Lead Specialist - Contract - Australia

Posted 2 Days Ago
Be an Early Applicant
Sydney, New South Wales, AUS
In-Office
Senior level
Information Technology • Software • Consulting
The Role
Leads complex penetration tests, vulnerability assessments, secure code reviews, exploit-path analysis, and adversary emulation. Provides technical leadership, evaluates security controls, translates vulnerabilities into business risks, improves testing methodologies, supports secure architecture and shift-left practices, automates assessments within CI/CD pipelines, develops training, mentors security professionals, and manages quality assurance and vendor engagements.
Summary Generated by Built In
Urgent requirement of Security Testing Lead Specialist - Contract - Australia

Requirements
    Key Accountabilities

    Include:
    • Lead and deliver high-complexity, high-assurance security assessments across customer’s systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.
    • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.
    • Evaluate the eƯ ectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.
    • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.
    • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.
    • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.
    • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction
    • Assess existing security controls and practices against expected standards and recommend improvements to address gaps and uplift security maturity.
    • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts and recommended mitigations.
    • Provide mentorship and technical guidance to uplift capability across both senior and junior team members.
    • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.
    • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.

    Additional information:
    • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.
    • Provide input into customer’s Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans
    • Develop and deliver training for junior team members and the broader customer community to uplift security capability.
    • Promote “shift-left” practices to enable the delivery of secure, high-quality code at speed.
    • Provide guidance on application security architecture and secure design considerations.
    • Develop scripts and contribute to automation initiatives to improve the eƯ iciency and eƯ ectiveness of security testing activities.
    • Refine and define engagement processes, secure code artefacts, security criteria, and use cases.
    • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices
    • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.
    • Operate eƯ ectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.
    • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function. Confidential
    • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.

    Essential
    • A minimum of 8 years’ experience in a Security Testing role.
    • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall.
    • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment.
    • Significant experience in implementing automated security assessment tools into CI/CD pipelines.
    • Excellent working knowledge of Security Assessment tools, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.
    • Ability to review and provide guidance and feedback on security assessment reports.
    • Strong understanding of application security architecture principles, including transport security, authentication, authorisation, threat modelling, and logging and monitoring.
    • Experience in training and developing people.
    • Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline.
    • Demonstrable skillsets exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.
    Highly Desirable
    • Prior experience as a developer/software engineer is a significant advantage.
    • Experience in developing security policy, standards, and security guidance.
    • Significant experience in other domain areas of Cyber Security.
    • A strong understanding of adjacent security dependencies including endpoint, application platforms, databases, network security technologies, and deployment frameworks.
    • Current industry certification, including but not limited to:
      • Offensive Security – OSCP, OSCE, OSWE
      • CREST – Certified Level qualifications (CCT, CCSC, CCSAS, CCSAM)
      • SANS – GPEN, GAWN, GWAPT, GXPN
      • (ISC)² – CISSP, CCSP
    • Experience in managing engagements with external security vendors.
    • Demonstrable history of developing exploits and zero-day discovery.

    Duration: 06 Months and possible extension

    Eligibility: Australian/NZ Citizens/PR Holders only


    Skills Required

    • Minimum 8 years of experience in security testing
    • Experience with DevOps and Waterfall software delivery models
    • Experience performing complex security assessments across multiple domains in large corporate environments
    • Experience implementing automated security assessment tools into CI/CD pipelines
    • Working knowledge of vulnerability scanners, static code analysis, and software composition analysis tools
    • Ability to review and provide guidance on security assessment reports
    • Strong understanding of application security architecture, transport security, authentication, authorization, threat modeling, logging, and monitoring
    • Experience training and developing people
    • Tertiary qualification in engineering, information or cyber security, IT, or a related discipline
    • Security testing skills exceeding OSCE, OSWE, or CREST-certified competency levels
    • Prior developer or software engineering experience
    • Experience developing security policies, standards, and guidance
    • Experience across additional cybersecurity domains
    • Understanding of endpoint, application platform, database, network security, and deployment technologies
    • Current industry certifications such as OSCP, OSCE, OSWE, CREST, GPEN, GAWN, GWAPT, GXPN, CISSP, or CCSP
    • Experience managing engagements with external security vendors
    • History of exploit development and zero-day discovery
    • Australian or New Zealand citizenship, or Australian permanent residency
    Am I A Good Fit?
    beta
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    13 Employees
    Year Founded: 2012

    What We Do

    Hastha Solutions is an SAP solutions and enterprise technology company serving government and private organizations. It specializes in SAP Enterprise Asset Management (EAM), enterprise mobility, GIS integration, enterprise document management, digitization, cloud transformation, and consumer-application integration. The company uses an analytical, vendor-agnostic approach to design and deliver tailored, cost-effective solutions that connect enterprise systems with community and consumer needs for clients.

    Similar Jobs

    Pfizer Logo Pfizer

    Feasibility Strategic Analytics Lead (FSAL) - Senior Manager

    Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
    In-Office or Remote
    33 Locations
    121990 Employees
    116K-193K Annually

    Legora Logo Legora

    Senior Acquisition Talent Partner, APAC

    Artificial Intelligence • Legal Tech • Software
    In-Office
    Sydney, New South Wales, AUS
    700 Employees

    ServiceNow Logo ServiceNow

    Architect

    Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
    Hybrid
    Sydney, New South Wales, AUS
    29000 Employees

    InterSystems Logo InterSystems

    Sales Manager

    Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Database • Analytics
    Easy Apply
    In-Office
    Sydney, New South Wales, AUS
    2100 Employees

    Similar Companies Hiring

    Onshore Thumbnail
    Artificial Intelligence • Fintech • Software • Financial Services
    New York, New York
    60 Employees
    Revel.io Thumbnail
    Aerospace • Hardware • Robotics • Software
    US
    50 Employees
    Blee Thumbnail
    Artificial Intelligence • Marketing Tech • Software
    New York, New York
    30 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account