Australia Post

Penetration Tester / Application Security Specialist

Australia Post

Cremorne, Victoria, Australia · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
2 weeks ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

Join Australia Post's technology team where innovation meets collaboration. As an Application Security Specialist, you will be instrumental in safeguarding the organization's digital assets by identifying vulnerabilities, conducting penetration tests, and validating security across web applications, APIs, and modern platforms. Working closely with engineering, architecture, product, and cyber security teams, you will embed security deeply into the software development lifecycle, enabling secure and fast delivery of solutions. This role suits hands-on penetration testers passionate about uncovering risks and influencing security enhancements.

Key Responsibilities

  • Lead penetration testing and security validation for web applications, APIs, and modern technology stacks.
  • Collaborate with engineering teams to improve secure SDLC practices via threat modelling, security advisory, and actionable remediation support.
  • Promote and optimize application security tools such as SAST, SCA, DAST, and CI/CD security controls.
  • Utilize AI-assisted security testing approaches while ensuring all activities are authorized, governed, and guided by human oversight.

Candidate Profile

You are a technically skilled and inquisitive security professional, enjoying direct engagement with offensive security tasks and aiding teams in secure development. Your communication skills enable you to convey complex technical issues to diverse stakeholders effectively, using risk-based strategies to drive security outcomes. You thrive solving challenging problems and embracing continuous learning across varied enterprise-scale technologies.

Essential Qualifications

  • Proven hands-on penetration testing expertise on web applications and APIs, encompassing scoping, execution, reporting, and verification of fixes.
  • Background in Application Security, Security Engineering, or DevSecOps, with experience integrating SAST, SCA, and CI/CD security measures.
  • Familiarity with cloud platforms (AWS, Azure, GCP), threat modelling, secure design principles, and AI/LLM security concepts and testing methodologies.

Additional Benefits and Culture

  • Be part of one of Australia’s largest technology environments protecting digital, cloud, mobile, and operational platforms impacting millions.
  • Join a collaborative Cyber Defence team emphasizing knowledge sharing and ongoing learning.
  • Access a broad spectrum of technology and security tools, fostering abundant opportunities for growth.
  • Experience an inclusive workplace welcoming diverse backgrounds, with flexible working options including two work-from-home days weekly.
  • Benefit from formal programs and mentoring for professional development.
  • Enjoy exclusive team discounts, evolving flexible policies, and health and wellbeing resources.

Diversity and Inclusion

Australia Post values diversity and strives to create an equitable and accessible workplace. The recruitment process and environment are supportive of people from all identities—including Aboriginal and Torres Strait Islander peoples, individuals with disabilities, LGBTQIA+ communities, and refugees. The company holds a Disability Confident Recruiter status and works to promote gender equity and remove bias through inclusive initiatives.

How they work

Communication Teamwork & Collaboration Problem Solving Learning Agility Persuasion & Influence
🤖
Online · instant AI help
Broxer