Penetration Tester - Deloitte Global Technology Team
Melbourne, Victoria, Australia · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join the Deloitte Global Technology team as a Penetration Tester and immerse yourself in a dynamic, innovative workplace. This position involves delivering penetration testing services by leveraging both advanced technology and manual expertise within Deloitte's cyber services organization worldwide.
Key Responsibilities
- Assist with the technical scope definition for security testing engagements
- Perform vulnerability assessments including Web Application, API, Network, Mobile, and Thick Client Penetration Testing
- Engage in targeted security research during downtime between projects
- Offer clear, actionable consulting to clients both verbally and in written reports regarding security findings
- Contribute to refining testing processes, methodologies, and documentation
- Maintain current knowledge through continuous training
- Analyze and comprehend complex system architectures
- Effectively communicate team services and capabilities to clients and stakeholders
Team Environment
Deloitte Technology drives innovation in technology and processes globally, focusing on what is possible to connect and protect Deloitte's internal and external communities.
Candidate Profile
- Minimum of five years' experience in penetration testing
- Proficiency with tools such as Burp Suite, OWASP ZAP, Metasploit, Postman, Swagger, NMAP, Qualys, and SQLMap
- Experience with Kali Linux or similar penetration testing operating systems
- Advanced knowledge in mobile and application penetration testing, including security architectural principles
- Insight into software security weaknesses and vulnerabilities
- Familiarity with at least one scripting language and one programming language/framework
- Proven ability to collaborate with diverse global stakeholders
- Capable of managing multiple projects simultaneously and prioritizing tasks effectively
- Strong verbal and written communication skills
Preferred Qualifications
- Certifications such as CEH, OSCP, or GIAC (e.g., GSEC, GWAB, GPEN)
- Knowledge of OWASP Top 10 for Applications, APIs, Thick Clients, and LLMs
- Experience with the MITRE ATT&CK Framework
- Cloud services testing
- Reverse engineering techniques
- Expertise in Static and Dynamic Application Security Testing (SAST & DAST)
- Understanding of agentic development related to penetration testing support
Why Work with Deloitte?
At Deloitte, impactful and stimulating work is at the core. The organization fosters continuous learning, innovation, and career growth through mentorship and coaching programs. Diversity, equity, and inclusion thrive here, ensuring a safe, welcoming environment where varied perspectives are valued. Flexible working arrangements facilitate work-life balance along with benefits like retail discounts, wellbeing leave, paid volunteering, extensive parental leave, and return-to-work support.