- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Company
Davidson Technology is partnering with a prominent Regional Council to provide a Penetration Tester who will support the Cyber Security and ICT Governance Service within an extensive program. This position is offered as an initial 12-month contract, with the possibility of two additional extensions lasting one year each.
Role Overview
The Penetration Tester will deliver specialist cybersecurity assurance and conduct technical security assessments aimed at enhancing the Council's cyber maturity, ICT governance, and operational resilience. The role involves thorough evaluation of the Council's ICT systems to uncover vulnerabilities and security gaps through structured penetration tests and assurance exercises. Responsibilities include identifying potential attack vectors, verifying the effectiveness of existing security controls, and providing clear, actionable, risk-informed remediation guidance.
You will collaborate closely with the Council's internal ICT team, managed service providers, and external vendors, supporting activities like security monitoring and incident response readiness, while contributing continuously to the advancement of cybersecurity practices.
This role also encompasses translating technical vulnerability findings into practical remediation strategies and insightful risk communication, assisting governance improvements and executive-level reporting. The goal is to ensure that security risks are comprehensively understood, prioritized appropriately, and managed effectively within the complex environment of local government operations.
Candidate Profile
The ideal candidate is an experienced Penetration Tester with demonstrated practical skills in discovering, exploiting, and documenting security vulnerabilities across multifaceted ICT environments such as networks, infrastructure, web applications, APIs, cloud services, and identity management systems.
You should be well-versed in penetration testing methodologies, attack techniques, and security frameworks capable of evaluating control performance, recognizing realistic attack paths, and converting technical details into clear, risk-based recommendations intended for both technical teams and senior-level stakeholders.
You must exhibit strong expertise in vulnerability assessments, security testing, threat analysis, and reporting, complemented by excellent communication and stakeholder engagement abilities. The capacity to work cooperatively with internal ICT teams, managed service providers, and third parties is essential.
Industry certifications like OSCP, CREST, GPEN, or equivalents are highly preferred.
Contract Details and Benefits
This fully remote role is offered as a 12-month contract with a competitive daily rate and includes the potential for two further 12-month extensions.
Application Instructions
Applicants are requested to submit their resumes in Microsoft Word format (.doc or .docx) only.