XPT Software Australia

Security Testing Lead Specialist

XPT Software Australia

Carlton, Victoria, Australia · Full Time

Be the first to apply

Experience
8+ yrs
Salary
Openings
1
Posted
3 days ago
Work mode
In office
Education
Tertiary qualification in Electrical/Electronic Engineering, Computer Science, Network or Software Engineering, Cyber Security, IT or related discipline
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Summary

We seek an experienced Security Testing Lead Specialist to spearhead comprehensive security evaluations across diverse systems. This role involves conducting advanced penetration testing, vulnerability analysis, and secure code reviews, focusing on actionable exploit scenarios and attack path development. The specialist will serve as a technical authority, providing expert guidance and leadership in security testing and secure software development within a large-scale corporate setting.

Key Responsibilities

  • Lead and execute intricate, high-assurance security assessments including penetration tests and vulnerability evaluations emphasizing realistic exploitability.
  • Assume a subject matter expert role for security testing, acting as the escalation point for challenging vulnerability analyses and adversary simulation exercises.
  • Assess system effectiveness in safeguarding organizational data and maintaining operational integrity; formulate strategic recommendations to enhance security resilience.
  • Detect and corroborate critical vulnerabilities, attack vectors, and exploit opportunities through analysis of automated scan results and manual tests.
  • Communicate technical risk findings clearly to business stakeholders to inform risk-based decisions and prioritize remediation efforts.
  • Drive continuous improvements in security testing methodologies, strategies, and standards, aligning with evolving industry best practices.
  • Collaborate closely with senior security leaders and cyber teams to define capability development and operational directions.
  • Review current security controls against industry standards; advise on enhancements to close gaps and elevate security maturity.
  • Ensure delivery of comprehensive, high-quality security assessment reports that elucidate risks, impacts, and mitigation advice.
  • Mentor and guide team members at all levels to enhance overall security testing capabilities.
  • Apply pragmatic, risk-based approaches balancing security requirements with business priorities and timelines.
  • Adhere to organizational Health, Safety and Environment (HSE) policies and regulatory compliance.

Additional Duties

  • Provide domain-wide technical leadership including leading multi-technical domain assessments and responding to escalated incidents.
  • Contribute to the development and refinement of penetration testing, vulnerability assessment, and secure coding methodologies, standards, and roadmaps.
  • Deliver training sessions to junior staff and wider organizational teams to uplift security competencies.
  • Champion shift-left security practices to facilitate rapid delivery of secure software.
  • Offer architectural guidance for application security and secure design principles.
  • Create automation scripts and support initiatives to enhance security testing efficiency.
  • Develop and optimize engagement processes, secure artefacts, security criteria, and test cases.
  • Engage with third-party vendors and acquired companies to evaluate and improve their security practices.
  • Perform quality assurance on Secure Code team deliverables to maintain technical excellence.
  • Navigates ambiguous and complex requirements to consistently produce outcomes aligned with cybersecurity goals.
  • Translate technical vulnerabilities into understandable business risk promptly, leveraging wider cyber security insights.
  • Balance business objectives with security standards, costs, timelines, and risks in a pragmatic manner.

Essential Qualifications and Experience

  • At least 8 years of professional experience in security testing roles.
  • Proficiency in diverse software delivery methodologies including DevOps and Waterfall.
  • Extensive experience performing complex security evaluations in large corporate environments.
  • Skilled in integrating automated security testing tools into CI/CD pipelines.
  • Strong hands-on experience with security assessment tools such as vulnerability scanners, static code analysis, and software composition analyzers.
  • Ability to critically review and provide actionable feedback on security reports.
  • Comprehensive understanding of application security architecture concepts including transport security, authentication, authorization, threat modeling, logging, and monitoring.
  • Experience in mentoring and developing junior staff.
  • Academic qualifications in Electrical/Electronic Engineering, Computer Science, Network or Software Engineering, Cyber Security, IT, or related disciplines.
  • Demonstrated advanced skills exceeding certifications like OSCE/OSWE or CREST within relevant domains.

Highly Beneficial Credentials and Skills

  • Previous background as a software developer or engineer is a considerable advantage.
  • Experience creating security policies, standards, and development guidelines.
  • Familiarity with other cybersecurity fields beyond security testing.
  • Solid grasp of related security technologies including endpoint protection, application platforms, databases, network security technologies, and development frameworks.
  • Current industry certifications such as OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); and (ISC)2 certifications like CISSP and CCSP.
  • Experience managing external security vendor engagements.
  • Proven track record in exploit development and zero-day vulnerability discovery.

Minimum education

Bachelor's Degree

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer