Senior Penetration Tester
Sydney, New South Wales, Australia · Full Time
Be the first to apply
- Experience
- 3–5 yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Gridware
Gridware stands as a leading cybersecurity firm in Australia, committed to helping organizations stay ahead of evolving threats by delivering highly tailored strategies underpinned by technical expertise. Their solutions span diverse industries, designed to be not only compliant but also intelligent, scalable, and sustainable.
Role Overview
We are looking for an experienced Senior Penetration Tester to join our team full-time. This position entails leading complex security assessments including traditional penetration testing and advanced adversary simulations. The successful candidate will play a key role in refining testing methodologies, mentoring junior consultants, and strengthening client partnerships while promoting innovation within the team.
Key Responsibilities
- Conduct Red Team operations involving command and control infrastructure, payload creation, evasion techniques, and physical as well as social engineering tactics.
- Perform penetration tests and security evaluations across cloud environments.
- Execute internal and external network and host penetration tests.
- Assess web applications, APIs, and mobile applications for vulnerabilities.
- Conduct wireless security assessments.
- Define scope of engagements, participate in rules of engagement discussions, and manage client expectations throughout assessment cycles.
- Communicate technical findings clearly to both technical teams and management, emphasizing risk alignment.
- Produce clear, concise reports with actionable remediation plans tailored to client priorities.
- Mentor, guide, and peer review junior staff, contributing to the development and evolution of methodologies.
- Assist with proposal creation, pre-sales activities, and help in crafting new service offerings.
Candidate Requirements
- 3 to 5 years of experience in offensive security consulting, with a track record of managing and delivering complex projects.
- Demonstrated resilience and adaptability under pressure, successfully overcoming obstacles to deliver results.
- Possession of penetration testing certifications such as CRTO, CRTL, OSCP, CPTS, or SANS credentials like GXPN or GWAPT; CREST CCT qualifications considered a strong advantage though not mandatory.
- Exceptional analytical and problem-solving capabilities coupled with lateral thinking and creativity in addressing security challenges.
- Ability to evaluate applications and infrastructure with a dual focus on technical and business risk.
- Experience developing custom scripts or tools to enhance testing effectiveness.
- Excellent communication and stakeholder management skills, capable of simplifying complex security topics for diverse audiences.
- Proficiency in drafting structured, risk-prioritized remediation reports.
- A strong enthusiasm for offensive security, driven by curiosity, innovation, and continuous development.
- Eligibility to secure and maintain required security clearances.
- Confidence in delivering technical presentations at community events, conferences, or internal knowledge-sharing sessions.
Level
Senior
Industry
Cybersecurity