Application Security Analyst

Rest Super

Sydney, City of Melbourne

Hybrid

AUD 120,000 - 160,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

5 Rest Days
Parental leave 22 weeks
AI & Data Academy
Income protection
Additional leave option
Rest Excellence Awards

Job summary

Rest Super is seeking an Application Security Analyst to strengthen security across our applications, APIs and software delivery practices. You will lead secure-by-design initiatives, collaborate with engineering and product teams, and drive risk-based remediation in a hybrid Sydney/Melbourne environment.

This 18-month fixed-term role focuses on embedding security into the development lifecycle, improving tooling, and guiding developers and security champions to strengthen our security posture

Qualifications

  • Experience in application security, DevSecOps or secure software development within a complex enterprise environment.
  • Experience conducting application security assessments across web apps, APIs and cloud-native environments.
  • Strong knowledge of OWASP Top 10, secure coding principles, threat modelling, vulnerability management and secure SDLC practices.
  • Hands-on experience with application security tools including SAST, DAST, SCA, API security testing and secrets detection.
  • Knowledge of ASVS, SAMM, NIST CSF and APRA CPS 234 frameworks.
  • Understanding of CI/CD pipelines, software delivery practices and cloud platforms, ideally AWS.
  • Familiarity with APIs, microservices and cloud-native environments.
  • Awareness of software supply chain risks and AI security considerations.
  • Strong analytical and communication skills for translating findings into actions.
  • Experience partnering with developers and delivery teams to improve security while supporting business goals.
  • Relevent security certifications welcomed but not essential.

Responsibilities

  • Lead application security assessments across web apps, APIs and cloud services, identifying risks and remediation plans.
  • Embed security into design through threat modelling and secure-by-design practices.
  • Validate, prioritise and manage findings with risk-based remediation guidance.
  • Drive the effectiveness of application security tooling (SAST/DAST/SCA, API security testing, secrets detection).
  • Promote secure SDLC and DevSecOps, integrating controls into CI/CD pipelines.
  • Coordinate penetration testing activities and oversee remediation outcomes.
  • Develop and maintain application security standards, guardrails and secure development practices.
  • Provide security guidance and enablement to developers, engineers and security champions.
  • Support security incident investigations related to vulnerabilities or insecure design.
  • Deliver security reporting, metrics and insights on risks and remediation performance.

Skills

Application security
DevSecOps
Threat modelling
SAST
DAST
SCA
OWASP Top 10
CI/CD security
AWS
Security tooling

Education

Bachelor's degree in Computer Science or Information Technology

Tools

SAST tools
DAST tools
SCA tools
Threat modelling tools

Job description

We’ve been around since 1988, and today we’re one of Australia’s largest profit‑to‑member super funds.

That means everything we do is focused on delivering better outcomes for our members – not shareholders.

Please note Rest does not accept speculative resumes from recruitment agencies

Rest will review applications prior to the closing date and may close the role earlier

Job Description
  • Shape and strengthen application security across Rest, one of Australia's largest profit-to-member super funds
  • Drive secure-by-design practices across modern cloud, API and DevSecOps environments
  • Partner with engineering, architecture and product teams to improve security outcomes at scale
  • Sydney or Melbourne Located - Hybrid Working - Blend of CBD Office and Remote

At Rest, we help more than 2 million Australians to build a better financial future. With around $112 billion in funds under management, we focus on delivering strong long-term outcomes for our members — from their first job through to retirement*. Your best at Rest means focusing on what matters, being trusted to get on with it, and knowing your work genuinely makes a difference. That’s how we operate every day, guided by our values: Be Daring, Keep It Simple, Take Action and Have Grit.

Join us as an Application Security Analyst on an 18 Month Fixed Term Contract. This is your opportunity to make a real contribution to the financial wellbeing of millions of Australians.

About the role

At Rest, we're committed to helping our members achieve a better retirement. As our Application Security Analyst, you'll play a critical role in strengthening the security of our applications, APIs and software delivery practices.

Working closely with engineering, architecture, product and technology teams, you'll lead application security initiatives, embed security into the development lifecycle, and provide pragmatic, risk-based guidance that supports secure delivery and innovation.

What you'll do
  • Lead application security assessments across web applications, APIs and cloud-based services, identifying risks and recommending appropriate treatment plans.
  • Partner with engineering and architecture teams to embed security into solution design through threat modelling and secure-by-design practices.
  • Validate, prioritise and manage application security findings, providing risk-based remediation guidance and distinguishing genuine risks from false positives.
  • Drive the effectiveness and continuous improvement of application security tooling, including SAST, DAST, SCA, API security testing and secrets detection.
  • Promote secure SDLC and DevSecOps practices, integrating security controls into CI/CD pipelines and software delivery processes.
  • Coordinate penetration testing activities, validate findings and oversee remediation outcomes.
  • Develop and maintain application security standards, guardrails and secure development practices.
  • Provide security guidance, education and enablement to developers, engineers and security champions.
  • Support security incident investigations where application vulnerabilities or insecure design may be contributing factors.
  • Deliver application security reporting, metrics and insights, highlighting emerging risks, remediation performance and overall security posture.
Qualifications
  • Bachelor's degree in computer science, Information Technology, or a related field (relevant work experience may be considered).

Required experience, understanding or credentials including:

  • Experience in application security, DevSecOps or secure software development within a complex enterprise environment, together with:
  • Experience conducting application security assessments across web applications, APIs and cloud-native environments.
  • Strong knowledge of OWASP Top 10, secure coding principles, threat modelling, vulnerability management and secure SDLC practices.
  • Hands-on experience with application security tools including SAST, DAST, SCA, API security testing and secrets detection.
  • Knowledge of application security assurance frameworks and standards such as OWASP ASVS, OWASP SAMM, NIST CSF and APRA CPS 234.
  • Understanding of CI/CD pipelines, software delivery practices and cloud platforms, ideally AWS.
  • Familiarity with modern application architectures, including APIs, microservices and cloud-native environments.
  • Awareness of software supply chain risks, open-source dependency management and security considerations for AI-enabled solutions.
  • Strong analytical and communication skills, with the ability to translate technical findings into clear, practical recommendations.
  • Experience partnering with developers, engineers, architects and delivery teams to improve security outcomes while supporting business objectives.
  • Relevant security certifications are welcomed but not essential.
Why Rest?

At Rest, you'll be part of a collaborative and inclusive culture where your work has meaningful impact. You'll have the opportunity to influence how security is embedded across our technology landscape while helping protect the services and experiences our members rely on every day.

Additional Information

.What you'll find at Rest

  • 5 Rest Days (wellbeing days) each year in addition to annual leave
  • Eligible employees are entitled to 22 weeks paid parental leave (gender neutral)
  • Learning and development opportunities, including AI & Data Academy, leadership programs, LinkedIn Learning, study assistance and professional memberships
  • Income Protection Insurance
  • Option to purchase additional leave
  • Recognition through our Rest Excellence Awards

If you share our values and this sounds like the kind of place you’d do your best work, we’d like to hear from you.

Rest is committed to creating a flexible work environment and culture that embraces diversity, equity, and inclusion - where people feel welcome, safe to be themselves and inspired to do their best.

We value the different backgrounds, lived experiences and abilities our diverse team brings. We welcome and encourage applications from candidates of all ages, cultural backgrounds, faiths, gender identities, sexual orientations and thinking styles. This includes people with disability, neurodiverse individuals, Aboriginal & Torres Strait Islander peoples and those with disrupted work history due to career or other breaks.

We welcome applications from all candidates. To be considered, you will need the right to work in Australia.

*Funds under management as at 30 June 2026. Rest is recognised as a superannuation leader across a range of areas including performance, responsible investment and member value. Find out more at

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

Rest • Sydney

Hybrid
AUD 110,000 - 140,000
5 Rest Days
Parental leave (22 weeks)
AI & Data Academy
+2
Application Security Analyst - 18 Month Fixed Term Contract
Application Security Analyst - 18 Month Fixed Term Contract

Rest • Sydney

Hybrid
AUD 140,000 - 210,000
Hybrid working
5 Rest Days (wellbeing days)
Paid parental leave (22 weeks)
+3
Cloud Security Engineer - CTEM
Cloud Security Engineer - CTEM

Rest • Sydney

Hybrid
AUD 120,000 - 150,000
Rest Days
Parental Leave
Learning & Development
+3
End User Computer Security Engineer - 12 Month Fixed Term Contract
End User Computer Security Engineer - 12 Month Fixed Term Contract

Rest • Sydney

Hybrid
AUD 120,000 - 160,000
5 Rest Days (wellbeing days)
Parental leave 22 weeks
Learning and development
+3
Senior Manager - Solutions & Remediation (9 Month Fixed Term Contract)
Senior Manager - Solutions & Remediation (9 Month Fixed Term Contract)

REST Industry Super • Sydney

Hybrid
AUD 180,000 - 240,000
Hybrid working
Generous parental leave
Senior Project Manager | 12 month FTC
Senior Project Manager | 12 month FTC

Rest • Sydney

Hybrid
AUD 140,000 - 210,000
5 Rest Days (wellbeing days)
22 weeks paid parental leave
AI & Data Academy
+3
Senior Change Manager, 12 month FTC at REST
Senior Change Manager, 12 month FTC at REST

REST • Sydney

On-site
AUD 140,000 - 180,000
Hybrid working
Rest Days 5 per year
Parental leave 22 weeks
Senior Project Manager | 12 month FTC
Senior Project Manager | 12 month FTC

REST Industry Super • Sydney

Hybrid
AUD 150,000 - 190,000
Hybrid working
5 Rest Days (wellbeing days)
22 weeks parental leave
+2
Solution Architect - 12 month FTC
Solution Architect - 12 month FTC

Rest • Sydney

On-site
AUD 180,000 - 240,000
Rest Days
AI & Data Academy
Learning & development
+1
Solution Architect - 12 month FTC
Solution Architect - 12 month FTC

Rest • City of Melbourne

On-site
AUD 140,000 - 190,000
5 Rest Days
22 weeks parental leave
AI & Data Academy
+1