Application Security Lead

randstad digital australia

City of Melbourne

On-site

AUD 140,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

randstad digital australia in Melbourne CBD seeks an experienced Application Security Specialist to own and operate the secure development lifecycle across a diverse software landscape. You will drive secure coding practices, threat modeling, and automated scanning tools integrated into active development workflows.

You will partner with engineering teams at varying security maturities, establishing standards, managing risk, and uplifting secure development without slowing delivery momentum.

Qualifications

  • 5+ years of software engineering experience, including some time focused on application security.
  • Experience with DevSecOps in modern CI/CD environments.
  • Hands-on in deploying, configuring, and optimizing AppSec tooling (SAST/DAST/SCA).
  • Strong background in Azure and Azure DevOps pipelines.
  • Proficient at secure code reviews across C#, .NET and web apps.
  • Deep understanding of OWASP Top 10 and secure design principles.
  • Ability to tailor AppSec strategy for teams with varying security maturity.
  • Excellent stakeholder engagement and communication skills.

Responsibilities

  • Own and operate application security end-to-end across the SDLC.
  • Identify and remediate security risks with Engineering teams.
  • Perform rigorous secure code reviews (primarily .NET).
  • Lead threat modeling sessions and formal security assessments.
  • Adapt AppSec processes for teams with different maturity levels.
  • Manage AppSec tooling integration (SAST/DAST/SCA) in CI/CD pipelines.
  • Maintain vulnerability visibility and risk prioritisation reporting.
  • Enforce secure design and development standards across the org.
  • Build Security Champions network across embedded teams.
  • Mentor developers to raise the baseline of secure coding.

Skills

Software engineering
Application security
DevSecOps
CI/CD pipelines
Azure
Azure DevOps
Secure code reviews
C#/.NET
OWASP Top 10
Stakeholder engagement

Tools

SAST
DAST
SCA

Job description

Summary

Opportunity to join a leading enterprise organisation to own and operate an established Application Security capability across a diverse software landscape. This role is focused on driving the integration of secure coding practices, threat modeling, and automated scanning tools directly into active development workflows. Operating in a hands-on technical capacity, you will partner closely with multiple engineering teams with varying security maturity levels to establish robust standardisations, manage application risk, and uplift secure development practices without compromising delivery momentum.

Location: Melbourne CBD

Key Criteria
  • 5+ years of software engineering experience, including at least 2+ years dedicated to an application security role.
  • Demonstrated expertise working within DevSecOps methodologies and modern CI/CD pipeline environments.
  • Hands-on experience deploying, configuring, and optimizing AppSec tooling including SAST, DAST, and SCA solutions.
  • Strong technical background operating within Azure environments and managing Azure DevOps pipelines.
  • Proficient in performing comprehensive secure code reviews, specifically across C#, .NET, and general web application architectures.
  • Deep domain understanding of OWASP Top 10 vulnerabilities and industry-standard secure design principles.
  • Proven capacity to tailor application security strategies to suit cross-functional teams with diverse security maturity levels.
  • Exceptional stakeholder engagement, communication, and self-management capabilities, balancing risk mitigation with delivery context.
Key Responsibilities
  • Own and operate application security end-to-end across the full Software Development Lifecycle (SDLC).
  • Identify and evaluate application security risks, partnering directly with Engineering teams to facilitate timely remediation.
  • Perform rigorous secure code reviews (primarily .NET) while actively fostering high-standard secure development practices.
  • Lead comprehensive threat modeling sessions and perform formal security assessments across core applications and automation workflows.
  • Adapt AppSec processes and controls to accommodate varying team maturity levels, achieving a balance between capability uplift, standardisation, and project delivery velocity.
  • Manage and optimize AppSec tooling integration (SAST, DAST, SCA) embedded within automated CI/CD pipelines.
  • Maintain end-to-end vulnerability visibility, establishing structured processes for risk prioritisation and leadership reporting.
  • Formulate and enforce secure design and development standards across the broader software organization.
  • Build and champion a Security Champions network across embedded engineering teams to drive decentralized security awareness.
  • Provide technical mentorship to software developers, continuously raising the baseline secure coding capability.
Experience

5 years

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Architect - Application Development, DevSecOps
Application Security Architect - Application Development, DevSecOps

Peoplebank • City of Melbourne

Hybrid
AUD 216,000 - 264,000
Up to $240k package
Permanent opportunity
Melbourne CBD location
+1
Senior Product Security Engineer
Senior Product Security Engineer

iterate • Council of the City of Sydney

Hybrid
AUD 150,000 - 210,000
Senior Product Security Engineer
Senior Product Security Engineer

iterate • City of Melbourne

On-site
AUD 140,000 - 180,000
AppSec Lead & Threat Modeling Champion
AppSec Lead & Threat Modeling Champion

randstad digital australia • City of Melbourne

On-site
AUD 140,000 - 180,000
Security Testing Lead: Expert in Pen Tests & Secure Coding
Security Testing Lead: Expert in Pen Tests & Secure Coding

The HR Ally • Sydney

On-site
AUD 150,000 - 230,000
.NET Technical Lead
.NET Technical Lead

Whizdom • Shire Of Laverton

On-site
AUD 110,000 - 150,000
Mission-critical platforms
Secure environment challenges
Collaborative team of professionals
+1
Application Security Technical Lead
Application Security Technical Lead

MedHealth • City of Melbourne

Hybrid
AUD 140,000 - 180,000
Hybrid work model
DevSecOps Engineer
DevSecOps Engineer

Peoplebank • City of Melbourne

Hybrid
AUD 100,000 - 160,000
6-month contract
Hybrid work (3 days onsite)
Melbourne CBD location near Southern/C
Security Testing Lead Specialist
Security Testing Lead Specialist

The HR Ally • Sydney

On-site
AUD 150,000 - 230,000
Security Testing Lead Specialist
Security Testing Lead Specialist

The HR Ally • City of Melbourne

On-site
AUD 140,000 - 190,000