Application Security Technical Lead

MedHealth

City of Melbourne

Hybrid

AUD 140,000 - 180,000

Full time

16 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

MedHealth is seeking an experienced Application Security Technical Lead to own and run application security across the SDLC, with hands-on responsibility to embed secure practices, tooling and processes into development workflows.

You will collaborate with multiple development teams, uplift security maturity, perform secure code reviews (C#, .NET) and lead threat modelling and security assessments across applications and automation workflows. Hybrid work arrangement offered.

Qualifications

  • 5+ years' experience in software engineering including 2+ in an application security role.
  • Strong experience with DevSecOps and CI/CD environments
  • Hands-on experience with AppSec tools (SAST, DAST, SCA)
  • Strong experience working in Azure environments and Azure DevOps pipelines
  • Comfortable reviewing code (C#, .NET, web applications)
  • Strong understanding of OWASP Top 10 and secure design principles
  • Experience working across multiple teams or platforms with varying maturity levels
  • Able to adapt approach based on risk, complexity and delivery context
  • Self-driven, accountable and strong at stakeholder engagement

Responsibilities

  • Own and operate application security across the SDLC
  • Identify and assess application security risks, partnering with Engineering teams on remediation
  • Perform secure code reviews (primarily .NET) and support secure development practices
  • Lead threat modelling and security assessments across applications and automation workflows
  • Adapt security practices to suit different team maturity levels, balancing uplift, standardisation and delivery needs
  • Own and optimise AppSec tooling (SAST, DAST, SCA) across CI/CD pipelines
  • Ensure effective security testing without impacting delivery velocity
  • Own vulnerability visibility, prioritisation and reporting
  • Define and apply secure design and development standards
  • Establish Security Champions across development teams
  • Mentor developers and uplift secure coding capability across teams

Skills

Software engineering
Application Security
DevSecOps
CI/CD
Azure
OWASP Top 10
Code review
Stakeholder engagement

Tools

SAST
DAST
SCA

Job description

MedHealth are a purpose-built collection of industry leading health, medical and employment brands. Our unique and diverse capabilities come together to get the best possible health and employment outcomes for you and the people you support. We support whole populations to better outcomes, yet never lose sight of the individual we are working with to build a better life through work and health.

Job Description

We're looking for an experienced Application Security Technical Lead to own and run application security across MedHealth.

This is a hands-on role responsible for operating and continuously improving an established AppSec capability - ensuring security practices, tooling and processes are effectively embedded into development workflows.

You will work across multiple applications and development teams, each with varying levels of application security maturity, tailoring your approach to uplift capability while maintaining delivery alignment.

Key responsibilities
  • Own and operate application security across the SDLC
  • Identify and assess application security risks, partnering with Engineering teams on remediation
  • Perform secure code reviews (primarily .NET) and support secure development practices
  • Lead threat modelling and security assessments across applications and automation workflows
  • Adapt security practices to suit different team maturity levels, balancing uplift, standardisation and delivery needs
  • Own and optimise AppSec tooling (SAST, DAST, SCA) across CI/CD pipelines
  • Ensure effective security testing without impacting delivery velocity
  • Own vulnerability visibility, prioritisation and reporting
  • Define and apply secure design and development standards
  • Establish Security Champions across development teams
  • Mentor developers and uplift secure coding capability across teams
Qualifications

What You'll Bring

  • 5+ years' experience in software engineering including 2+ in an application security role.
  • Strong experience with DevSecOps and CI/CD environments
  • Hands-on experience with AppSec tools (SAST, DAST, SCA)
  • Strong experience working in Azure environments and Azure DevOps pipelines
  • Comfortable reviewing code (C#, .NET, web applications)
  • Strong understanding of OWASP Top 10 and secure design principles
  • Experience working across multiple teams or platforms with varying maturity levels
  • Able to adapt approach based on risk, complexity and delivery context
  • Self-driven, accountable and strong at stakeholder engagement
Additional Information

Why you’ll love it here:

  • Ability to own and run a mature Application Security capability
  • Work across a diverse application landscape and multiple engineering teams
  • Work somewhere serious about cybersecurity done right.
  • A culture that values continuous improvement, learning, and knowledge sharing.
  • Great balance of working from home and office collaboration.

You are welcome here.

Our fast-growing team of more than 4,000 people around Australia represent a huge array of life experiences, skills and ways of thinking. We value all these differences.

We are an Equal Opportunity Employer, proudly welcoming people with disability including mental health conditions, people from diverse cultural and linguistic backgrounds, people from the LGBTQIA+ community, veterans, carers and Indigenous Australians to our team.

We are happy to adjust our recruitment process to support accessibility needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Service Desk Team Leader
IT Service Desk Team Leader

Methodist Medical Group • City of Melbourne

Hybrid
AUD 90,000 - 120,000
Hybrid work
Employee discounts
Novated leasing
+3
IT Service Desk Team Leader
IT Service Desk Team Leader

MedHealth • City of Melbourne

Hybrid
AUD 90,000 - 120,000
Hybrid work
Health insurance discounts
Novated leasing
+3
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Emmbr • Sydney

Hybrid
AUD 110,000 - 160,000
Hybrid work arrangement
IT Service Delivery Manager
IT Service Delivery Manager

MedHealth • City of Melbourne

Hybrid
AUD 140,000 - 180,000
Hybrid work arrangement
Desktop Support Technician
Desktop Support Technician

Methodist Medical Group • City of Melbourne

Hybrid
AUD 65,000 - 90,000
Hybrid work
Health discounts
Novated leasing
+3
Head of Cyber Security
Head of Cyber Security

hipages Group • Sydney

Hybrid
AUD 200,000 - 300,000
Hybrid work model
Career development
Learning opportunities
+1
Senior Application Engineer
Senior Application Engineer

Medibank • City of Melbourne

On-site
AUD 120,000 - 170,000
DevSecOps Engineer
DevSecOps Engineer

Transport for NSW • Sydney

On-site
AUD 120,000 - 160,000
Head of Product Security
Head of Product Security

Talenza • Council of the City of Sydney

Hybrid
AUD 180,000 - 260,000
Competitive salary package
Bonus
Flexible working arrangements
Workplace Security Architect
Workplace Security Architect

Macquarie Group • Sydney

Hybrid
AUD 120,000 - 160,000
Wellbeing leave
Service bonus leave
Paid parental leave
+3