Cyber Security Assurance Testing Lead

University of New South Wales

Penrith City Council

Hybrid

AUD 140,000 - 170,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible Working Options
Career development opportunities
17% Superannuation
Extra leave over Christmas
Discounts and entitlements

Job summary

UNSW is seeking a Cyber Security Assurance Testing Lead to own and deliver testing across ICT services and initiatives within a risk-managed framework. Based in Kensington/Sydney, the role requires hands-on testing, reporting on findings, and guiding risk remediation with business owners.

The ideal candidate has extensive IT security operations experience, strong knowledge of security standards (ISO 27001, NIST, OWASP), and relevant certifications.

Qualifications

  • 6+ years of IT security services experience, 3+ years in penetration testing, vulnerability management, application security testing, source code review.
  • Experience in 1st line assurance role, working with vulnerability management and scanning systems.
  • Scripting in PowerShell, Python, Bash is advantageous.
  • AWS, Azure and Microsoft365 security experience desirable but not mandatory.
  • A relevant degree with extensive experience in cyber security operations or assurance teams within major organisations or an equivalent level of knowledge gained through any other combination of education, training, and experience.
  • Excellent understanding of industry-wide security standards and compliance frameworks such as ISO 27001, NIST 800-53, OWASP, CSA, Essential 8, PCI DSS, COBIT 5, Mitre ATT&CK.
  • Relevant industry certification(s) such as SANS certifications, CEH, OSCP, CompTIA Security+, and cloud platform certifications such as, AWS Security Specialty, Microsoft Azure (highly desirable).
  • Strong interpersonal, communication and negotiation skills including ability to develop effective relationships and influence key stakeholders at all levels in the organisation.
  • Analytical ability to present with credibility and translate technical and complex information concisely for diverse audiences using strong analytical and problem-solving skills.
  • Demonstrated high level of personal motivation, resilience, and ability to work effectively individually or in teams.
  • Experience in the use of automated vulnerability scanning, security validation, penetration testing, static and dynamic application security testing, and cloud posture management tools e.g. Pentera, Tenable.io, Checkmarx, Lacework, GuardDuty etc.
  • Ability to code in PowerShell, Python, Bash, etc is advantageous.
  • An understanding of and commitment to UNSW's aims, objectives and values in action, together with relevant policies and guidelines.
  • Knowledge of health & safety (psychosocial and physical) responsibilities and commitment to attending relevant health and safety training.

Responsibilities

  • Ensure that high and medium cyber risk rated information resources and services are regularly subjected to security testing which includes penetration tests, web application scanning, dynamic application security testing and API testing.
  • Proactively conduct automated penetration testing and vulnerability assessments of new and existing applications, systems, and networks using relevant tools.
  • Facilitate annual controls assurance testing including but not limited to annual penetration testing of high cyber risk rated assets, red teaming exercises, etc, with the support of cyber security analysts, internal team members and external testing partners.
  • Review, validate and triage findings from the manual and automated penetration tests, vulnerability scans, app security testing, CSPM tools, API testing, etc.
  • Update the cyber risk register with risks from controls assurance tests.
  • Communicate and report on controls assurance testing findings and associated risks, and work with business owners, control owners and operators to remediate and close findings/issues as per vulnerability remediation timeframes stipulated in in the University’s security standards.
  • Ensure the accurate and timely release of controls assurance testing reporting and metrics.
  • Regularly review threat and vulnerability advisories from various sources (e.g. ACSC, NCSC, CISA) and, where a high priority response is required across the organisation, collaborate with the Cyber Security Operations teams.
  • Contribute to the ongoing development and execution of a continuous control’s assurance testing approach, including monitoring, control uplift (incl. automation) and rationalisation.
  • Support the independent audit of cyber security controls on behalf of the University, including statutory audits completed by the Audit Office of NSW.
  • Maintain awareness of changes to legal, regulatory compliance and contractual obligations that are relevant to the University’s management of cyber security risks.
  • Promote awareness of the University’s internal and external environment for emerging cyber security threats.
  • Build effective working relationship with internal and external stakeholders to develop innovative solutions that meet business needs.
  • Promote a culture of continuous improvement, championing professional standards, innovation, and methods.
  • Other duties appropriate and in line with to this position as requested by the Cyber Security Controls Assurance Manager or the Cyber Security leadership team.
  • Align with and actively demonstrate the Code of Conduct and Values.
  • Cooperate with all health and safety policies and procedures of the university and take all reasonable care to ensure that your actions or omissions do not impact on the psychosocial or physical health and safety of yourself or others.
  • Ensure hazards and risks psychosocial and physical are identified and controlled for tasks, projects, and activities that pose a health and safety risk within your area of responsibility.

Skills

Penetration testing
Vulnerability management
Application security testing
Source code review
PowerShell scripting
Python scripting
Bash scripting
AWS security
Azure security
Microsoft 365 security
Communication skills
Negotiation skills
Problem solving

Education

Relevant degree
SANS CEH OSCP CompTIA Security+
AWS/Azure cloud certifications

Tools

Pentera
Tenable.io
Checkmarx
Lacework
GuardDuty

Job description

  • Full time continuing role within UNSW IT, Cyber Directorate - Cyber Security Assurance Testing Lead
  • Starting Salary $153,933 plus generous superannuation and leave loading
  • Kensington, Sydney location, 2-3 days in the office, Hybrid working
About UNSW:

UNSW isn’t like other places you’ve worked. Yes, we’re a large organisation with a diverse and talented community; a community doing extraordinary things. Together, we are driven to be thoughtful, practical, and purposeful in all we do. Taking this combined approach is what makes our work matter. It’s the reason we’re one of the top 20 universities in the world (QS top 20) and a member of Australia’s prestigious Group of Eight. If you want a career where you can thrive, be challenged and do meaningful work, you’re in the right place.

The Cyber Security Assurance Testing Lead maintains, delivers and administers Cyber Security Assurance Services within a fit-for-purpose and adaptive Cyber Security Risk Management framework. The role is responsible for the assurance testing of ICT services and IT initiatives, and the provision of cyber security subject matter expertise, controls assurance, and reporting services to university stakeholders. The Cyber Security Assurance Testing Lead reports to the Cyber Security Controls Assurance Manager and has no direct reports.

Accountabilities:
  • Ensure that high and medium cyber risk rated information resources and services are regularly subjected to security testing which includes penetration tests, web application scanning, dynamic application security testing and API testing.
  • Proactively conduct automated penetration testing and vulnerability assessments of new and existing applications, systems, and networks using relevant tools.
  • Facilitate annual controls assurance testing including but not limited to annual penetration testing of high cyber risk rated assets, red teaming exercises, etc, with the support of cyber security analysts, internal team members and external testing partners.
  • Review, validate and triage findings from the manual and automated penetration tests, vulnerability scans, app security testing, CSPM tools, API testing, etc.
  • Update the cyber risk register with risks from controls assurance tests.
  • Communicate and report on controls assurance testing findings and associated risks, and work with business owners, control owners and operators to remediate and close findings/issues as per vulnerability remediation timeframes stipulated in in the University’s security standards.
  • Ensure the accurate and timely release of controls assurance testing reporting and metrics.
  • Regularly review threat and vulnerability advisories from various sources (e.g. ACSC, NCSC, CISA) and, where a high priority response is required across the organisation, collaborate with the Cyber Security Operations teams.
  • Contribute to the ongoing development and execution of a continuous control’s assurance testing approach, including monitoring, control uplift (incl. automation) and rationalisation.
  • Support the independent audit of cyber security controls on behalf of the University, including statutory audits completed by the Audit Office of NSW.
  • Maintain awareness of changes to legal, regulatory compliance and contractual obligations that are relevant to the University’s management of cyber security risks.
  • Promote awareness of the University’s internal and external environment for emerging cyber security threats.
  • Build effective working relationship with internal and external stakeholders to develop innovative solutions that meet business needs.
  • Promote a culture of continuous improvement, championing professional standards, innovation, and methods.
  • Other duties appropriate and in line with to this position as requested by the Cyber Security Controls Assurance Manager or the Cyber Security leadership team.
  • Align with and actively demonstrate the Code of Conduct and Values.
  • Cooperate with all health and safety policies and procedures of the university and take all reasonable care to ensure that your actions or omissions do not impact on the psychosocial or physical health and safety of yourself or others.
  • Ensure hazards and risks psychosocial and physical are identified and controlled for tasks, projects, and activities that pose a health and safety risk within your area of responsibility.

Candidates do not need to meet every criterion to apply. We will consider equivalent skills and experience gained through diverse career paths, professional development, technical training and practical experience, alongside relevant desirable experience.

  • 6+ years of IT security services experience, 3+ years of experience in penetration testing, vulnerability management, application security testing, source code review.
  • Experience in 1st line assurance role, working with vulnerability management and scanning systems.
  • Scripting in PowerShell, Python, Bash, etc is advantageous.
  • AWS, Azure and Microsoft365 security experience desirable but not mandatory.
  • A relevant degree with extensive experience in cyber security operations or assurance teams within major organisations or an equivalent level of knowledge gained through any other combination of education, training, and experience.
  • Excellent understanding of industry-wide security standards and compliance frameworks such as ISO 27001, NIST 800-53, OWASP, CSA, Essential 8, PCI DSS, COBIT 5, Mitre ATT&CK etc.
  • Relevant industry certification(s) such as SANS certifications, CEH, OSCP, CompTIA Security+, and cloud platform certifications such as, AWS Security Speciality, Microsoft Azure (highly desirable).
  • Strong interpersonal, communication and negotiation skills including ability to develop effective relationships and influence key stakeholders at all levels in the organisation.
  • Analytical ability to present with credibility and translate technical and complex information concisely for diverse audiences using strong analytical and problem-solving skills.
  • Demonstrated high level of personal motivation, resilience, and ability to work effectively individually or in teams.
  • Experience in the use of automated vulnerability scanning, security validation, penetration testing, static and dynamic application security testing, and cloud posture management tools e.g. such as Pentera, Tenable.io, Checkmarx, Lacework, GuardDuty etc.
  • Ability to code in PowerShell, Python, Bash, etc is advantageous.
  • An understanding of and commitment to UNSW's aims, objectives and values in action, together with relevant policies and guidelines.
  • Knowledge of health & safety (psychosocial and physical) responsibilities and commitment to attending relevant health and safety training.
Benefits and Culture:
  • Flexible Working Options (work from home, flexible hours etc)
  • Career development opportunities
  • 17% Superannuation contributions and additional leave loading payments
  • Additional 3 days of leave over Christmas period
  • Discounts and entitlements (retail, education, fitness)

For further details on the benefits, please visit https://www.jobs.unsw.edu.au/lifestyle-benefits

Please note: Sponsorship is not available for this role; valid Australian working rights are required on application.

Pre-Employment Checks:

As part of our recruitment process candidates may be required to undergo pre-employment screening, which may include reference checks, qualification verification, right-to-work verification, and criminal history screening where relevant to the role.

Contact: Jen MacLachlan - Talent Acquisition Partner- e: j.maclachlan@unsw.edu.au

Applications close: Thursday 10th of September at 11.30pm

UNSW is committed to equity diversity and inclusion. Applications from women, people of culturally and linguistically diverse backgrounds, those living with disabilities, members of the LGBTIQ+ community; and people of Aboriginal and Torres Strait Islander descent, are encouraged. UNSW provides workplace adjustments for people with disability, and access to flexible work options for eligible staff.

The University reserves the right not to proceed with any appointment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead - Hybrid Role
Senior Incident Response Lead - Hybrid Role

UNSW • Sydney

Hybrid
AUD 180,000 - 260,000
Flexible Working Options
Career development opportunities
17% Superannuation contributions and 3
+2
Manager, Cyber Security Incident Response
Manager, Cyber Security Incident Response

University of New South Wales • Penrith City Council

Hybrid
AUD 180,000 - 240,000
Flexible Working Options
Career development opportunities
17% Superannuation contributions and 3
Manager, Cyber Security Incident Response
Manager, Cyber Security Incident Response

UNSW • Council of the City of Sydney

Hybrid
AUD 210,000 - 270,000
Flexible working options
Career development opportunities
Superannuation 17% + extra leave
+2
Principal Incident Response Analyst
Principal Incident Response Analyst

University of New South Wales • Penrith City Council

Hybrid
AUD 180,000 - 240,000
Hybrid working
Excellent salary package
Principal Incident Response Analyst
Principal Incident Response Analyst

UNSW • Sydney

Hybrid
AUD 180,000 - 260,000
Flexible Working Options
Career development opportunities
17% Superannuation contributions and 3
+2
Manager, Cyber Security Incident Response
Manager, Cyber Security Incident Response

University of New South Wales • Council of the City of Sydney

Hybrid
AUD 180,000 - 230,000
Flexible working options
Career development opportunities
17% Superannuation contributions
+2
Principal Incident Response Analyst
Principal Incident Response Analyst

UNSW Employees, Location, Alumni • Randwick City Council

Hybrid
AUD 180,000 - 240,000
Flexible Working Options
17% Superannuation
Leave loading + Christmas break
Test Analyst
Test Analyst

University of New South Wales • Penrith City Council

Hybrid
AUD 110,000 - 140,000
Product Manager - IT Services
Product Manager - IT Services

University of New South Wales • Randwick City Council

Hybrid
AUD 139,000 - 169,000
Flexible Working Options
17% Superannuation contributions and (
Product Manager - IT Services
Product Manager - IT Services

UNSW • Sydney

Hybrid
AUD 139,000 - 169,000
Flexible Working Options
Career development opportunities
17% Superannuation contributions and 3