Get more replies from employers
Send a job-specific resume in minutes.
Best Practice Software in Australia is seeking a senior Information Security Specialist to embed with our product teams from design onwards. You’ll shape architecture decisions, drive threat modelling, and ensure security is built into our development lifecycle.
You’ll own and tune SAST/DAST tooling in CI/CD, manage penetration testing engagements, and help lead our OWASP SAMM maturity roadmap alongside the security directorate, across Bundaberg and Brisbane.
At Best Practice Software, our vision is communities connected with care. We’re achieving this through our mission to build a culture people love, where:
If you share our vision and values, please consider this exciting career opportunity to join our growing team in Bundaberg or Brisbane, Queensland.
Bp Premier sits inside thousands of Australian general practices and touches the health records of millions of people. The security decisions made in our products matter — and this role is where they get made well. At Best Practice Software, our vision is communities connected with care, and application security is at the core of how we deliver it.
This is a senior, embedded security partner role, not an advisory position. You'll sit within our security directorate but spend much of your time embedded with our product teams and developers, from design onwards — the kind of person who would rather influence a design decision early than write a findings report about it later, and who demonstrates the ability to apply knowledge directly into our product planning and delivery processes.
You’ll have modern tooling behind you (SAST, DAST, CI/CD pipelines, Kubernetes) and a security maturity roadmap (OWASP SAMM) to help drive.
As an Information Security Specialist, we’ll call on your unique talents, skills, expertise, and experience to:
1. Practical offensive testing skills — you can penetration test web applications, APIs and services to a professional standard, working manually beyond automated tooling and demonstrating real exploitability rather than forwarding scanner output
2. Structured threat modelling — you can facilitate threat modelling sessions with architects and developers using recognised approaches (STRIDE, attack trees or similar), and turn the results into prioritised, actionable engineering work
3. Turning risk into clear security requirements — you can translate regulatory, contractual and risk-based drivers into specific, testable security requirements that fit how delivery teams actually work: user stories, acceptance criteria and definition of done, not a separate document nobody reads
4. A remediation mindset, not just a findings mindset — you recommend proportionate, practical controls, talk credibly about trade-offs, compensating controls and residual risk with engineers and risk owners alike, and stay involved until the issue is genuinely closed
5. Credibility with development teams — you explain risk in terms engineers care about, challenge constructively without becoming a blocker, and build enough trust that teams come to you for advice before they build rather than after
Our team members enjoy exclusive access to our brilliant B-Perks Program, offering great rewards like birthday leave, an annual health and wellbeing bonus, and sponsored rewards to recognise outstanding contributions. You’ll also access our leadership development program and learning opportunities across our group of businesses and enjoy the freedom and flexibility to work as you work best. We offer purpose and impact, an inclusive culture, a connected workforce, transparent leadership, and growth and belonging.