Offensive Security Engineer

The NRMA

City of Parramatta Council

Hybrid

AUD 110,000 - 150,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flexible work arrangements
Travel discounts
NRMA Rewards membership
Insurance discounts
Career growth opportunities

Job summary

The NRMA is looking for an Offensive Security Engineer to join our Technology team in Sydney Olympic Park. You will protect NRMA technology and data by identifying weaknesses, validating controls and supporting safer delivery across our environment.

You’ll work with engineering, cloud, platform, infrastructure and security teams to embed security early in SDLC, reduce production vulnerabilities and provide assurance across applications, APIs and cloud environments.

Qualifications

  • Experience in cybersecurity, application security, penetration testing, security engineering or DevSecOps.
  • Strong knowledge of web application, API and cloud security.
  • Hands-on experience with security testing tools such as SAST, DAST and CSPM platforms.
  • Understanding of secure software development and CI/CD environments.
  • Experience identifying, validating and remediating security vulnerabilities.
  • Knowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST and PCI DSS.
  • Ability to automate tasks using scripting languages such as Python or PowerShell.
  • Strong analytical and problem-solving capabilities.
  • Excellent stakeholder engagement and communication skills.
  • Ability to provide practical, risk-based security advice to technical and business teams.
  • Relevant cybersecurity qualifications, certifications or equivalent industry experience.
  • A passion for emerging security technologies, automation and continuous improvement.

Responsibilities

  • Plan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services and cloud-hosted workloads.
  • Operate, administer and optimise security testing platforms, including SAST, DAST, CSPM and attack simulation tooling.
  • Embed security testing early in the software development lifecycle and support secure development practices across engineering teams.
  • Integrate application security, dependency, open-source risk, DAST and API security testing controls into code repositories, IDEs and CI/CD pipelines.
  • Conduct authorised penetration testing, technical security assessments, security design reviews and threat modelling for material changes.
  • Validate, triage and document security findings, including severity, business impact, accountable owners, target remediation dates and closure evidence.
  • Track remediation progress, retest resolved vulnerabilities and elevate overdue or material findings where required.
  • Use cloud security posture management tooling to assess cloud vulnerabilities, misconfigurations, attack paths and compliance posture.
  • Conduct MITRE ATT&CK-aligned control validation, adversary emulation and purple team activities across key security controls.
  • Provide practical remediation advice to engineering and technology teams, including guidance aligned to OWASP Top 10, PCI DSS secure coding requirements and secure AI development practices.
  • Automate repeatable discovery, testing, ticketing, evidence collection, reporting, remediation tracking and validation activities where practical.
  • Produce evidence-based reports, service metrics and control-effectiveness insights to support operational, executive, audit and governance reporting.

Skills

Cybersecurity
Penetration testing
SAST/DAST
Cloud security
CI/CD
Scripting (Python/PowerShell)
Stakeholder communication
Security awareness
Threat modelling

Education

Bachelor's or higher in Cybersecurity or related field

Tools

SAST
DAST
CSPM
Attack simulation tooling

Job description

We have an exciting opportunity for an Offensive Security Engineer to join our Technology team based in Sydney Olympic Park. This role plays an important part in protecting the confidentiality, integrity, availability and resilience of NRMA technology and data by identifying exploitable weaknesses before they cause harm, validating the effectiveness of security controls, and supporting safer delivery across our technology environment.

Reporting to the Senior Manager, Security Compliance & Governance, you’ll work closely with engineering, cloud, platform, infrastructure, architecture and security teams to embed security early in the software development lifecycle, reduce vulnerabilities reaching production, and provide evidence‑based assurance across applications, APIs, cloud environments and security controls.

This is a hands‑on role for someone who enjoys practical security testing, automation, threat emulation, vulnerability lifecycle management and working with technical teams to improve security outcomes in a complex enterprise environment.

This 9-12 month maximum term contract role offers a hybrid work arrangement across our Sydney Olympic Park, Sydney CBD offices and working from home, as agreed and required for the role.

What You’ll Do
  • Plan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services and cloud-hosted workloads.
  • Operate, administer and optimise security testing platforms, including SAST, DAST, CSPM and attack simulation tooling.
  • Embed security testing early in the software development lifecycle and support secure development practices across engineering teams.
  • Integrate application security, dependency, open‑source risk, DAST and API security testing controls into code repositories, IDEs and CI/CD pipelines.
  • Conduct authorised penetration testing, technical security assessments, security design reviews and threat modelling for material changes.
  • Validate, triage and document security findings, including severity, business impact, accountable owners, target remediation dates and closure evidence.
  • Track remediation progress, retest resolved vulnerabilities and elevate overdue or material findings where required.
  • Use cloud security posture management tooling to assess cloud vulnerabilities, misconfigurations, attack paths and compliance posture.
  • Conduct MITRE ATT&CK‑aligned control validation, adversary emulation and purple team activities across key security controls.
  • Provide practical remediation advice to engineering and technology teams, including guidance aligned to OWASP Top 10, PCI DSS secure coding requirements and secure AI development practices.
  • Automate repeatable discovery, testing, ticketing, evidence collection, reporting, remediation tracking and validation activities where practical.
  • Produce evidence‑based reports, service metrics and control‑effectiveness insights to support operational, executive, audit and governance reporting.
What You’ll Bring
  • Experience in cybersecurity, application security, penetration testing, security engineering or DevSecOps.
  • Strong knowledge of web application, API and cloud security.
  • Hands‑on experience with security testing tools such as SAST, DAST and CSPM platforms.
  • Understanding of secure software development and CI/CD environments.
  • Experience identifying, validating and remediating security vulnerabilities.
  • Knowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST and PCI DSS.
  • Ability to automate tasks using scripting languages such as Python or PowerShell.
  • Strong analytical and problem‑solving capabilities.
  • Excellent stakeholder engagement and communication skills.
  • Ability to provide practical, risk‑based security advice to technical and business teams.
  • Relevant cybersecurity qualifications, certifications or equivalent industry experience.
  • A passion for emerging security technologies, automation and continuous improvement.
What's in it for you?

At the NRMA we aren’t just about discounts (although you do get these too). We offer benefits to help make work and life just right for you!

  • Progressive flexibility, leave and well‑being benefits to balance all of life's priorities
  • Travel discounts on SIXT car rental, cruises, and accommodation at our award‑winning NRMA Holiday Parks and Resorts
  • Complimentary myNRMA Rewards membership including free Roadside Assistance & discounts on groceries, movie tickets, gift cards, gym memberships, attractions, restaurants and much more
  • Discounts on a range of NRMA personal insurance products including car, home & travel
  • Grow, progress or relocate your career and move around the NRMA Group or different locations with us.
Know you belong

We're for inclusion, diversity and representing the members, guests, customers and communities we serve. That's why we welcome applications from First Nations, people with disability, those from diverse cultural backgrounds, people of all genders, members of the LGBTQI+ community, and anyone else who wants to be a part of our team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hands-On Offensive Security Engineer - App & Cloud Security
Hands-On Offensive Security Engineer - App & Cloud Security

The NRMA • City of Parramatta Council

Hybrid
AUD 110,000 - 150,000
Flexible work arrangements
Travel discounts
NRMA Rewards membership
+2
Technical Support Specialist
Technical Support Specialist

My NRMA • Sydney

On-site
AUD 75,000 - 100,000
Technical Support Specialist
Technical Support Specialist

The NRMA • Sydney

On-site
AUD 75,000 - 105,000
Flexible work options
Travel discounts and memberships
NRMA membership and perks
Training and Knowledge Lead
Training and Knowledge Lead

The NRMA • City of Parramatta

Hybrid
AUD 120,000 - 180,000
Progressive flexibility
Travel discounts on SIXT car rental,\u
Complimentary My NRMA membership with\
+2
Senior Tax Analyst
Senior Tax Analyst

The NRMA • Sydney

Hybrid
AUD 120,000 - 150,000
Hybrid work model
Travel discounts
myNRMA Rewards membership
Team Coordinator- Roadside Contact Centre
Team Coordinator- Roadside Contact Centre

The NRMA • City of Parramatta

Hybrid
AUD 90,000 - 110,000
Progressive flexibility & well-being benefits
Travel discounts on rentals, cruises, and accommodations
Complimentary myNRMA membership with benefits
+2
Training and Knowledge Lead
Training and Knowledge Lead

My NRMA • Sydney

Hybrid
AUD 120,000 - 160,000
Hybrid work model
Travel discounts on NRMA services and
Complementary My NRMA membership and R
Senior Manager, Cyber Offensive
Senior Manager, Cyber Offensive

NSW Public Service Commission • Ryde

Hybrid
AUD 180,000 - 240,000
Senior Manager, Cyber Offensive
Senior Manager, Cyber Offensive

Transport for NSW • Sydney

Hybrid
AUD 180,000 - 250,000
Hybrid work arrangement
Flexible work options
Inclusion programs
Training and Knowledge Lead
Training and Knowledge Lead

NRMA • City of Parramatta

Hybrid
AUD 140,000 - 190,000
Flexible working arrangements
Travel discounts (SIXT, cruises, NRMA)
NRMA membership with Roadside
+2