Offensive Security Engineer — Hybrid (9–12 Month Contract)

NRMA

Sydney

Hybrid

AUD 140,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Travel discounts on SIXT car rental,
NRMA Holiday Parks & Resorts discounts
myNRMA Rewards with Roadside Assist &
Insurance discounts
Career growth opportunities

Job summary

NRMA is seeking an Offensive Security Engineer for its Technology team in Sydney Olympic Park. The role protects NRMA technology and data by identifying weaknesses, validating controls and supporting secure delivery across applications, APIs, cloud environments and security controls.

You will work with engineering, cloud, platform and security teams to embed security early in SDLC, reduce vulnerabilities, and provide evidence-based assurance in a complex enterprise environment.

Qualifications

  • Experience in cybersecurity, application security, penetration testing, security engineering or DevSecOps.
  • Strong knowledge of web application, API and cloud security.
  • Hands-on experience with security testing tools such as SAST, DAST and CSPM platforms.
  • Understanding of secure software development and CI/CD environments.
  • Experience identifying, validating and remediating security vulnerabilities.
  • Knowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST and PCI DSS.
  • Ability to automate tasks using scripting languages such as Python or PowerShell.
  • Strong analytical and problem-solving capabilities.
  • Excellent stakeholder engagement and communication skills.
  • Ability to provide practical, risk-based security advice to technical and business teams.
  • Relevant cybersecurity qualifications, certifications or equivalent industry experience.
  • A passion for emerging security technologies, automation and continuous improvement.

Responsibilities

  • Plan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services and cloud-hosted workloads.
  • Operate, administer and optimise security testing platforms, including SAST, DAST, CSPM and attack simulation tooling.
  • Embed security testing early in the software development lifecycle and support secure development practices across engineering teams.
  • Integrate application security, dependency, open-source risk, DAST and API security testing controls into code repositories, IDEs and CI/CD pipelines.
  • Conduct authorised penetration testing, technical security assessments, security design reviews and threat modelling for material changes.
  • Validate, triage and document security findings, including severity, business impact, accountable owners, target remediation dates and closure evidence.
  • Track remediation progress, retest resolved vulnerabilities and elevate overdue or material findings where required.
  • Use cloud security posture management tooling to assess cloud vulnerabilities, misconfigurations, attack paths and compliance posture.
  • Conduct MITRE ATT&CK-aligned control validation, adversary emulation and purple team activities across key security controls.
  • Provide practical remediation advice to engineering and technology teams, including guidance aligned to OWASP Top 10, PCI DSS secure coding requirements and secure AI development practices.
  • Automate repeatable discovery, testing, ticketing, evidence collection, reporting, remediation tracking and validation activities where practical.
  • Produce evidence-based reports, service metrics and control-effectiveness insights to support operational, executive, audit and governance reporting.

Skills

Cybersecurity
Application security
Penetration testing
Security engineering
DevSecOps
Web security
API security
Cloud security
SAST
DAST
CSPM
CI/CD security
Scripting (Python)
PowerShell
MITRE ATT&CK
OWASP Top 10
ISO 27001
NIST
PCI DSS
Communication skills

Tools

SAST tools
DAST tools
CSPM platforms

Job description

NRMA is seeking an Offensive Security Engineer for its Technology team in Sydney Olympic Park. The role protects NRMA technology and data by identifying weaknesses, validating controls and supporting secure delivery across applications, APIs, cloud environments and security controls.

You will work with engineering, cloud, platform and security teams to embed security early in SDLC, reduce vulnerabilities, and provide evidence-based assurance in a complex enterprise environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Engineer
Offensive Security Engineer

NRMA • Sydney

Hybrid
AUD 140,000 - 180,000
Travel discounts on SIXT car rental,
NRMA Holiday Parks & Resorts discounts
myNRMA Rewards with Roadside Assist &
+2
Head of Offensive Security & Penetration Testing
Head of Offensive Security & Penetration Testing

NSW Public Service Commission • Ryde

Hybrid
AUD 180,000 - 240,000
Security Analyst - Contract
Security Analyst - Contract

NCS • Sydney

On-site
AUD 120,000 - 150,000
Security Analyst - Contract
Security Analyst - Contract

NCS Australia • Sydney

On-site
AUD 120,000 - 180,000
Contract Security Analyst – External Attack Surface
Contract Security Analyst – External Attack Surface

NCS Australia • Sydney

On-site
AUD 120,000 - 180,000
Cyber Security Engineer - Hybrid, Growth & Training (Sydney)
Cyber Security Engineer - Hybrid, Growth & Training (Sydney)

Centorrino Technologies • Sydney

Hybrid
AUD 120,000 - 180,000
Senior Manager, Cyber Offensive
Senior Manager, Cyber Offensive

Transport For Nsw • Sydney

Hybrid
AUD 180,000 - 280,000
Application Security Analyst — Hybrid, 18‑Month FTC
Application Security Analyst — Hybrid, 18‑Month FTC

Rest • Sydney

Hybrid
AUD 110,000 - 140,000
5 Rest Days
Parental leave (22 weeks)
AI & Data Academy
+2
Senior Manager, Cyber Offensive
Senior Manager, Cyber Offensive

NSW Public Service Commission • Ryde

Hybrid
AUD 180,000 - 240,000
Senior Security Engineer – ANZ, Hybrid & Architect
Senior Security Engineer – ANZ, Hybrid & Architect

Goodman Fielder Pty Limited • Sydney

Hybrid
AUD 180,000 - 240,000
Hybrid work model