Penetration Tester

XPT Software Australia

City of Melbourne

On-site

AUD 150,000 - 210,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

XPT Software Australia is seeking an experienced Security Testing Lead Specialist to drive advanced assessments, oversight, and risk-based decision making. You will lead complex engagements, mentor the team, and shape testing strategies across multiple domains.

You will translate technical findings into business risk insights for remediation and work with cross-functional cyber security teams to uplift overall security maturity. This is a senior role requiring 8+ years in security testing.

Qualifications

  • Application Security Certification is mandatory.
  • Lead and deliver high-complexity, high-assurance security assessments across customer systems.
  • Provide authoritative technical leadership in security testing and secure development.
  • Translate technical findings into clear business risk insights for remediation.
  • Drive evolution of security testing strategy, methodologies and standards.

Responsibilities

  • Lead complex security testing engagements across multiple domains.
  • Act as escalation point for vulnerabilities, assessments and adversary emulation.
  • Assess controls and practices against standards and uplift security maturity.
  • Deliver high-quality security assessment reports with clear risk messaging.
  • Mentor senior and junior team members to uplift capability.
  • Collaborate with broader cyber security teams to shape capability development.
  • Translate vulnerabilities into business risk suitable for stakeholder decisions.
  • Develop training for junior team members and customers to uplift security capability.
  • Promote shift-left practices to deliver secure code faster.
  • Ensure reporting aligns with industry best practices and client requirements.

Education

Application Security Certification (mandatory)
OSCP/OSCE3/OSWE
CREST – CCSAS/CCSMM/CCSC
SANS – GPEN/GWAPT/GXPN
(ISC)2 – CISSP/CCSP

Job description

Requirements

JD – Security Testing - Lead Specialist

Minimum of 8 years’ experience in a Security Testing role


Must Have


  • Application Security Certification is mandatory.

  • Lead and deliver high-complexity, high-assurance security assessments across Customer’s systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

  • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

  • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

  • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

  • Translate technical findings into clear, actionable business risk insights, supporting informed decision-making and prioritised remediation.

  • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

  • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

  • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.

  • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

  • Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

  • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

  • Fulfil Health, Safety, and Environment responsibilities in accordance with organisational policies and regulatory requirements.


Additional Information


  • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

  • Provide input into Customer’s Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

  • Develop and deliver training for junior team members and the broader Customer community to uplift security capability.

  • Promote “shift-left” practices to enable the delivery of secure, high-quality code at speed.

  • Provide guidance on application security architecture and secure design considerations.

  • Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

  • Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

  • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

  • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

  • Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations

  • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

  • Confidential

  • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.


Current Industry Certification, Including But Not Limited To


  • Offensive Security – OSCP, OSCE3, OSWE


CREST – Certified Level Qualifications (CCT, CCSC, CCSAS, CCSAM)


  • SANS – GPEN, GAWN, GWAPT, GXPN.

  • (ISC)2 – CISSP, CCSP

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

XPT Software • City of Melbourne

On-site
AUD 140,000 - 190,000
Security Testing Lead Specialist
Security Testing Lead Specialist

XPT Software Australia Pty Ltd • Australia

On-site
AUD 120,000 - 190,000
Security Testing Lead Specialist - Contract - Australia
Security Testing Lead Specialist - Contract - Australia

Hastha Solutions • Sydney

On-site
AUD 166,000 - 240,000
Security Testing Lead
Security Testing Lead

Zone IT Solutions • Council of the City of Sydney

On-site
AUD 110,000 - 170,000
Security Testing Lead Specialist
Security Testing Lead Specialist

The HR Ally • Sydney

On-site
AUD 150,000 - 230,000
Security Testing Lead Specialist
Security Testing Lead Specialist

The HR Ally • City of Melbourne

On-site
AUD 140,000 - 190,000
Penetration Tester
Penetration Tester

Jobtailor • City of Brisbane

Hybrid
AUD 90,000 - 130,000
Security Testing Lead: Expert in Pen Tests & Secure Coding
Security Testing Lead: Expert in Pen Tests & Secure Coding

The HR Ally • Sydney

On-site
AUD 150,000 - 230,000
Penetration Tester
Penetration Tester

Synechron • Sydney

On-site
AUD 120,000 - 180,000
Penetration Tester
Penetration Tester

Calleo • City of Melbourne

Hybrid
AUD 120,000 - 150,000
Hybrid working arrangement
12 month contract with extension options
Opportunity to influence security posture