Penetration Tester (Australia)

Packetlabs

Sydney

On-site

AUD 140,000 - 190,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Packetlabs is seeking an experienced security tester to join our penetration testing and consulting team. You will perform web, mobile, and API assessments, conduct source-code reviews, and reverse-engineer apps to reveal real impact for clients.

You will work with bleeding-edge tooling and collaborate across time zones; on-call or after-hours in line with Eastern Time alignment may be required. A strong OSCP/OSWE background is highly valued.

Qualifications

  • Experienced developer/application security tester joining a security consulting team.
  • Solid programming knowledge in multiple languages and frameworks.
  • Familiarity with web services and data formats (XML/JSON/SOAP/REST/AJAX).

Responsibilities

  • Penetration test web, mobile apps, thick clients, and APIs.
  • Perform source code review and whitebox testing to prove impact.
  • Reverse engineer mobile and thick client apps.
  • Chain flaws to other areas (cloud/AD) at manager's discretion.
  • Create detailed remediation reports and debrief at technical and executive levels.
  • Perform SAST/DAST on enterprise, SaaS, and custom apps.
  • Identify and eliminate false positives with scanners and validation.
  • Deep OWASP understanding across Web/API/Mobile/AI-LLM.

Skills

C
C#
Python
Objective-C
Java
JavaScript
SQL
AngularJS
AI/LLM security
Web/API security

Education

Post-secondary degree
OSCP
OSWE
BSCP

Tools

Burp Suite

Job description

Packetlabs was built by an ethical hacker after seeing vulnerability assessments presented as penetration tests. Our slogan "Ready for more than a VA scan?" drives at the importance of not providing our clients with a false sense of security.

We are a passionate team of highly trained, proactive, pentesters. We provide expert-level penetration testing services that are thorough and tailored to help foster a safe digital space where everyone has the right to privacy and security. Packetlabs consultants find weaknesses others overlook and continuously learn new ways to evade controls. We hold ourselves to a very high standard.

only hire individuals with the same drive and passion.

Note: While the position is based in Australia, initial onboarding and collaboration may involve some after-hours work to align with our Eastern Time Zone (Canada/US) team. Flexible scheduling options will be supported as the role transitions to standard local hours.

Who We Are Looking For
  • Core values:
    • You have a customer-first mentality. Is a great communicator with clients, project managers, and teammates. Rapid responses and on time.
    • You deliver work that you take pride in. Your work is an autograph of your excellence.
    • You dig deeper into every finding. Doesn't stop until impact is proven.
    • You are comfortable being uncomfortable. Goes towards obstacles, not away from them. Consulting isn't your typical job and requires adapting to rapidly changing environments.
    • You are always learning. Cybersecurity is changing every day, and you need to keep up or want to keep up. Be deeply aware of your skillset and be willing to improve.
    • You are self-motivated and dependable.
    • You are humble. Egos don't have a place at Packetlabs.
  • Education and experience:
    • We are looking for an experienced developer/application security tester to join our team:
    • Solid working knowledge of programming languages, including C, C#, Python, Objective-C, Java, JavaScript, SQL, and frameworks like AngularJS.
    • Familiarity with web services and data exchange formats such as XML, JSON, SOAP, REST, and AJAX.
    • Understanding of AI/LLM weaknesses and flaws in applications.
    • Extensive experience/expertise in using an attack proxy (e.g. Burp Suite)
  • Preferred if you have 3 - 5 years of experience working in penetration testing and consulting
  • A graduate of a post-secondary college or university degree program.
  • Has at least two years of experience dealing with information security-related tasks.
  • Has professional qualifications (one or more): OSCP, OSWE, BSCP.
  • OSCP or Burp is mandatory for our organization.
What You’ll Be Doing
  • Your primary role is to perform penetration testing of web applications, mobile applications, thick clients, and APIs.
  • Source code review and whitebox penetration testing to prove the impact of application flaws.
  • Reverse engineering of mobile and thick client applications.
  • You sometimes chain application flaws to other areas, such as cloud and on-prem AD infrastructure. Opportunities for lateral movement into the infrastructure teams are limited and given at the manager's discretion.
  • Develop detailed reports on findings and remediations for impactful findings. You will learn to debrief these findings at both a technical and executive level.
  • Perform SAST and DAST on enterprise, SaaS, and custom in-house applications.
  • Experience in using scanners and knowledge of validation and elimination of false positives.
  • A strong understanding of OWASP in Web, API, Mobile, and AI/LLM is necessary, but you will be asked to go beyond.
Why us?
  • Immediate and continual offensive security training
  • Amazing team and working environment
  • Competitive compensation and growth opportunity
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Tester (Australia)
Penetration Tester (Australia)

Packetlabs Ltd. • City of Melbourne

On-site
AUD 120,000 - 160,000
Immediate offensive security training
Amazing team and working environment
Competitive compensation and growth
Penetration Tester
Penetration Tester

HackLabs • Sydney

On-site
AUD 100,000 - 150,000
Penetration Tester
Penetration Tester

W Solutions Co • City of Brisbane

Hybrid
AUD 90,000 - 120,000
Senior Penetration Tester — Offensive Security Specialist
Senior Penetration Tester — Offensive Security Specialist

Packetlabs • Sydney

On-site
AUD 140,000 - 190,000
Lead Penetration Tester
Lead Penetration Tester

Decipher Bureau • Council of the City of Sydney

On-site
AUD 120,000 - 170,000
Competitive salary plus equity
Diverse work environment
Opportunity to influence AI-driven tools
Penetration Tester
Penetration Tester

PwC • Newcastle City Council

On-site
AUD 80,000 - 98,000
Four weeks annual leave
Floating public holidays
Flexible work arrangements
Offensive Security Consultant
Offensive Security Consultant

Triskele Labs • Australia

Hybrid
AUD 90,000 - 150,000
Training and development
Employee Assistance Program (EAP)
Social functions organized by People &
+2
Penetration Tester
Penetration Tester

Calleo • City of Melbourne

Hybrid
AUD 120,000 - 150,000
Hybrid working arrangement
12 month contract with extension options
Opportunity to influence security posture
Security Services Consultant
Security Services Consultant

Planit • Sydney

Hybrid
AUD 130,000 - 180,000
Career development
Wellness programs
LinkedIn Learning licences
+2
Sydney-Consultant Level 1-Security Services
Sydney-Consultant Level 1-Security Services

NRI Holdings • Sydney

Hybrid
AUD 90,000 - 150,000
Career development opportunities
Grow skills vertically and Horizontaly
Wide variety of work