Security Testing Lead Specialist

XPT Software Australia

City of Melbourne

On-site

AUD 140,000 - 190,000

Full time

44 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

XPT Software Australia is seeking an experienced Security Testing Senior Lead to lead high-complexity assessments and drive secure development practices across our systems. You will act as a technical authority, guide adversary emulation activities, and mentor team members while balancing risk with business needs.

You will evaluate security controls, translate findings into business risk insights, and help shape testing strategy, standards, and roadmaps within a large corporate environment.

Qualifications

  • Minimum 8 years in a Security Testing role.
  • Experience with DevOps and Waterfall software delivery models.
  • Experience performing complex security assessments across domains in a large corporate environment.
  • Experience implementing automated security assessment tools in CI/CD pipelines.
  • Strong knowledge of security assessment toolsets (Vulnerability Scanners, SAST, SCA).
  • Ability to review security assessment reports and provide guidance.
  • Understanding of application security architecture (transport security, auth, authorization, threat modelling, logging).
  • Proven track record in training and developing people.

Responsibilities

  • Lead and deliver high-complexity security assessments across systems, including penetration testing, vulnerability assessments, and code reviews.
  • Provide technical leadership as a security testing SME and escalation point.
  • Evaluate protection of organisational data and functionality; provide strategic recommendations.
  • Identify critical vulnerabilities and attack vectors; analyse scans and manual tests.
  • Translate findings into clear business risk insights for prioritised remediation.
  • Shape security testing strategy, standards, and roadmaps; drive continuous improvement.
  • Collaborate with Security Testing – Senior Lead and cyber teams to plan capability development.
  • Assess controls against standards and uplift security maturity.
  • Ensure high-quality security assessment reports with risks and mitigations.
  • Mentor and guide senior and junior team members.

Skills

Security testing
Penetration testing
Threat modelling
CI/CD security
Mentoring
Adversary emulation
Reporting & communication

Education

Electrical/Electronic or Computer/Software Engineering or Cyber Security degree

Tools

Vulnerability scanners
SAST tools
Software Composition Analysis
CI/CD integration

Job description

  • Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.
  • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.
  • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.
  • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.
  • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.
  • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.
  • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.
  • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.
  • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.
  • Provide mentorship and technical guidance to uplift capability across both senior and junior team members.
  • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.
  • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.
Key Accountabilities Include
  • Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.
  • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.
  • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.
  • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.
  • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.
  • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.
  • Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.
  • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.
  • Ensure delivery of high-quality security assessment reports, clearly articulating risk, impacts, and recommended mitigations.
  • Provide mentorship and technical guidance to uplift capability across both senior and junior team members.
  • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.
  • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.
Additional Information
  • Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.
  • Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.
  • Develop and deliver training for junior team members and the broader community to uplift security capability.
  • Promote shift-left practices to enable the delivery of secure, high-quality code at speed.
  • Provide guidance on application security architecture and secure design considerations.
  • Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.
  • Refine and define engagement processes, secure code artefacts, security criteria, and use cases.
  • Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.
  • Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.
  • Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.
  • Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.
  • Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.
Essential
Qualifications / Experiences
  • A minimum of 8 years’ experience in a Security Testing role
  • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall
  • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment
  • Significant experience in implementing automated security assessment tools into CI/CD pipelines
  • Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.
  • Ability to review and provide guidance and feedback on security assessment reports
  • Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring.
  • Experience in training and developing people
  • Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline
  • Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.
Highly Desirable
  • Prior experience as a developer / software engineer is a significant advantage.
  • Experience in developing security policy, standards, and development guidelines
  • Significant experience in other domain areas of Cyber Security
  • A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.
  • Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP
  • Experience in managing engagements with external security vendors
  • Demonstrable history of developing exploits and zero-day discovery
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Testing - Lead Specialist
Security Testing - Lead Specialist

XPT Software • City of Melbourne

On-site
AUD 160,000 - 230,000
Security Testing Lead Specialist
Security Testing Lead Specialist

XPT Software Australia Pty Ltd • Australia

On-site
AUD 120,000 - 190,000
Security Testing Lead Specialist - Contract - Australia
Security Testing Lead Specialist - Contract - Australia

Hastha Solutions • Sydney

On-site
AUD 166,000 - 240,000
Penetration Tester
Penetration Tester

XPT Software Australia • City of Melbourne

On-site
AUD 150,000 - 210,000
Penetration Tester
Penetration Tester

XPT Software • City of Melbourne

On-site
AUD 140,000 - 190,000
Security Testing Lead Specialist
Security Testing Lead Specialist

The HR Ally • City of Melbourne

On-site
AUD 140,000 - 190,000
Security Testing Lead Specialist
Security Testing Lead Specialist

The HR Ally • Sydney

On-site
AUD 150,000 - 230,000
Security Testing Lead: Expert in Pen Tests & Secure Coding
Security Testing Lead: Expert in Pen Tests & Secure Coding

The HR Ally • Sydney

On-site
AUD 150,000 - 230,000
Security Testing Lead
Security Testing Lead

Zone IT Solutions • Council of the City of Sydney

On-site
AUD 110,000 - 170,000
Senior Security Consultant
Senior Security Consultant

CSO Group • Sydney

On-site
AUD 120,000 - 180,000