Web Application Penetration Tester - Nullify

Black Nova Venture Capital

Sydney

On-site

AUD 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Nullify is seeking a hands-on security tester to perform deep, manual pentests on customer web applications in Sydney. You will go beyond automated scans to validate auth flows, business logic, and multi-step exploit chains, feeding results back into our detection system.

You will partner with customer security teams from scoping to reporting and continuously learn new frameworks and patterns to stay ahead of threats.

Qualifications

  • Production web apps security experience across real-world environments.
  • Experience analyzing auth flows and business logic for vulnerabilities.
  • Ability to reproduce findings as repeatable techniques for automation.

Responsibilities

  • Run deep, manual web app pentests for clients, beyond automated scans.
  • Convert findings into reproducible techniques and feed them into detection systems.
  • Collaborate with client security teams from scoping to reporting.
  • Stay ahead of new frameworks, auth patterns, and vulnerability classes.

Skills

Penetration testing
OWASP Top 10
Manual web app testing
Security tooling

Tools

Custom tooling development

Job description

Nullify runs autonomous security work most teams can't staff for. This role is the human edge of that — validating what our agents find, going after what they can't, and feeding every technique back into the system so it gets sharper.


What You'll Do


  • Run deep, manual web app pentests against customer surface area that automated scanning alone won't catch — auth flows, business logic, multi-step exploit chains.

  • Turn novel findings into reproducible techniques that get encoded back into Nullify's detection and validation agents.

  • Partner with customer security teams during engagements, from scoping through report-back.

  • Keep pace with the frontier: new frameworks, new auth patterns, new classes of vulnerability.


What You Bring


  • Real-world experience finding and exploiting vulnerabilities in production web applications — OWASP Top 10 and beyond.

  • Comfort working close to the metal: reading application code, tracing requests, building custom tooling when off-the-shelf doesn't cut it.

  • A bias toward proof over speculation — you validate before you report.

  • Bonus: experience training or evaluating AI systems on security tasks.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Web App Penetration Tester: Hands-On, AI-Savvy
Senior Web App Penetration Tester: Hands-On, AI-Savvy

Black Nova Venture Capital • Sydney

On-site
AUD 120,000 - 180,000
Account Executive - Nullify
Account Executive - Nullify

Black Nova Venture Capital • Sydney

On-site
AUD 120,000 - 180,000
Penetration Tester
Penetration Tester

Synechron • Sydney

On-site
AUD 120,000 - 180,000
A.I. Engineer - Nullify
A.I. Engineer - Nullify

Black Nova Venture Capital • Sydney

On-site
AUD 90,000 - 130,000
Penetration Tester (Australia)
Penetration Tester (Australia)

Packetlabs • Sydney

On-site
AUD 140,000 - 190,000
Penetration Tester
Penetration Tester

XPT Software Australia • City of Melbourne

On-site
AUD 150,000 - 210,000
Penetration Tester (Australia)
Penetration Tester (Australia)

Packetlabs Ltd. • City of Melbourne

On-site
AUD 120,000 - 160,000
Immediate offensive security training
Amazing team and working environment
Competitive compensation and growth
Penetration Tester
Penetration Tester

HackLabs • Sydney

On-site
AUD 100,000 - 150,000
Senior Penetration Tester: Web & AD Security Expert
Senior Penetration Tester: Web & AD Security Expert

Jobtailor • City of Brisbane

Hybrid
AUD 90,000 - 130,000
Penetration Tester
Penetration Tester

Orro Group • City of Brisbane

Hybrid
AUD 100,000 - 150,000