Senior Information Security Consultant

Jobtailor

Wellington

On-site

NZD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Westpac New Zealand is seeking an experienced security tester to plan, lead and deliver authorised, independent penetration testing across technology services, identifying exploitable weaknesses and demonstrating credible attack paths with business impact.

You will provide practical root-cause remediation guidance, collaborate with engineering, risk and third-party stakeholders, and continuously improve testing coverage, including cloud-native and AI-enabled services, while ensuring safe,

Qualifications

  • Demonstrated experience independently delivering penetration testing or offensive-security assessments in large enterprise environments.

Responsibilities

  • Plan, lead and deliver authorised, independent and risk-based security testing across Westpac New Zealand technology services
  • Identify and safely validate exploitable weaknesses
  • Demonstrate credible attack paths and explain customer and business impact
  • Provide practical root-cause remediation guidance
  • Work with engineering, service, risk and third-party stakeholders to verify remediation
  • Improve the effectiveness, coverage and repeatability of security assurance activities
  • Support customer, business and operational resilience
  • Ensure testing is conducted safely, ethically and within approved scope
  • Evolve testing methodologies and automation capabilities
  • Assess emerging technologies, including cloud-native and AI-enabled services

Skills

Penetration Testing
Offensive Security Assessments
Secure Coding Principles
Attack Path Analysis
Security-Focused Code Reviews
Windows Security
Linux Security
TCP/IP Networking
API Security
Cloud Security

Education

OSCP
OSWE
OSEP
OSCE3
CREST CRT/CCT
HTB CPTS
GXPN
GPEN

Tools

Python
PowerShell
Bash
Kubernetes
Docker
OpenShift
CI/CD Pipeline
DevSecOps

Job description

  • Plan, lead and deliver authorised, independent and risk-based security testing across Westpac New Zealand technology services
  • Identify and safely validate exploitable weaknesses
  • Demonstrate credible attack paths and explain customer and business impact
  • Provide practical root-cause remediation guidance
  • Work with engineering, service, risk and third-party stakeholders to verify remediation
  • Improve the effectiveness, coverage and repeatability of security assurance activities
  • Support customer, business and operational resilience
  • Ensure testing is conducted safely, ethically and within approved scope
  • Evolve testing methodologies and automation capabilities
  • Assess emerging technologies, including cloud-native and AI-enabled services
Requirements
  • Demonstrated experience independently delivering penetration testing or offensive-security assessments in large enterprise environments
  • Technical depth in at least two testing domains, with breadth across web, API, network, infrastructure, cloud, identity or mobile security testing
  • Strong understanding of secure coding principles and ability to perform security-focused code reviews
  • Strong knowledge of Windows Security, Linux Security, Active Directory, Authentication and Authorisation, TCP/IP Networking, DNS, HTTP/S and API Security
  • Ability to analyse attack paths and determine exploitability and business risk
  • Experience producing penetration-testing reports for technical and non-technical audiences
  • Practical scripting and/or automation capability using Python, PowerShell, Bash or similar languages
  • Working knowledge of at least one major public cloud platform
  • Strong judgement regarding approvals, scope management, evidence handling and testing safety
  • Excellent written communication, stakeholder engagement and consulting skills
  • Preferred: financial services or regulated industry experience
  • Preferred: Kubernetes, Docker, OpenShift or container security testing
  • Preferred: CI/CD pipeline and DevSecOps security testing
  • Preferred: experience assessing AI-enabled systems, agents and LLM-based applications
  • Preferred: familiarity with attack-path validation and automated penetration-testing platforms
  • Preferred: relevant professional certification or equivalent demonstrated capability, such as OSCP, OSWE, OSEP, OSCE3, CREST CRT/CCT, HTB CPTS, GXPN, GPEN, or advanced SANS offensive security certification
Core Competencies

Demonstrates expertise in penetration testing and offensive security assessments, with a strong understanding of secure coding principles and the ability to analyze attack paths. Proficient in scripting and automation, with experience in cloud security and stakeholder engagement.

Highest-signal resume keywords
  • Penetration Testing
  • Offensive Security Assessments
  • Secure Coding Principles
  • Python Scripting
  • Cloud Security
ATS Optimization Keywords
Hard Skills
  • Penetration Testing
  • Offensive Security Assessments
  • Secure Coding Principles
  • Attack Path Analysis
  • Security-Focused Code Reviews
  • Windows Security
  • Linux Security
  • TCP/IP Networking
  • API Security
  • Cloud Security
Soft Skills
  • Excellent Written Communication
  • Stakeholder Engagement
  • Judgement Regarding Approvals
  • Scope Management
Certifications & Qualifications
  • OSCP
  • OSWE
  • OSEP
  • OSCE3
  • CREST CRT/CCT
  • HTB CPTS
  • GXPN
  • GPEN
Industry Keywords
  • Financial Services
  • Regulated Industry
  • Cloud-Native Services
  • AI-Enabled Systems
Tools & Technologies
  • Python
  • PowerShell
  • Bash
  • Kubernetes
  • Docker
  • OpenShift
  • CI/CD Pipeline
  • DevSecOps
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Testing Lead – Security & Risk
Senior Penetration Testing Lead – Security & Risk

Westpac New Zealand Ltd • Auckland

On-site
NZD 140,000 - 190,000
4 weeks holiday
5 wellbeing days
Banking benefits
+3
Senior Penetration Testing & Cloud Security Consultant
Senior Penetration Testing & Cloud Security Consultant

Jobtailor • Wellington

On-site
NZD 120,000 - 180,000
Service Delivery Lead, Systems Administrator
Service Delivery Lead, Systems Administrator

Jobtailor • Auckland

On-site
NZD 120,000 - 180,000
Senior Information Security Consultant
Senior Information Security Consultant

Westpac New Zealand Ltd • Auckland

On-site
NZD 140,000 - 190,000
4 weeks holiday
5 wellbeing days
Banking benefits
+3
Hands-On Information Security Engineer: Protect & Elevate Platforms
Hands-On Information Security Engineer: Protect & Elevate Platforms

Westpac New Zealand Limited • Auckland

Hybrid
NZD 90,000 - 150,000
4 weeks holiday + wellbeing leave
Extended leave options up to 4 weeks/​
Banking benefits
+4
Integration Developer
Integration Developer

Jobtailor • Auckland

On-site
NZD 120,000 - 160,000
Senior Cybersecurity Consultant
Senior Cybersecurity Consultant

Datacom • Wellington

On-site
NZD 120,000 - 190,000
social events
chill-out spaces
remote working
+2
Information Security Engineer
Information Security Engineer

Westpac Bank • Auckland

On-site
NZD 90,000 - 130,000
4 weeks holiday + wellbeing leave
Additional leave options
Banking benefits & superannuation
+4
Information Security Engineer
Information Security Engineer

Westpac Bank • Takutai

On-site
NZD 100,000 - 140,000
4 weeks holiday + 5 wellbeing days
Additional leave options up to 4 weeks
Banking benefits and superannuation
+4
Senior Cybersecurity Consultant
Senior Cybersecurity Consultant

Datacom • Auckland

On-site
NZD 140,000 - 190,000
Remote working
Flexi-hours
Professional development