Best Practice Software logo
Best Practice SoftwarePosted 1 week ago

Information Security Specialist

HybridBundaberg, Queensland, Australia

Full TimeSenior LevelSmall

Job Summary

Partner with product and development teams from the design stage to facilitate threat modelling and shape architecture decisions before code is written. Validate findings by demonstrating real exploitability of vulnerabilities to build developer trust, and build security directly into backlog items, acceptance criteria, and definition of done. Own and tune SAST/DAST tooling in CI/CD pipelines to produce actionable signal, and manage the penetration testing program by identifying needs, scoping engagements, and driving outputs into actioned work. Own the security maturity roadmap alongside the security directorate using frameworks like OWASP SAMM. This senior embedded role focuses on influencing design early rather than generating findings reports later, supported by modern tooling including Kubernetes and SAST/DAST. Ideal for candidates with practical offensive testing skills and a remediation mindset who can translate risk into clear security requirements.

Required Qualifications

  • Practical offensive testing skills — you can penetration test web applications, APIs and services to a professional standard, working manually beyond automated tooling and demonstrating real exploitability rather than forwarding scanner output
  • Structured threat modelling — you can facilitate threat modelling sessions with architects and developers using recognised approaches (STRIDE, attack trees or similar), and turn the results into prioritised, actionable engineering work
  • Turning risk into clear security requirements — you can translate regulatory, contractual and risk-based drivers into specific, testable security requirements that fit how delivery teams actually work: user stories, acceptance criteria and definition of done, not a separate document nobody reads
  • A remediation mindset, not just a findings mindset — you recommend proportionate, practical controls, talk credibly about trade-offs, compensating controls and residual risk with engineers and risk owners alike, and stay involved until the issue is genuinely closed
  • Credibility with development teams — you explain risk in terms engineers care about, challenge constructively without becoming a blocker, and build enough trust that teams come to you for advice before they build rather than after

Desired Qualifications

  • Experience with regulated health data — Privacy Act / APP 11, notifiable data breaches, ADHA conformance or My Health Record integration — or a working knowledge of the Australian healthcare community and its unique challenges
  • Industry certifications such as CSSLP, OSCP, PNPT or CREST — or the drive to earn one
  • Experience lifting an organisation's maturity against a framework such as OWASP SAMM
  • Development or security experience across .NET, Microsoft SQL Server and Azure-native cloud, including client-server as well as web architectures
  • Experience working in application security alongside large development teams
  • A tertiary qualification or accreditation in a related discipline — or a demonstrated commitment to progressing your learning and development

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce