Offensive Security Engineer
HybridSydney Olympic Park, New South Wales, Australia
Job Summary
Plan and perform authorized, risk-based security testing across web applications, APIs, infrastructure, networks, identity services, and cloud-hosted workloads. Operate and optimize security testing platforms including SAST, DAST, and CSPM while integrating application security controls into CI/CD pipelines. Conduct penetration testing, threat modeling, and adversary emulation to validate controls and provide practical remediation advice aligned with OWASP Top 10 and PCI DSS. Track remediation progress, retest resolved vulnerabilities, and produce evidence-based reports for governance and audit. This 9-12 month maximum term contract offers a hybrid work arrangement across Sydney Olympic Park, Sydney CBD, and remote locations.
Required Qualifications
- Experience in cybersecurity, application security, penetration testing, security engineering or DevSecOps
- Strong knowledge of web application, API and cloud security
- Hands-on experience with security testing tools such as SAST, DAST and CSPM platforms
- Understanding of secure software development and CI/CD environments
- Experience identifying, validating and remediating security vulnerabilities
- Knowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST and PCI DSS
- Ability to automate tasks using scripting languages such as Python or PowerShell
- Strong analytical and problem-solving capabilities
- Excellent stakeholder engagement and communication skills
- Ability to provide practical, risk-based security advice to technical and business teams
- Relevant cybersecurity qualifications, certifications or equivalent industry experience
Desired Qualifications
- A passion for emerging security technologies, automation and continuous improvement
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.