XPT Software Australia logo
XPT Software AustraliaPosted 1 week ago

Security Testing Lead Specialist

On-siteMelbourne, Victoria, Australia

ContractSenior LevelSmall

Job Summary

Lead high-complexity security assessments including advanced penetration testing, vulnerability assessments, and source code security reviews. Identify and validate critical vulnerabilities, exploit paths, and attack vectors by analyzing scan outputs and manual testing results. Provide authoritative technical leadership as a subject matter expert, acting as the primary escalation point for complex engagements and adversary emulation activities. Translate technical findings into clear, actionable business risk insights to support informed decision-making and prioritized remediation. Drive the evolution of security testing strategy, methodologies, and standards while ensuring alignment with industry best practices. Mentor team members and develop training to uplift security capability across the function. Operate effectively in environments with ambiguous requirements, balancing security objectives with business constraints.

Required Qualifications

  • A minimum of 8 years' experience in a Security Testing role
  • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall
  • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment
  • Significant experience in implementing automated security assessment tools into CI/CD pipelines
  • Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools
  • Ability to review and provide guidance and feedback on security assessment reports
  • Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring
  • Experience in training and developing people
  • Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline
  • Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position

Desired Qualifications

  • Prior experience as a developer / software engineer is a significant advantage
  • Experience in developing security policy, standards, and development guidelines
  • Significant experience in other domain areas of Cyber Security
  • A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks
  • Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP
  • Experience in managing engagements with external security vendors
  • Demonstrable history of developing exploits and zero-day discovery

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce