Security Testing Lead Specialist

Location
Melbourne, Sydney, Brisbane, Canberra, Adelide, Perth
Workplace
On-site

About this role

Security Testing Lead Specialist

Key Accountabilities Include

·       Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

·       Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

·       Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

·       Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

·       Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.

·       Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

·       Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

·       Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.

·       Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

·       Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

·       Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

·       Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.

Additional Information

·       Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

·       Provide input into Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

·       Develop and deliver training for junior team members and the broader community to uplift security capability.

·       Promote shift-left practices to enable the delivery of secure, high-quality code at speed.

·       Provide guidance on application security architecture and secure design considerations.

·       Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

·       Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

·       Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

·       Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

·       Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.

·       Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

·       Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.

Qualifications / Experiences

Essential

·       A minimum of 8 years’ experience in a Security Testing role

·       Experience and exposure to a variety of software delivery models, including DevOps and Waterfall

·       Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment

·       Significant experience in implementing automated security assessment tools into CI/CD pipelines

·       Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.

·       Ability to review and provide guidance and feedback on security assessment reports

·       Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring.

·       Experience in training and developing people

·       Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline

·       Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST – Certified qualifications for domain areas in scope for the position.

Highly Desirable

·       Prior experience as a developer / software engineer is a significant advantage.

·       Experience in developing security policy, standards, and development guidelines

·       Significant experience in other domain areas of Cyber Security

·       A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.

·       Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP

·       Experience in managing engagements with external security vendors

·       Demonstrable history of developing exploits and zero-day discovery



Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?