TL;DR
Security Consultant (Offensive Security): Identifying vulnerabilities and simulating real-world attacks to strengthen client security postures with an accent on web application, API, and infrastructure penetration testing. Focus on delivering actionable security findings and collaborating on high-impact engagements across diverse industries.
Location: Sydney or Melbourne, Australia
Company
hirify.global is a global security consultancy working with some of the most experienced practitioners in the industry.
What you will do
- Perform penetration tests across web applications, infrastructure, and other technologies.
- Deliver clear, actionable security findings and remediation advice.
- Document vulnerabilities and support clients in resolving them.
- Work closely with global stakeholders to ensure successful engagement delivery.
- Communicate effectively with both technical and non-technical audiences.
- Contribute to team knowledge-sharing and potentially mentor junior consultants.
Requirements
- Strong communication skills.
- English: Excellent spoken and written required.
- Experience collaborating in consulting environments.
- Hands-on technical experience in web application and API security testing.
- Experience with external & internal infrastructure testing.
- Familiarity with Windows and Linux command-line and systems.
- Understanding of mobile app security (iOS/Android).
Nice to have
- Programming or scripting skills.
- Code review experience.
- Firewall testing or configuration review experience.
- Containerisation security testing (e.g., Docker, Kubernetes).
- Cloud-native security assessment across major platforms (Azure, AWS, GCP).
- AI and machine learning security testing, including model and pipeline assessment.
- Industry certifications such as CREST CRT, Offensive Security OSCP.
Culture & Benefits
- Flexible working options.
- Financial and investment benefits (pension, life assurance, parental leave).
- Community and volunteering programs.
- Employee referral program.
- Wellness and lifestyle initiatives.
- Learning and development opportunities and access to certifications.
Hiring process
- Final candidates will undergo mandatory background checks (BS7858/AS4811-2022).
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →