1 месяц назад
Offensive Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Offensive Security Engineer (Cybersecurity): Identifying and validating exploitable weaknesses across applications, APIs, infrastructure, networks, identity services, and cloud-hosted workloads with an accent on penetration testing, threat emulation, vulnerability management, and DevSecOps. Focus on integrating security controls into CI/CD pipelines, automating testing and remediation workflows, and conducting MITRE ATT&CK-aligned control validation.
Location: Hybrid work across Sydney Olympic Park and Sydney CBD offices, with working from home as agreed and required. Based in Sydney Olympic Park, Australia.
Company
is an Australian member-owned organisation providing roadside assistance, electric vehicle charging, holiday parks and lodges, car rentals, harbour transport, and ocean cruising.
What you will do
- Plan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services, and cloud workloads.
- Operate and optimise SAST, DAST, CSPM, and attack simulation platforms.
- Embed application security, dependency, API, and open-source risk testing into repositories, IDEs, and CI/CD pipelines.
- Conduct penetration testing, security assessments, design reviews, threat modelling, adversary emulation, and purple team activities.
- Validate findings, track remediation, retest vulnerabilities, and provide practical risk-based advice to engineering and technology teams.
- Automate testing, evidence collection, reporting, remediation tracking, and control validation activities.
Requirements
- Experience in cybersecurity, application security, penetration testing, security engineering, or DevSecOps.
- Strong knowledge of web application, API, cloud, and secure software development practices.
- Hands-on experience with SAST, DAST, and CSPM security testing tools.
- Experience identifying, validating, remediating, and reporting security vulnerabilities.
- Knowledge of OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST, and PCI DSS.
- Ability to automate tasks with Python or PowerShell, alongside strong analytical, problem-solving, and stakeholder communication skills.
Culture & Benefits
- 9–12 month maximum-term contract with a hybrid work arrangement.
- Progressive flexibility, leave, and wellbeing benefits.
- Travel discounts on SIXT car rental, cruises, and Holiday Parks and Resorts.
- Complimentary my Rewards membership with roadside assistance and partner discounts.
- Discounts on car, home, and travel insurance products.
- Opportunities to grow, progress, or relocate within the Group and across different locations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →