Skip to main content
AfterDuty

Offensive Security Specialist

Vanguard · Melbourne, Victoria

Type
Full-time
Posted
13 days ago

Overview

Your investigative mindset and experience following digital traces are valuable, but deep technical hacking skills aren't built in policing.

About this role

About Vanguard

More than 45 years ago, John C. Bogle a visionary to start an investment company that did things differently. A company with no external shareholders. Where all the profits were invested back into the business and used to lower costs. Evidently, it was as bold as it was brilliant. To this day, Vanguard Group still has no external shareholders. That means no share prices to protect, and no profits to generate for outside owners.

Today, Vanguard is one of the world’s largest investment management companies, serving more than 50 million investors worldwide. For more than 30 years Vanguard Australia has been supporting individual investors, financial advisers, and superannuation members to achieve their long-term financial goals.

What You'll Do

The Offensive Security Analyst is an individual contributor on the Offensive Security & Fraud Testing (OSFT) team. This role focuses on hands-on Red Teaming and adversary simulation using traditional tools and techniques .

Role Overview

We are seeking a talented Offensive Security Analyst to join our team of ethical hackers. In this mid-level role, you will be an integral part of our red teaming and penetration testing efforts, using your technical expertise to find and exploit vulnerabilities across web applications, networks, cloud platforms, and critical systems. By thinking like an attacker, you will help us identify weaknesses before real adversaries do, and work with cross-functional partners to fix them. This is a hands-on role focused on traditional offensive security methods – you’ll use well-known and custom tools to emulate sophisticated threat actors, improve our security posture, and reduce risk.

Key Responsibilities

  • Red Team Operations & Adversary Simulation: Participate in full-scope red team engagements, contributing across the kill-chain (reconnaissance, exploitation, lateral movement, data exfiltration, etc.). Occasionally lead targeted adversary simulations at moderate scope (e.g., a spear-phishing campaign or an endpoint compromise scenario, using phishing or malware implants). Emulate real threat actor TTPs aligned with frameworks like MITRE ATT&CK to test our detection and response capabilities.
  • Collaborative Remediation & Purple Team Support: Work closely with defensive teams – such as developers, system engineers, and security operations – to ensure discovered issues are understood and remediated effectively. Provide actionable technical guidance to fix vulnerabilities (e.g., code remediation suggestions for development teams). Support purple team exercises by sharing attacker perspective knowledge and helping defensive teams validate alerts and improve detection rules.
  • Document each engagement thoroughly, producing clear and detailed penetration test reports that explain findings, their severity, and recommended mitigations.
  • Continuously research emerging vulnerabilities, new exploit techniques, and security trends in the offensive domain.
  • 3–5+ years of hands-on penetration testing and/or red teaming experience. Proven track record of identifying and exploiting vulnerabilities across web applications (deep knowledge of OWASP Top 10), networks, and cloud services. Familiarity with shell scripting and programming (Python, PowerShell, Bash) for exploit development and automation. Strong understanding of network protocols, operating systems, identity management, and security architecture.
  • Demonstrated ability to think like an attacker to anticipate and craft creative exploitation scenarios. Familiarity with frameworks and methodologies like MITRE ATT&CK, PTES (Penetration Testing Execution Standard), and relevant compliance standards (NIST, ISO), ensuring tests are realistic and comprehensive.
  • Strong written and verbal communication skills to produce high-quality reports and articulate risk to stakeholders.

Preferred Qualifications

  • Offensive security certifications such as OSCP, OSWE, OSWA, GPEN, GWAPT, or similar, demonstrating validated skills in penetration testing.
  • Experience performing threat modeling and incorporating attacker perspective into security design reviews.
  • Familiarity with cloud platforms (AWS, Azure, GCP) and their specific security considerations.
  • Knowledge of secure software development practices and experience working with DevSecOps or CI/CD pipeline security.
  • Red team operations exposure or small-scale adversary simulations (beyond standard pentesting), showing the ability to plan multi-phase attacks and operate stealthily.
  • Active participation in the security community (e.g., CTFs, bug bounties, open-source contributions) demonstrating passion for offensive security.

Inclusion Statement

Vanguard’s continued commitment to diversity and inclusion is firmly rooted in our culture. Every decision we make to best serve our clients, crew (internally employees are referred to as crew), and communities is guided by one simple statement: “Do the right thing.”

We believe that a critical aspect of doing the right thing requires building diverse, inclusive, and highly effective teams of individuals who are as unique as the clients they serve. We empower our crew to contribute their distinct strengths to achieving Vanguard’s core purpose through our values.

When all crew members feel valued and included, our ability to collaborate and innovate is amplified, and we are united in delivering on Vanguard’s core purpose.

Our core purpose: To take a stand for all investors, to treat them fairly, and to give them the best chance for investment success.

Special Factors

Vanguard is not offering visa sponsorship for this position

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

About security roles for ex-police

Security management, operations and consultancy roles. Years of operational policing — command, incident response, public order — translate directly into corporate security, and employers in this sector actively rate police experience.

See all security jobs in Melbourne

Why this fits a police background

  • Financial crime & fraud
  • Working to legislation & regulation
  • Security operations

More security jobs for ex-police

  • Security Operations Orchestration Manager

    Corrs Chambers Westgarth · Melbourne

    Full-time

    Your incident command, crisis management and multi-agency coordination experience directly maps to leading security operations and incident response.

    Posted 7 days ago

  • Technical Director Security - SCEC

    Mott MacDonald · Melbourne

    Full-time

    Your security clearance, command experience and incident management are directly transferable to leading secure infrastructure projects.

    Posted 8 days ago

  • Loss Prevention Specialist

    Hanes Brands Australasia · Melbourne

    Full-time

    Your investigative skills and incident-handling experience translate directly to loss prevention audits and investigations.

    Posted 9 days ago

  • Security Supervisor

    Western Health Newfoundland · Melbourne

    Full-time

    Your incident command, conflict management and risk-assessment experience maps directly to supervising hospital security operations.

    Posted 10 days ago