Skip to main content
AfterDuty

Security Testing Lead Specialist

The HR Ally · Sydney, New South Wales

Type
Full-time
Posted
10 days ago

Overview

Your cybercrime investigation experience provides a foundation in understanding attack vectors and digital evidence.

About this role

Role: Security Testing Lead Specialist

*Location:*Sydney/Melbourne

Job type: Permanent

Eligibility: Australian PRs and Citizens

Key Accountabilities Include

Lead and deliver high-complexity, high-assurance security assessments across customer's

systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.

Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.

Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.

Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.

Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.

Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.

Collaborate with the Security Testing – Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.

Assess existing security controls and practices against expected standards and recommend improvements to address gaps and uplift security maturity.

Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.

Provide mentorship and technical guidance to uplift capability across both senior and junior team members.

Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.

Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.

Additional information

Provide technical leadership across the domain, including performing and leading complex assessments across multiple technical domains, and responding to escalated incidents and engagements.

Provide input into customer's Penetration Testing, Vulnerability Assessment and Secure Code processes, methodologies, standards, and corresponding roadmaps and enhancement plans.

Develop and deliver training for junior team members and the broader customer community to uplift security capability.

Promote shift-left practices to enable the delivery of secure, high-quality code at speed.

Provide guidance on application security architecture and secure design considerations.

Develop scripts and contribute to automation initiatives to improve the efficiency and effectiveness of security testing activities.

Refine and define engagement processes, secure code artefacts, security criteria, and use cases.

Collaborate with third parties, including vendors and newly acquired entities, to assess and uplift their security and development practices.

Conduct quality assurance reviews of deliverables produced within the Secure Code team to ensure high technical standards.

Operate effectively in environments with ambiguous or conflicting requirements, consistently delivering high-quality outcomes aligned with Cyber Security expectations.

Translate technical vulnerabilities into business risk for stakeholders in a timely manner, leveraging insights from the broader Cyber Security function.

Apply a pragmatic approach to security testing, balancing business objectives, standards alignment, cost, time, and risk considerations.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Sydney

Why this fits a police background

  • Working to legislation & regulation
  • Training & coaching delivery

More cyber security & digital forensics jobs for ex-police

  • Manager, Cyber Defence and Resilience

    Commonwealth Superannuation Corporation (CSC) · Sydney

    Full-time

    Your incident command and risk management experience in policing translates directly into cyber defence leadership.

    Posted Yesterday

  • IT Engineer, Support

    Future Secure AI · Sydney

    Full-time

    Your experience with identity access management and security operations in policing transfers directly to this in-house build role.

    Posted 7 days ago

  • Head of Technology Risk & AI

    Profusion · Sydney

    Full-time

    Head of Technology Risk & AI Financial Services | Risk Leadership | Melbourne or Sydney Australians considering a return home are encouraged to apply Company Overview Our client is a large, well-established Australian financial services organisation operating within the superannuation sector.

    Posted 7 days ago

  • Full-time

    Your experience managing risk registers, audit actions, and compliance frameworks in policing transfers directly to this governance role.

    Posted 8 days ago