Haystack
← Back to Jobs
Full time
Administrative
XS

Security Testing - Lead Specialist

XPT Software Australia Pty LtdMelbourne, Victoria🇦🇺AustraliaPosted 31 Aug 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
On Site
Location
Melbourne, Victoria, Australia

Job Description

XPT Software Australia Pty Ltd Contract

Security Testing - Lead Specialist

Melbourne, Australia Posted on 08/28/2026

  • XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
  • XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains
  • We have 120+technocrats in Australia working at our clientlocations
  • XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe
  • We have served100+ clients globally, fulfilling their onsite-offshoreneeds
Job Description

JD - Security Testing -Lead Specialist:

Minimum of 8 years'experience in a Security Testing role

MustHave
  • Leadand deliver high-complexity, high-assurance security assessments acrossCustomer's systems, including advanced penetration testing, vulnerabilityassessments, and source code security reviews, focusing on real-worldexploitability and attack path development.
  • Provideauthoritative technical leadership as a subject matter expert in securitytesting and secure development, acting as the primary escalation point forcomplex vulnerabilities, assessments, and adversary emulation activities.
  • Evaluatethe effectiveness of systems in protecting organisational data andmaintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.
  • Identifyand validate critical vulnerabilities, exploit paths, and attack vectors,including analysing scan outputs and manual testing results to assess riskand impact accurately.
  • Translatetechnical findings into clear, actionable business risk insights, supportinginformed decision-making and prioritised remediation.
  • Drivethe evolution of security testing strategy, methodologies, and standards,ensuring alignment with industry best practices and continuous improvementacross the function.
  • Collaboratewith the Security Testing - Senior Lead and broader cyber security teams toshape capability development, resourcing, and operational direction.
  • Assessexisting security controls and practices against expected standards, andrecommend improvements to address gaps and uplift security maturity.
  • Ensuredelivery of high-quality security assessment reports, clearly articulatingrisks, impacts, and recommended mitigations.
  • Providementorship and technical guidance to uplift capability across both senior andjunior team members.
  • Applya pragmatic, risk-based approach to all activities, balancing securityrequirements with business objectives, timelines, and operationalconstraints.
  • FulfilHealth, Safety, and Environment responsibilities in accordance withorganisational policies and regulatory requirements.
Additionalinformation
  • Providetechnical leadership across the domain, including performing and leadingcomplex assessments across multiple technical domains, and responding toescalated incidents and engagements.
  • Provideinput into Customer's Penetration Testing, Vulnerability Assessment andSecure Code processes, methodologies, standards, and corresponding roadmapsand enhancement plans.
  • Developand deliver training for junior team members and the broader Customercommunity to uplift security capability.
  • Promote"shift-left" practices to enable the delivery of secure, high-quality code atspeed.
  • Provideguidance on application security architecture and secure designconsiderations.
  • Developscripts and contribute to automation initiatives to improve the efficiencyand effectiveness of security testing activities.
  • Refineand define engagement processes, secure code artefacts, security criteria,and use cases.
  • Collaboratewith third parties, including vendors and newly acquired entities, to assessand uplift their security and development practices.
  • Conductquality assurance reviews of deliverables produced within the Secure Codeteam to ensure high technical standards.
  • Operateeffectively in environments with ambiguous or conflicting requirements,consistently delivering high-quality outcomes aligned with Cyber Securityexpectations
  • Translatetechnical vulnerabilities into business risk for stakeholders in a timelymanner, leveraging insights from the broader Cyber Security function.
  • Applya pragmatic approach to security testing, balancing business objectives,standards alignment, cost, time, and risk considerations.
Currentindustry certification, including but not limited to:

OffensiveSecurity - OSCP, OSCE3, OSWE

Similar jobs