Haystack
← Back to Jobs
Full time
Administrative
AI

Security Testing Lead Specialist - Australia

Ayan InfotechSydney, New South Wales🇦🇺AustraliaPosted 18 Aug 2026

Why This Role Stands Out

This hybrid contract role offers a fantastic opportunity to lead critical security testing initiatives across Australia, leveraging your expertise to significantly enhance organizational data protection and resilience. You'll thrive here if you're a seasoned security professional eager to provide technical leadership, drive strategic improvements, and translate complex findings into actionable business insights. Apply now to make a tangible impact and advance your career in a dynamic environment.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Sydney, New South Wales, Australia

Job Description

Ayan Infotech are looking for a Security Testing Lead Specialist for a short term contract to start with (possibly extend) and can be performed from any capital cities of Australia.

All applicants must have full unrestricted work rights in Australia.

Title: Security Testing Lead Specialist

Location: Australia-wide (Hybrid)

Type: Contract (initially to end of Dec 26, may extend)

Key Accountabilities Include
  • Lead and deliver high-complexity, high-assurance security assessments across systems, including advanced penetration testing, vulnerability assessments, and source code security reviews, focusing on real-world exploitability and attack path development.
  • Provide authoritative technical leadership as a subject matter expert in security testing and secure development, acting as the primary escalation point for complex vulnerabilities, assessments, and adversary emulation activities.
  • Evaluate the effectiveness of systems in protecting organisational data and maintaining intended functionality, and provide strategic recommendations to improve security posture and resilience.
  • Identify and validate critical vulnerabilities, exploit paths, and attack vectors, including analysing scan outputs and manual testing results to assess risk and impact accurately.
  • Translate technical findings into clear, actionable business risk insights, supporting informed decision making and prioritised remediation.
  • Drive the evolution of security testing strategy, methodologies, and standards, ensuring alignment with industry best practices and continuous improvement across the function.
  • Collaborate with the Security Testing - Senior Lead and broader cyber security teams to shape capability development, resourcing, and operational direction.
  • Assess existing security controls and practices against expected standards, and recommend improvements to address gaps and uplift security maturity.
  • Ensure delivery of high-quality security assessment reports, clearly articulating risks, impacts, and recommended mitigations.
  • Provide mentorship and technical guidance to uplift capability across both senior and junior team members.
  • Apply a pragmatic, risk-based approach to all activities, balancing security requirements with business objectives, timelines, and operational constraints.
  • Fulfil Health, Safety, and Environment (HSE) responsibilities in accordance with organisational policies and regulatory requirements.
Essential Experience
  • A minimum of 8 years' experience in a Security Testing role.
  • Experience and exposure to a variety of software delivery models, including DevOps and Waterfall.
  • Significant experience in performing complex security assessments across a range of domain areas in a large corporate environment.
  • Significant experience in implementing automated security assessment tools into CI/CD pipelines.
  • Exceptional working knowledge of Security Assessment toolsets, such as Vulnerability Scanners, Static Code Analysis and Software Composition Analysis tools.
  • Ability to review and provide guidance and feedback on security assessment reports.
  • Strong understanding of application security architecture principles including transport security, authentication, authorisation, threat modelling, and logging and monitoring.
  • Experience in training and developing people.
  • Demonstratable skillset exceeding that expected of a person holding OSCE/OSWE or CREST - Certified qualifications for domain areas in scope for the position.
Highly Desirable
  • Prior experience as a developer / software engineer is a significant advantage.
  • Experience in developing security policy, standards, and development guidelines
  • Significant experience in other domain areas of Cyber Security
  • A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.
  • Current industry certification, including but not limited to: OSCP, OSCE3, OSWE; CREST (CCT, CCSC, CCSAS, CCSAM); SANS (GPEN, GAWN, GWAPT, GXPN); (ISC)2 CISSP, CCSP
  • Experience in managing engagements with external security vendors.
  • Demonstrable history of developing exploits and zero-day discovery.

Contact: for more details.

Similar jobs