Haystack
← Back to Jobs
Full time
Technology
HS

DevSecOps Security Consultant / Engineer - Contract - Sydney

Hastha SolutionsSydney, Sydney🇦🇺AustraliaPosted 14 Sept 2026

Why This Role Stands Out

This contract role offers a fantastic opportunity to leverage your extensive DevSecOps and cloud security expertise in a hybrid Sydney-based environment, driving impactful security initiatives. You'll thrive if you have 8+ years of experience in cyber, cloud, or application security and enjoy collaborating with engineering teams to embed security throughout the SDLC. Apply now to make a significant contribution to Hastha Solutions' security posture.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Sydney, Sydney, Australia
Stakeholder Management

Job Description

DevSecOps Security Consultant / Engineer - Contract - Sydney

Sydney, Australia Posted on 09/11/2026

Urgentrequirement of DevSecOps Security Consultant / Engineer - Contract - Sydney

Requirements

Experience:

  • 8+ relevant experience in Cyber Security, Cloud Security, Application Security, or DevSecOps engineering roles.

Key Responsibilities:

  • Conduct comprehensive DevSecOps security discovery, assessment, and risk evaluation activities across cloud platforms, applications, and development environments.
  • Perform security posture reviews using Orca Security and GitHub Advanced Security to identify vulnerabilities, misconfigurations, exposed assets, code security issues, and compliance gaps.
  • Analyse cloud workloads, repositories, infrastructure configurations, and application architectures to assess security risks and recommend mitigation strategies.
  • Partner with DevOps, engineering, and application teams to integrate security controls and secure-by-design principles throughout the software development lifecycle (SDLC).
  • Implement and enhance security capabilities within CI/CD pipelines, including automated security testing, code scanning, secret detection, dependency analysis, and policy enforcement.
  • Review and validate security findings, prioritize risks based on business impact, and provide actionable remediation guidance to stakeholders.
  • Track remediation efforts and security improvements across cloud environments, containerised workloads, and source code repositories.
  • Support vulnerability management activities, including identification, reporting, risk assessment, and remediation verification.
  • Contribute to the development of DevSecOps standards, security baselines, governance frameworks, and operational procedures.
  • Collaborate with cross functional teams to improve cloud security architecture, compliance readiness, and security monitoring capabilities.
  • Prepare assessment reports, security dashboards, executive summaries, and technical recommendations for management and project teams.

Required Skills and Experience:

  • Strong hands on experience with Orca Security and GitHub Advanced Security.
  • Practical knowledge of DevSecOps methodologies, security automation, and secure software development practices.
  • Experience securing CI/CD platforms and integrating security controls into development pipelines.
  • Strong understanding of cloud security concepts, including identity and access management, network security, data protection, and workload security.
  • Experience with vulnerability management, risk assessment, and remediation tracking.
  • Knowledge of application security principles, code security testing, and software supply chain security.
  • Familiarity with cloud platforms such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).
  • Understanding of container security, Kubernetes security, and Infrastructure as Code (IaC) security practices.
  • Strong analytical, troubleshooting, and problem solving skills.
  • Excellent communication and stakeholder management capabilities.

Preferred Qualifications:

  • Relevant cloud security or cybersecurity certifications.
  • Experience working in enterprise scale DevSecOps and cloud transformation programs.
  • Knowledge of regulatory compliance frameworks and industry security standards.

Education:

  • Bachelor's degree in computer science, Information Security, Information Technology, Engineering, or a related field.

Duration: 03 Monthsandpossible extension

Eligibility: Australian/NZCitizens/PR Holders only

Similar jobs