Cyber Offensive Security Lead

1 week ago


Council of the City of Sydney, Australia Ampol Full time
Ampol Ampol connects our proud history with everything our business is known for today, our trusted high-quality products, our commitment to customer service, local communities and the largest leading transport fuels network in Australia.

View company page

  • Key role in Security maturity journey, uplifting Security Testing
  • Hybrid, flexible working environment, with Alexandria (Sydney), Melbourne or Brisbane office options

About Ampol

Here at Ampol, we are proud of our heritage as Australia's only owned fuel brand. Fuel may be the foundation of our business, but our motivation and purpose come from the people, industries, and communities we engage with. From our origins until today, we've always been inspired by the role we can play in people's lives – to keep them moving, to make journeys happen.

In the next few years, Ampol will be evolving our energy offering to ensure we continue to meet the ongoing needs of our customers whilst best leveraging marketplace opportunities as they arise. We are investing in our infrastructure and people to ensure that we can continue to provide, safe, reliable, and competitive supply to our valued customers.

For over 100 years we have supported Australians to travel far and wide, and we'll be here for 100 more powering better journeys.

The role:

The Cyber Offensive Security Lead will be part of the Cyber Security Architecture team for Ampol Group, responsible for developing and delivering the Enterprise Cyber Security Testing standards, guidelines and procedures (incl. Application Security, penetration testing etc).

The Cyber Offensive Security Lead will also provide cyber risk consulting, compliance, advice/recommendations across the enterprise to support current & future requirements, propose Security Testing solutions and governance that deliver the desired security posture.

This is a permanent position that can be based from any of our Australian offices (Alexandria NSW, Brisbane or Melbourne) with flexible, hybrid work options available.

  • Identify, influence, advise and recommend cyber security services and technology that will enable business solutions to be delivered in a pragmatic manner whilst preserving the integrity of the Ampol enterprise environment and ensure ongoing compliance with relevant regulatory requirements.
  • Analysis/assessment of business requests whilst constructively challenging and negotiating the requirements to derive the underlying needs together with development or quality assurance of solution designs, vendor proposals, business cases and service implementation plans/documentation.
  • Provide guidance and support to Project teams on cyber security architectural risks and aspects of infrastructure or system development and integration
  • Build and maintain effective working relationships with business customers and external vendors/suppliers to support Ampol objectives
  • Support education and awareness activities to optimise the use of existing technologies, services and controls (people, process and technology) to arrive at a "risk-informed" and pragmatic outcome.
  • Development, and communication of the enterprise cyber security architecture including defining the relevant design standards and legislative requirements (ISO, NIST, PCI/DSS,), policies, key principles, technical strategies/standards, guidelines and procedures required to support it.
  • Assist the evolution of the enterprise cyber security architecture by defining the risks, policies, methods, models, tools, processes, and procedures that describe the organisation's current and future cyber security state

About you:

  • Proven expertise in the development of information, applications and/or cyber security architectures and designs for complex business environments
  • Strong influencing, collaboration and organisational skills
  • Proven expertise in applying security architecture principles, practices and processes within enterprise architecture, IT investment and governance frameworks.
  • Relevant certifications such as for security management (CISSP, CISM, or CISA); Offensive security (OSCP, CREST, CEH, GSEC); Architecture (SABSA, TOGAF); or technical and practical (GIAC / SANS) or vendor specific for Microsoft, are advantageous

Demonstrated expertise and experience with:

  • SOA security design, controls and implementation
  • A broad range of technical concepts: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy.
  • Information/Cyber Security Frameworks and standards (ISO 27k, NIST, ITIL, SABSA, TOGAF, IRAP, COBIT, etc)
  • IT information protection, security and regulatory policies and standards
  • IT Systems Engineering Process and Engineering life cycles

We'll take you further by:

  • Our total remuneration is competitive. This is across base salary , a performance incentive, employee share offers and a 25% discount on Fuel for two privately used cars
  • We are flexible. Many of our teams have embraced hybrid work, balancing time spent remote working, with time spent at an office to connect and work together where it adds value.
  • We value recognition. We have an internal recognition platform amplifying the achievements of those who do great work and demonstrate our capabilities and values.
  • Career development and learning opportunities including LinkedIn Learning and other tailored training solutions.
  • Paid Parental Leave - up to 12 weeks paid Parental leave, and up to a year off (unpaid). In addition to the 12 months of unpaid parental leave, employees may apply for a further 12 months of unpaid parental leave (a total of 24 months for each birth)
  • BabyCare Package - financial and flexible support for parents transitioning back to work.
  • Need some wheels? Novated Lease options are available.
  • Invest in your future with the Employee Share Scheme
  • Leave Options – We offer wellbeing leave and leave purchasing.
  • Care for your Community. Spend one paid day a year volunteering with one of our Ampol Foundation partners.

We're an equal opportunity workplace. We not only embrace diversity and inclusion; we celebrate what makes you unique. We welcome applications from people of all ages, cultural backgrounds, and diverse sexualities and genders (including if you identify as transgender). We also highly encourage Aboriginal and Torres Strait Islander peoples to apply for roles with Ampol.

If we've got your interest, we encourage you to submit an application because we would love to tell you more. Click 'Apply Online' below to register your interest.

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Council Of The City Of Sydney, Australia Ampol Limited Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Create Alert Company: Ampol Key role in Security maturity journey, uplifting Security Testing Hybrid, flexible working environment, with Alexandria (Sydney), Melbourne or Brisbane office options About Ampol Here at Ampol, we are proud of our heritage as Australia's only...


  • Council Of The City Of Sydney, Australia Ampol Full time

    Ampol Ampol connects our proud history with everything our business is known for today, our trusted high-quality products, our commitment to customer service, local communities and the largest leading transport fuels network in Australia. View company page Key role in Security maturity journey, uplifting Security Testing Hybrid, flexible working environment,...


  • Sydney, Australia Qantas Airways Limited Full time

    Multiple opportunities to join our Group Cyber Defence area! - Be part of a new team that values great cyber security principles and practices - Permanent opportunity with Hybrid WFH model based at our Head Office in Mascot At Qantas, we represent Australia to the world. Our diverse country is known for its unique spirit, mateship, and a can-do attitude....


  • Sydney, New South Wales, Australia Qantas Airways Limited Full time

    Multiple opportunities to join our Group Cyber Defence area Be part of a new team that values great cyber security principles and practices Permanent opportunity with Hybrid WFH model based at our Head Office in MascotAt Qantas, we represent Australia to the world. Our diverse country is known for its unique spirit, mateship, and a can-do attitude. Together...

  • Cyber Security Manager

    2 months ago


    Sydney, Australia Qantas Group Full time

    Multiple opportunities to join our Group Cyber Defence area! Be part of a new team that values great cyber security principles and practices Permanent opportunity with Hybrid WFH model based at our Head Office in Mascot At Qantas, we represent Australia to the world. Our diverse country is known for its unique spirit, mateship, and a can-do...

  • Cyber Security Manager

    2 months ago


    Sydney, Australia Qantas Full time

    Multiple opportunities to join our Group Cyber Defence area! Be part of a new team that values great cyber security principles and practicesPermanent opportunity with Hybrid WFH model based at our Head Office in Mascot At Qantas, we represent Australia to the world. Our diverse country is known for its unique spirit, mateship, and a can-do attitude....


  • Sydney, Australia Security Careers at Mantel Group Full time

    Mantel Group is an Australian-owned technology consulting business with capabilities across Cloud, Digital, Data & Security. Since our inception in November 2017, we have experienced remarkable growth across Australia & New Zealand and are honoured to be recognised as a Great Place to Work for 4 years in a row! We hire smart and talented people and get out...


  • Sydney, New South Wales, Australia Security Careers at Mantel Group Full time

    Mantel Group is an Australian-owned technology consulting business with capabilities across Cloud, Digital, Data & Security. Since our inception in November 2017, we have experienced remarkable growth across Australia & New Zealand and are honoured to be recognised as a Great Place to Work for 4 years in a rowWe hire smart and talented people and get out of...

  • Offensive Security

    1 week ago


    Sydney, New South Wales, Australia Paxus Australia Pty Ltd Full time

    Posted 17 November 202- SalaryWeekly pay + Flexibility and ability to WFH LocationSydney Job type Contract DisciplineSecurity + Cyber Security Reference263762Job description:The Offensive Security Specialist will regularly conduct advanced penetration tests and ethical hacking to identify vulnerabilities in computer systems early thus helping prevent...


  • Council of the City of Sydney, Australia ClearCompany Full time

    Rubix Solutions are currently seeking an experienced Cyber Security (NV1) for a long term defence programmeRubix Solutions is representing a leading defence consultancy, offering multiple opportunities for experienced Cyber Security Specialists. These roles are within the Enterprise Technology Operations Branch (ETOB) of the Chief Information Officer Group...


  • Sydney, Australia Naviro Pty Ltd Full time

    Join a growing cyber security firm - Work on challenging and interesting projects - Be surrounded by like minded specialists in offensive security Sekuro Operations is seeking a full time ‘Consultant’ to join our Offensive Security Team in Sydney, NSW. The role is suited for professionals with experience in manual penetration testing and a passion for...


  • Council Of The City Of Sydney, Australia Clearcompany Full time

    Exciting opportunity for a Cyber Security Architect (GRC skill) to shape security strategy and ensure project integrity in a collaborative environment Cyber Security Architect (GRC background)Reports to: Chief Information Security Officer (CISO)About the Company: Our client is a leading organization committed to creating extraordinary places that build trust...


  • Sydney, New South Wales, Australia Naviro Pty Ltd Full time

    Join a growing cyber security firm Work on challenging and interesting projects Be surrounded by like minded specialists in offensive securitySekuro Operations is seeking a full time 'Consultant' to join our Offensive Security Team in Sydney, NSW. The role is suited for professionals with experience in manual penetration testing and a passion for all things...


  • Council Of The City Of Sydney, Australia Endeavour Group Full time

    Let's create a more sociable future together At Endeavour, we're totally into what we do.With a portfolio that includes Dan Murphy's, BWS, ALH Hotels, Pinnacle Drinks and more, we love to bring people together.Together we share our passion for our products and industry; it's what inspires us to dream big, and continue to create new experiences for our...


  • Sydney, New South Wales, Australia Cyber Crime Full time

    Exciting opportunity to join a best-in-class cyber teamDevelop broad experience in cyber security operationsWork alongside an inspiring, supportive, and collaborative Cyber teamBuild Your Expertise: Become a Cyber Security ProfessionalLooking to launch your career in cyber security? Insignia Financial is building a world-class cyber security team, and we're...


  • Council of the City of Sydney, Australia Endeavour Group Full time

    Let's create a more sociable future togetherAt Endeavour, we're totally into what we do. With a portfolio that includes Dan Murphy's, BWS, ALH Hotels, Pinnacle Drinks and more, we love to bring people together. Together we share our passion for our products and industry; it's what inspires us to dream big, and continue to create new experiences for our...


  • Council Of The City Of Sydney, Australia Peoplebank Australia Ltd Full time

    Initial 6 months contract +extensions Hybrid Work Model Location: CBD We are looking for a Senior Network Security Engineer to join a market leader.You will be part of the Cyber Security Operations team and will be responsible for: Responsibilities: Technical lead for a project responsible for delivering network security standards Review of major system...

  • Offensive Security

    2 months ago


    Sydney, Australia Paxus Australia Pty Ltd Full time

    Posted 17 November 2023 - SalaryWeekly pay + Flexibility and ability to WFH - LocationSydney - Job type Contract - DisciplineSecurity + Cyber Security - Reference263762 **Job description**: The Offensive Security Specialist will regularly conduct advanced penetration tests and ethical hacking to identify vulnerabilities in computer systems early thus...


  • Council of the City of Ryde, Australia Oracle Full time

    Senior Principal Offensive Security Researcher Oracle Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services. View company page We are a world-class team of application security researchers who love new challenges. We are an inclusive and diverse, with a full range of experience and a global reach. We...


  • Council Of The City Of Sydney, Australia Clearcompany Full time

    About the CompanyThis organisation is a multi-billion dollar global business with a large Australian presence.As a key player in the retail space, they have a significant team in Australia, supported by a global powerhouse brand at group level.About the RoleThe Cyber Security Manager supports the Australian business by ensuring technology, applications and...