Application Security Specialist

4 weeks ago


Sydney, New South Wales, Australia Protecht Group Full time

About Protecht Group

We are a fast-growing Governance, Risk & Compliance (GRC) SaaS business, providing world-class enterprise risk management, compliance, training, and advisory services to over 350 customers across various industry sectors through our offices across APAC, USA & Europe.

Our cloud-based SaaS platform – Protecht.ERM is a comprehensive, flexible, and dynamic risk management solution that sets us apart.

The Culture and Benefits

  • A positive and super friendly culture where learning is valued and supported.
  • A highly flexible culture that lets people work across home and our offices.
  • A strong commitment to your learning and development – fortnightly dedicated L&D afternoons.
  • Reward & Recognition programs.
  • A strong focus on work / life balance with access to Birthday leave, bonus days, paid parental leave and long service leave.
  • Monthly social events.
  • Competitive remuneration and Annual Performance Bonus.
  • Novated car leasing.
  • Wellbeing support.
  • Generous Employee Referral program.

About the Role

As our Application Security Specialist, you will help ensure that every step of the software development lifecycle follows security best practices in supporting and developing our SaaS product – Protecht.ERM (Enterprise Risk Management). Located in our central Sydney office and reporting to the Head of Cyber Security, you will be working in a fun and exciting security team that strives to implement best security practices for development, testing and agile project delivery.

Key Responsibilities

  • Review application code for security vulnerabilities and best practices.
  • Help Protecht developers deliver high quality and security hardened code based on OWASP and Protecht secure coding standards.
  • Assess application vulnerabilities and provide clear paths for developers to mitigate the vulnerabilities.
  • Create and maintain a single view of application security tasks from different sources, analyse and prioritise the tasks with different dev teams.
  • Drive and upskill Protecht developers to maintain a security aware culture.
  • Own and enforce secure development policies amongst the Protecht development teams.
  • Create and maintain documentation to support the development of secure software.
  • Run automated security testing tools (SAST, DAST) to detect vulnerabilities.
  • Build and integrate automated security tools into CI/CD pipelines for continuous security testing.
  • Work closely with Protecht developers and platform teams to integrate security throughout the Software Development Life Cycle (SDLC).
  • Ensure security requirements are incorporated into the design phase and architecture reviews.
  • Perform threat modelling with the Protecht development teams to identify and prioritise potential security risks during the design phase.
  • Monitor the evolving threat landscape and proactively conduct security research to identify common application threats and attack vectors to then develop mitigating solutions and minimise risk.
  • Collaborate with external stakeholders for the scoping, managing, validating and remediating of vulnerability assessment and penetration tests.
  • Participate in audits and reviews to validate the security of applications (ISO27001, SOC2, IRAP).
  • Ensure applications comply with relevant security standards and regulations (e.g., OWASP, GDPR).
  • Collaborate in an agile environment with cyber security, development and platform teams.
  • Contribute to various security projects and assist the Head of Cyber Security in delivering the cyber security roadmap.

Requirements

  • Passion for application security.
  • Relevant tertiary qualification such as a degree in computer science or information systems.
  • 2 or more years proven commercial experience in security, preferably in application security or software engineering role.
  • Experience with architecture and security reviews, threat modelling applications.
  • Strong understanding of secure software development fundamentals.
  • The ability to identify security issues through secure code review.
  • Commercial experience Java and/or React development.
  • Experience with REST APIs.
  • Experience with common information security frameworks, standards, principles, and processes (OWASP, SANS, NIST, ISO, etc.).
  • Understanding and experience with common security libraries, security controls, and common security vulnerabilities.

Desirable Attributes

  • Experience with cloud infrastructure environments (AWS) and containerized environments (Docker, Kubernetes).
  • Understanding of identity providers (SAML, SCIM).
  • Experience with SAST/DAST tools.
  • Experience using JIRA and Confluence.
  • Understanding of risk management.
  • Exposure to penetration testing for web application.
  • Security / Application Security Certifications (CISSP, CEH, OSCP, CREST).

Next Steps

We invite you to apply for this exciting opportunity to join our team at Protecht Group.



  • Sydney, New South Wales, Australia ASIC Full time

    About ASIC ASIC is a leading innovative company seeking an Application Security Specialist to lead our product security and application security initiatives, ensuring that security is integrated into every aspect of the software development lifecycle and deployment processes. About the Role As an Application Security Specialist, you will be...


  • Sydney, New South Wales, Australia Zone IT Solutions Full time

    About the RoleWe are seeking an experienced Security Specialist to join our team and protect our applications from potential threats.Key Responsibilities:Conduct thorough security assessments and identify vulnerabilities in our applications.Develop and implement secure coding practices and guidelines to prevent security breaches.Collaborate with software...


  • Sydney, New South Wales, Australia Zone IT Solutions Full time

    We are seeking a highly skilled and experienced Chief Application Security Specialist to ensure the security and integrity of our applications and systems.About UsZone IT Solutions is an Australia-based recruitment company specializing in Digital, ERP, and larger IT Services. We offer flexible, efficient, and collaborative solutions to organizations...


  • Sydney, New South Wales, Australia Salt Recruitment Full time

    Salt Recruitment is proud to offer a challenging opportunity for a Cyber Security Specialist - Application Lead to join our team.About UsSalt Recruitment is a leading recruitment agency with a strong focus on technology and innovation.About the RoleWe are seeking a highly skilled Cyber Security Specialist - Application Lead to lead our application security...


  • Sydney, New South Wales, Australia Tal Services Limited Full time

    Job Description:At Tal Services Limited, we are seeking an experienced Application Security Engineer to enhance our security posture by integrating security practices into our software development lifecycle. The ideal candidate will collaborate closely with product development teams to identify, analyse, and mitigate security vulnerabilities in our...


  • Sydney, New South Wales, Australia Tal Services Limited Full time

    About the RoleWe are seeking an experienced Application Security Engineer to join our Cyber Security team at Tal Services Limited. As an Application Security Engineer, you will play a critical role in enhancing our security posture by integrating security practices into our software development lifecycle.Key ResponsibilitiesCollaborate with product...


  • Sydney, New South Wales, Australia Protecht Group Full time

    About Protecht GroupWe are a fast-growing Governance, Risk & Compliance (GRC) SaaS business, providing world-class enterprise risk management, compliance, training, and advisory services to over 350 customers across various industry sectors through our offices across APAC, USA & Europe.Our Unique OfferingOur cloud-based SaaS platform – Protecht.ERM is one...


  • Sydney, New South Wales, Australia Protecht Group Full time

    About Protecht GroupWe are a fast-growing SaaS company that provides enterprise risk management, compliance, and advisory services to over 350 customers globally. Our cloud-based platform, Protecht.ERM, is a comprehensive risk management solution that supports our mission of empowering businesses to thrive in a rapidly changing world.The Culture and...

  • Cybersecurity Manager

    3 weeks ago


    Sydney, New South Wales, Australia Tech-Cyber-Mgmt&Strategy Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Manager - Application Security Specialist to join our team.Key ResponsibilitiesDevelop and deliver an AppSec framework for standardised and measurable secure software development practices.Lead and mentor a small application security team, managing outcomes and stakeholder relationships across the...


  • Sydney, New South Wales, Australia Wilson Security Pty Ltd Full time

    About the Job:Wilson Security Pty Ltd is a leading provider of integrated security solutions, seeking an experienced Security Operations Specialist to join our team. This role is based in various locations across North Ryde and Hornsby Region, offering full-time and casual positions with varying shifts.Job Summary:We are expanding our presence in NSW,...

  • Security Specialist

    2 weeks ago


    Sydney, New South Wales, Australia MSS Security Pty Ltd Full time

    About MSS Security Pty LtdWe are a leading security company in Australia, with a national presence. Our goal is to deliver exceptional service and protect high-profile sites.We have a strong people-focused culture.We offer extensive development opportunities.We provide stability and certainty in our roles.Our Security Officers work across various sectors and...

  • Security Engineer

    4 weeks ago


    Sydney, New South Wales, Australia ASIC Full time

    Job Role SummaryASIC is seeking an experienced Application Security Engineer to lead product security and application security initiatives, ensuring security is integrated into every aspect of the software development lifecycle and deployment processes.About the RoleThis is a key position in ASIC's cybersecurity team, supporting the cyber assurance function...


  • Sydney, New South Wales, Australia Wilson Security Pty Ltd Full time

    At Wilson Security, our Corporate Real Estate Team in Sydney is seeking a skilled Security Officer to join our national specialist security network.This exciting opportunity requires a strong customer service focus, with excellent interpersonal and verbal/written communication skills. You will work closely with our clients and colleagues to provide...


  • Sydney, New South Wales, Australia Tyro Payments Limited Full time

    About Tyro Payments LimitedWe're a tech company at heart, fostering a diverse and inclusive environment, and a passion for continuous learning has always been one of the most important parts of our company's culture.Tyros are a highly collaborative mix of people. You will work closely with our awesome teams and individuals in engineering, product management,...


  • Sydney, New South Wales, Australia MSS Security Pty Ltd Full time

    About MSS SecurityMSS Security Pty Ltd is a leading security company in Australia, with a national footprint across the country. We have unrivalled experience in delivering high-quality security services and protecting some of the nation's highest profile sites.Our CultureWe value our employees and strive to create a positive work environment. Our culture is...


  • Sydney, New South Wales, Australia Tech-Cyber-Mgmt&Strategy Full time

    Lead Our Application Security TeamWe are seeking an experienced Application Security Manager to lead our dedicated application security team. The successful candidate will be responsible for developing and implementing robust security standards and practices, collaborating with engineering stakeholders, and ensuring the integration of security into the...


  • Sydney, New South Wales, Australia MSS Security Pty Ltd Full time

    Job DescriptionWe are seeking a highly motivated Protection Security Specialist to join our team in Adelaide.About MSS SecurityMSS Security Pty Ltd is one of Australia's leading security companies, delivering high-quality services and protecting prominent sites nationwide. To learn more about us, visit our website at www.msssecurity.com.au.Key...


  • Sydney, New South Wales, Australia Randstad Full time

    Randstad is seeking a seasoned Application Security Architect to safeguard the digital landscape of our esteemed insurance client.What will you do?Develop and implement robust security measures throughout the Software Development Lifecycle (SDLC).Design and integrate secure coding practices into image and code repositories like Bitbucket.Collaborate with...


  • Sydney, New South Wales, Australia MSS Security Pty Ltd Full time

    About MSS SecurityMSS Security Pty Ltd is a leading security company with a national footprint across Australia. We deliver high-quality service and protect some of the nation's highest profile sites.CultureOur employees enjoy working with MSS because we:Have a high people and culture focus;Offer extensive development and progression opportunities;Provide...


  • Sydney, New South Wales, Australia Tech-Cyber-Mgmt&Strategy Full time

    Job OverviewWe are seeking an experienced Application Security Leader to join our team at Tech-Cyber-Mgmt&Strategy. This is a unique opportunity to leverage your expertise in application security to drive innovation and ensure the highest levels of security for our products.