Application Security Specialist

1 month ago


Sydney, New South Wales, Australia Tal Services Limited Full time
Job Description:

At Tal Services Limited, we are seeking an experienced Application Security Engineer to enhance our security posture by integrating security practices into our software development lifecycle. The ideal candidate will collaborate closely with product development teams to identify, analyse, and mitigate security vulnerabilities in our applications and services.

Key Responsibilities:
  • Drive Application Security strategy across Enterprise and provide timely support and education to development teams on application security best practices, including secure coding techniques and the use of security tools.
  • Work with product development teams to design and implement secure solutions, ensuring adherence to secure coding practices throughout the software development lifecycle (SDLC), onboard applications to application security tools and integrate Application Security plug-ins with CI/CD pipeline so the security issues are identified during the coding stage.
  • Identify, analyse, and remediate vulnerabilities identified through Application Security tools, regular security assessments, penetration testing, and code reviews.
  • Lead application threat modelling sessions and application architecture reviews to proactively identify and address security threats and conduct security assessments on applications to identify and remediate vulnerabilities.
  • Evaluate, recommend, and manage Application Security tools and technologies including related policies and procedures that enhance application security, including static and dynamic analysis tools. Execute planned and ad-hoc security scans of software applications and interpret results for development teams.
  • Maintain comprehensive documentation of application security processes and controls, security vulnerabilities, risk assessments, and remediation plans. Prepare security metrics and reports for stakeholders.
  • Collaborate with product development teams, Cyber and other stakeholder for incident response, threat detection, and forensics teams to address security incidents and improve overall security posture.
  • Develop and deliver security training programs for developers and other stakeholders to foster a security-first culture.
  • Ascertain a holistic understanding of TAL's systems, products, applications, development workloads and lifecycles as well as current TAL policies, standards and processes.
  • Work with vendors to tailor application security tools to fit TAL workloads and improve policies and processes currently in place.
  • Ensure required training and development is undertaken in a timely manner and keep up to date with the latest industry trends in cyber security including what technologies and controls may be the best fit for certain solution requirements with an emphasis on security.

Requirements:
  • A relevant tertiary qualification, preferably a Bachelor's degree in Computer Science, Information Technology or equivalent.
  • Minimum of 3 years in application security, software development, or a related IT role, with a strong focus on security practices including development, secure coding and vulnerability management, threat modelling and secure architecture.
  • Experience in Static Application Security Testing (SAST) tools such as Checkmarx, Snyk, Synopsys, etc., Software Composition Analysis (SCA) tools such as Snyk, Blackduck, Sonatype etc, and Dynamic Application Security Testing (DAST) tools such as Checkmarks and Veracode and understanding of how to integrate them into CI/CD pipelines.
  • Working knowledge in Azure Cloud and associated technologies including but not limited Azure DevOps, Microsoft Defender for Cloud, Azure Policies and Compliance frameworks, WAF, Firewalls and Entra ID.
  • Hands-on development experience in programming languages such as .NET and Java.
  • Experience in automation using scripting languages such as Powershell, JavaScript and Python.
  • Knowledge and experience in web application security including the ability to interpret associated security risks and vulnerabilities such as OWASP Top10
  • Strong understanding of application security standards (OWASP ASVS, NIST SP 800-218, etc.) and secure coding guidelines.
  • Experience with security testing methodologies, including penetration testing, vulnerability assessments and remediation.
  • Experience with Agile development methodologies with working knowledge in products such as Jira.
  • Fundamental knowledge of microservice architecture (Containerisation, Docker and Kubernetes)
  • Experience or knowledge in writing and deploying Infrastructure as Code (IaC), preferably experience in Terraform.
  • Knowledge of regulatory and industry standards and frameworks, APRA CPS234, ASD8, CIS 20, NIST CSF and MITRE Attack.
  • Relevant certifications (CEH, OSWE, OSCP, CASE, AZ-500, etc.) are preferred but not mandatory.
  • Strong analytical and problem-solving skills, with the ability to communicate complex security concepts to non-technical stakeholders.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills.
  • Ability to deal with ambiguity and work independently with limited direction in a fast-paced environment.
  • Penetration testing experience preferred but not mandatory
  • Passionate about security, with an intention to always excel and self-driven to develop technical and professional skills.

Additional Information:

At Tal Services Limited, we value diversity in all its forms and are committed to fostering an inclusive and equitable culture for all our people. We encourage Aboriginal and Torres Strait Islander people, individuals from all backgrounds, including those with caring responsibilities, people living with disability, and individuals from the CALD and LGBTQI+ communities to apply. Even if you don't check every box in the criteria above, we encourage you to apply today or get in touch with us here.

To provide you with the best experience, we can accommodate you at any stage of the recruitment process. Simply inform our Recruitment team at any time.

Tal Services Limited is recognised by the Workplace Gender Equality Agency as an Employer of Choice. We are proud to be a member of Diversity Council Australia and the Australian Network on Disability. For information on our reconciliation journey, take a look at our Innovate Reconciliation Action Plan.

We acknowledge the Traditional Custodians of the Land in which our Head Office is based, the land of the Gadigal people of the Eora Nation, and recognise their deep connections to the land, sea, and culture.
We extend this acknowledgment to the many Traditional Lands that we operate across and pay our respects to Elders past, present, and emerging.

  • Sydney, New South Wales, Australia ASIC Full time

    About ASIC ASIC is a leading innovative company seeking an Application Security Specialist to lead our product security and application security initiatives, ensuring that security is integrated into every aspect of the software development lifecycle and deployment processes. About the Role As an Application Security Specialist, you will be...


  • Sydney, New South Wales, Australia Protecht Group Full time

    About Protecht GroupWe are a fast-growing Governance, Risk & Compliance (GRC) SaaS business, providing world-class enterprise risk management, compliance, training, and advisory services to over 350 customers across various industry sectors through our offices across APAC, USA & Europe.Our cloud-based SaaS platform – Protecht.ERM is a comprehensive,...


  • Sydney, New South Wales, Australia Zone IT Solutions Full time

    About the RoleWe are seeking an experienced Security Specialist to join our team and protect our applications from potential threats.Key Responsibilities:Conduct thorough security assessments and identify vulnerabilities in our applications.Develop and implement secure coding practices and guidelines to prevent security breaches.Collaborate with software...


  • Sydney, New South Wales, Australia Zone IT Solutions Full time

    We are seeking a highly skilled and experienced Chief Application Security Specialist to ensure the security and integrity of our applications and systems.About UsZone IT Solutions is an Australia-based recruitment company specializing in Digital, ERP, and larger IT Services. We offer flexible, efficient, and collaborative solutions to organizations...


  • Sydney, New South Wales, Australia Salt Recruitment Full time

    Salt Recruitment is proud to offer a challenging opportunity for a Cyber Security Specialist - Application Lead to join our team.About UsSalt Recruitment is a leading recruitment agency with a strong focus on technology and innovation.About the RoleWe are seeking a highly skilled Cyber Security Specialist - Application Lead to lead our application security...


  • Sydney, New South Wales, Australia Tal Services Limited Full time

    About the RoleWe are seeking an experienced Application Security Engineer to join our Cyber Security team at Tal Services Limited. As an Application Security Engineer, you will play a critical role in enhancing our security posture by integrating security practices into our software development lifecycle.Key ResponsibilitiesCollaborate with product...


  • Sydney, New South Wales, Australia Protecht Group Full time

    About Protecht GroupWe are a fast-growing Governance, Risk & Compliance (GRC) SaaS business, providing world-class enterprise risk management, compliance, training, and advisory services to over 350 customers across various industry sectors through our offices across APAC, USA & Europe.Our Unique OfferingOur cloud-based SaaS platform – Protecht.ERM is one...


  • Sydney, New South Wales, Australia Protecht Group Full time

    About Protecht GroupWe are a fast-growing SaaS company that provides enterprise risk management, compliance, and advisory services to over 350 customers globally. Our cloud-based platform, Protecht.ERM, is a comprehensive risk management solution that supports our mission of empowering businesses to thrive in a rapidly changing world.The Culture and...

  • Cybersecurity Manager

    3 weeks ago


    Sydney, New South Wales, Australia Tech-Cyber-Mgmt&Strategy Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Manager - Application Security Specialist to join our team.Key ResponsibilitiesDevelop and deliver an AppSec framework for standardised and measurable secure software development practices.Lead and mentor a small application security team, managing outcomes and stakeholder relationships across the...


  • Sydney, New South Wales, Australia Wilson Security Pty Ltd Full time

    About the Job:Wilson Security Pty Ltd is a leading provider of integrated security solutions, seeking an experienced Security Operations Specialist to join our team. This role is based in various locations across North Ryde and Hornsby Region, offering full-time and casual positions with varying shifts.Job Summary:We are expanding our presence in NSW,...

  • Security Specialist

    2 weeks ago


    Sydney, New South Wales, Australia MSS Security Pty Ltd Full time

    About MSS Security Pty LtdWe are a leading security company in Australia, with a national presence. Our goal is to deliver exceptional service and protect high-profile sites.We have a strong people-focused culture.We offer extensive development opportunities.We provide stability and certainty in our roles.Our Security Officers work across various sectors and...

  • Security Engineer

    4 weeks ago


    Sydney, New South Wales, Australia ASIC Full time

    Job Role SummaryASIC is seeking an experienced Application Security Engineer to lead product security and application security initiatives, ensuring security is integrated into every aspect of the software development lifecycle and deployment processes.About the RoleThis is a key position in ASIC's cybersecurity team, supporting the cyber assurance function...


  • Sydney, New South Wales, Australia Wilson Security Pty Ltd Full time

    At Wilson Security, our Corporate Real Estate Team in Sydney is seeking a skilled Security Officer to join our national specialist security network.This exciting opportunity requires a strong customer service focus, with excellent interpersonal and verbal/written communication skills. You will work closely with our clients and colleagues to provide...


  • Sydney, New South Wales, Australia Tyro Payments Limited Full time

    About Tyro Payments LimitedWe're a tech company at heart, fostering a diverse and inclusive environment, and a passion for continuous learning has always been one of the most important parts of our company's culture.Tyros are a highly collaborative mix of people. You will work closely with our awesome teams and individuals in engineering, product management,...


  • Sydney, New South Wales, Australia Tech-Cyber-Mgmt&Strategy Full time

    Lead Our Application Security TeamWe are seeking an experienced Application Security Manager to lead our dedicated application security team. The successful candidate will be responsible for developing and implementing robust security standards and practices, collaborating with engineering stakeholders, and ensuring the integration of security into the...


  • Sydney, New South Wales, Australia MSS Security Pty Ltd Full time

    About MSS SecurityMSS Security Pty Ltd is a leading security company in Australia, with a national footprint across the country. We have unrivalled experience in delivering high-quality security services and protecting some of the nation's highest profile sites.Our CultureWe value our employees and strive to create a positive work environment. Our culture is...


  • Sydney, New South Wales, Australia MSS Security Pty Ltd Full time

    Job DescriptionWe are seeking a highly motivated Protection Security Specialist to join our team in Adelaide.About MSS SecurityMSS Security Pty Ltd is one of Australia's leading security companies, delivering high-quality services and protecting prominent sites nationwide. To learn more about us, visit our website at www.msssecurity.com.au.Key...


  • Sydney, New South Wales, Australia Randstad Full time

    Randstad is seeking a seasoned Application Security Architect to safeguard the digital landscape of our esteemed insurance client.What will you do?Develop and implement robust security measures throughout the Software Development Lifecycle (SDLC).Design and integrate secure coding practices into image and code repositories like Bitbucket.Collaborate with...


  • Sydney, New South Wales, Australia Tech-Cyber-Mgmt&Strategy Full time

    Job OverviewWe are seeking an experienced Application Security Leader to join our team at Tech-Cyber-Mgmt&Strategy. This is a unique opportunity to leverage your expertise in application security to drive innovation and ensure the highest levels of security for our products.


  • Sydney, New South Wales, Australia MSS Security Pty Ltd Full time

    About MSS Security Pty LtdWe are offering a competitive salary of $65,000 - $80,000 per annum for this Control Room Operator position in Sydney CBD.Job Description:The successful applicant will be responsible for monitoring security systems, responding to incidents, and providing exceptional customer service to staff and visitors. Key responsibilities...