Application Security Specialist

7 days ago


Melbourne, Victoria, Australia IT M S Full time
Job Description

We are seeking an experienced Application Security Engineer to enhance our security posture by integrating security practices into our software development lifecycle.

The ideal candidate will collaborate closely with product development teams to identify, analyse, and mitigate security vulnerabilities in our applications and services.

As an Application Security Engineer at TAL, you will be responsible for ensuring the security of our applications by implementing and maintaining robust security measures, and ensure applications are onboarded to Application Security tools and continuous integration of Application Security plug-ins in CI/CD pipeline.

You will work closely with development teams to identify, mitigate and risk assess security vulnerabilities throughout the software development lifecycle.

You will also foster security awareness and security culture, providing security training to development teams.

You will collaborate with Business, Risk and Cyber and other stakeholders to understand business requirements and translate them into technical solutions while improving application security and compliance of the products.

Key Responsibilities:
  • Drive Application Security strategy across Enterprise and provide timely support and education to development teams on application security best practices, including secure coding techniques and the use of security tools.
  • Work with product development teams to design and implement secure solutions, ensuring adherence to secure coding practices throughout the software development lifecycle (SDLC), onboard applications to application security tools and integrate Application Security plug-ins with CI/CD pipeline so the security issues are identified during the coding stage.
  • Identify, analyse, and remediate vulnerabilities identified through Application Security tools, regular security assessments, penetration testing, and code reviews.
  • Lead application threat modelling sessions and application architecture reviews to proactively identify and address security threats and conduct security assessments on applications to identify and remediate vulnerabilities.
  • Evaluate, recommend, and manage Application Security tools and technologies including related policies and procedures that enhance application security, including static and dynamic analysis tools.
  • Execute planned and ad-hoc security scans of software applications and interpret results for development teams.
  • Maintain comprehensive documentation of application security processes and controls, security vulnerabilities, risk assessments, and remediation plans.
  • Prepare security metrics and reports for stakeholders.
  • Collaborate with product development teams, Cyber and other stakeholder for incident response, threat detection, and forensics teams to address security incidents and improve overall security posture.
  • Develop and deliver security training programs for developers and other stakeholders to foster a security-first culture.
  • Ascertain a holistic understanding of TAL's systems, products, applications, development workloads and lifecycles as well as current TAL policies, standards and processes.
  • Work with vendors to tailor application security tools to fit TAL workloads and improve policies and processes currently in place.
  • Ensure required training and development is undertaken in a timely manner and keep up to date with the latest industry trends in cyber security including what technologies and controls may be the best fit for certain solution requirements with an emphasis on security.
Requirements:
  • A relevant tertiary qualification, preferably a Bachelor's degree in Computer Science, Information Technology or equivalent.
  • Minimum of 3 years in application security, software development, or a related IT role, with a strong focus on security practices including development, secure coding and vulnerability management, threat modelling and secure architecture.
  • Experience in Static Application Security Testing (SAST) tools such as Checkmarx, Snyk, Synopsys, etc., Software Composition Analysis (SCA) tools such as Snyk, Blackduck, Sonatype etc, and Dynamic Application Security Testing (DAST) tools such as Checkmarks and Veracode and understanding of how to integrate them into CI/CD pipelines.
  • Working knowledge in Azure Cloud and associated technologies including but not limited Azure Dev Ops, Microsoft Defender for Cloud, Azure Policies and Compliance frameworks, WAF, Firewalls and Entra ID.
  • Hands-on development experience in programming languages such as.NET and Java.
  • Experience in automation using scripting languages such as Powershell, Java Script and Python.
  • Knowledge and experience in web application security including the ability to interpret associated security risks and vulnerabilities such as OWASP Top10 Strong understanding of application security standards (OWASP ASVS, NIST SP, etc.) and secure coding guidelines.
  • Experience with security testing methodologies, including penetration testing, vulnerability assessments and remediation.
  • Experience with Agile development methodologies with working knowledge in products such as Jira.
  • Fundamental knowledge of microservice architecture (Containerisation, Docker and Kubernetes)Experience or knowledge in writing and deploying Infrastructure as Code (IaC), preferably experience in Terraform.
  • Knowledge of regulatory and industry standards and frameworks, APRA CPS234, ASD8, CIS 20, NIST CSF and MITRE Attack.
  • Relevant certifications (CEH, OSWE, OSCP, CASE, AZ-500, etc.) are preferred but not mandatory.
  • Strong analytical and problem-solving skills, with the ability to communicate complex security concepts to non-technical stakeholders.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills.
  • Ability to deal with ambiguity and work independently with limited direction in a fast-paced environment.
  • Penetration testing experience preferred but not mandatory Passionate about security, with an intention to always excel and self-driven to develop technical and professional skills.

We value diversity in all its forms and are committed to fostering an inclusive and equitable culture for all our people.

We encourage Aboriginal and Torres Strait Islander people, individuals from all backgrounds, including those with caring responsibilities, people living with disability, and individuals from the CALD and LGBTQI+ communities to apply.

Even if you don't check every box in the criteria above, we encourage you to apply today or get in touch with us To provide you with the best experience, we can accommodate you at any stage of the recruitment process.

Simply inform our Recruitment team at any time.

TAL is recognised by the Workplace Gender Equality Agency as an Employer of Choice.

We are proud to be a member of Diversity Council Australia and the Australian Network on Disability.

For information on our reconciliation journey, take a look at our We acknowledge the Traditional Custodians of the Land in which our Head Office is based, the land of the Gadigal people of the Eora Nation, and recognise their deep connections to the land, sea, and culture.

We extend this acknowledgment to the many Traditional Lands that we operate across and pay our respects to Elders past, present, and emerging.

Everyone at TAL has a responsibility to do the right thing and is accountable for the way they conduct themselves.

Our expectations are that you follow the principles set out in our Code of Conduct when you come to work every day.

Risk management is everyone's responsibility.

If you are already a TAL employee please apply via the Smart Recruiters button in Workday and navigate to the Employee Portal.

This is important to ensure that your application is recorded accurately.

TAL Opportunity Types:

Promote local employment to your region, community or member organisation with a u Workin Talent Community.

Find out more.

#J-18808-Ljbffr



  • Melbourne, Victoria, Australia UniSuper Full time

    About UniSuperUniSuper is a leading superannuation fund in Australia, dedicated to providing exceptional retirement outcomes for its members. With a strong focus on innovation and customer-centricity, we're committed to making a positive impact on the lives of our members and the broader community.The OpportunityWe're seeking an experienced Application...


  • Melbourne, Victoria, Australia XPT Software Australia Pty Ltd Full time

    Job Title: Application Security SpecialistAt XPT Software Australia Pty Ltd, we are seeking an experienced Application Security Specialist to join our team. As a key member of our security team, you will be responsible for conducting comprehensive vulnerability assessments and penetration testing on applications and systems to identify potential security...


  • Melbourne, Victoria, Australia XPT Software Australia Pty Ltd Full time

    Job Title: Program Delivery / Platform Arch/Eng/Security with NV2Job Summary: XPT Software Australia Pty Ltd is seeking a highly skilled Application Security Specialist to join our team. As a key member of our security team, you will be responsible for conducting comprehensive vulnerability assessments and penetration testing on applications and systems to...


  • Melbourne, Victoria, Australia XPT Software Australia Pty Ltd Full time

    Job Title: Program Delivery / Platform Arch/Eng/Security with NV2Job Summary: We are seeking an experienced Application Security Specialist to join our team at XPT Software Australia Pty Ltd. The successful candidate will be responsible for conducting comprehensive vulnerability assessments and penetration testing on applications and systems to identify...


  • Melbourne, Victoria, Australia Prosa Ung Full time

    About the RoleWe are seeking an experienced Application Security Specialist to join our team at Prosa Ung. As a key member of our security team, you will play a critical role in ensuring the integrity and security of our applications and data.Key ResponsibilitiesSupport the design and development of secure solutions to protect our applications and data from...


  • Melbourne, Victoria, Australia Prosa Ung Full time

    About the RoleWe are seeking an experienced Application Security Specialist to join our team at Prosa Ung. As a key member of our security team, you will play a critical role in ensuring the integrity and security of our applications and data.Key ResponsibilitiesSupport the design and development of secure solutions to protect our applications and data from...


  • Melbourne, Victoria, Australia Prosa Ung Full time

    About the RoleWe are seeking an experienced Application Security Specialist to join our team at Prosa Ung. As a key member of our security team, you will play a critical role in ensuring the integrity and security of our applications and data.Key ResponsibilitiesSupport the design and development of secure solutions to protect our applications and data from...


  • Melbourne, Victoria, Australia ISS SECURITY PL Full time

    {"title": "Freight Security Specialist", "content": "Secure the Future of LogisticsAt ISS Security P/L, we're committed to safeguarding the integrity of our clients' assets and ensuring the smooth flow of goods and services through our facilities. As a Freight Security Specialist, you'll play a critical role in maintaining the highest standards of security...


  • Melbourne, Victoria, Australia Tal Services Limited Full time

    Job DescriptionWe are seeking an experienced Application Security Engineer to enhance our security posture by integrating security practices into our software development lifecycle.The ideal candidate will collaborate closely with product development teams to identify, analyse, and mitigate security vulnerabilities in our applications and services.Key...


  • Melbourne, Victoria, Australia Tal Services Limited Full time

    Job Title: Application Security EngineerWe are seeking an experienced Application Security Engineer to join our Cyber Security team at TAL Services Limited. As a key member of our team, you will play a critical role in enhancing our security posture by integrating security practices into our software development lifecycle.Key Responsibilities:Drive...


  • Melbourne, Victoria, Australia Tal Services Limited Full time

    Job Title: Application Security EngineerWe are seeking an experienced Application Security Engineer to join our Cyber Security team at TAL Services Limited. As a key member of our team, you will play a critical role in enhancing our security posture by integrating security practices into our software development lifecycle.Key Responsibilities:Drive...


  • Melbourne, Victoria, Australia XPT Software Australia Pty Ltd Full time

    Job Title: Program DeliveryThis is a remote position.Key Responsibilities:Conduct comprehensive vulnerability assessments and penetration testing on applications and systems to identify potential security risks.Provide expert guidance on application security best practices, standards, and frameworks.Develop and execute application security testing...


  • Melbourne, Victoria, Australia UniSuper Full time

    About UniSuperWe're a leading superannuation fund in Australia, dedicated to helping our members achieve a better tomorrow. Our mission is to provide innovative solutions that make a positive impact on people's lives.The OpportunityWe're seeking an experienced Application Security Specialist to join our team. As a key member of our security team, you'll play...


  • Melbourne, Victoria, Australia UniSuper Full time

    About UniSuperWe're a leading superannuation fund in Australia, dedicated to helping our members achieve a better tomorrow. Our mission is to provide innovative solutions that make a positive impact on people's lives.The OpportunityWe're seeking an experienced Application Security Specialist to join our team. As a key member of our security team, you'll play...


  • Melbourne, Victoria, Australia UniSuper Full time

    About UniSuperWe're a leading superannuation fund in Australia, dedicated to helping our members achieve a better future. Our mission is to provide exceptional retirement outcomes for our members, and we're looking for talented individuals to join our team.The OpportunityWe're seeking an experienced Application Security Specialist to join our team. As a key...


  • Melbourne, Victoria, Australia UniSuper Full time

    About UniSuperWe're a leading superannuation fund in Australia, dedicated to helping our members achieve a better tomorrow. Our mission is to provide innovative solutions that make a positive impact on people's lives.The OpportunityWe're seeking an experienced Application Security Specialist to join our team. As a key member of our security team, you'll play...

  • Security Officer

    3 weeks ago


    Melbourne, Victoria, Australia MSS Security Full time

    About MSS SecurityMSS Security is a leading security company with a national footprint across Australia, delivering high-quality services and protecting high-profile sites. To learn more, visit our website.Our CultureWe value our employees and offer:A high people and culture focusExtensive development and progression opportunitiesStability and certainty in a...

  • Security Officer

    2 weeks ago


    Melbourne, Victoria, Australia MSS Security Full time

    About MSS SecurityMSS Security is one of Australia's leading security companies, with a national footprint across the country. We have unrivalled experience in delivering high-quality service and protecting some of the nation's highest-profile sites.Our CultureWe value our employees and strive to create a positive work environment. Our culture is built on...

  • Security Officer

    2 weeks ago


    Melbourne, Victoria, Australia MSS Security Full time

    About MSS SecurityMSS Security is one of Australia's leading security companies, with a national footprint across the country. We have unrivalled experience in delivering high-quality service and protecting some of the nation's highest profile sites.Our CultureWe value our employees and strive to create a positive work environment. Our culture is built on...


  • Melbourne, Victoria, Australia MSS Security Pty Ltd Full time

    About MSS Security Pty LtdMSS Security Pty Ltd is a premier security provider in Australia, recognized for its extensive experience in delivering exceptional service and protecting some of the nation's most significant venues. For further details, please visit our website.Company CultureAt MSS, our employees appreciate working with us due to our:Commitment...