Penetration Tester, Cyber Security

2 weeks ago


Sydney, Australia Toll Group Full time

About Toll Group

At Toll, we do more than just logistics - we move the businesses that move the world. Our 16,000 team members can help solve any logistics, transport, or supply chain challenge - big or small. We have been supporting our customers for more than 130 years. Today, we support more than 20,000 customers worldwide with 500 sites in 27 markets, and a forwarding network spanning 150 countries. We are proudly part of Japan Post —
- Location Flexible - Brisbane, Melbourne or Sydney

Group IT provides technology strategy, governance, delivery, and support for all of Toll. The team enable Toll with the right technology foundations and business systems to grow the business and support our customer needs.

As we continue to evolve and transform, we have a new opportunity for a Penetration Tester to join our Cyber Security Team.

Reporting into the Cyber Security Threat Prevention Manager, you will provide first line of defence against threat actors, responsible for ensuring that Toll Group has the capability to prevent and detect security threats and respond accordingly.

Your key focus will be to manage identity, access and data protection capabilities.

Your responsibilities will include:
- Conduct red/purple team exercises to test the defence capability and effectiveness of the blue team / Security Operations Centre (SOC)-
- Perform threat assessment and threat modelling- Conduct threat hunting and analysis- Manage and mentor the junior analysts within the Cyber Threat Prevention Teams

To be successful you will have:
- Minimum 8 years’ experience as a Cyber Security Specialists/Penetration Tester focusing on: Red Team Operations / Threat Hunting- Excellent knowledge and experience in risk management strategies for safe execution of Red-Blue Team exercises- Excellent knowledge and experience in using the MITRE ATT&CK framework- Demonstrated experience in identifying and defending on different TTPs- Strong knowledge and hands on experience on security tools (Burpsuite, Kali, Crowdstrike, Splunk)- In-depth understanding and experience on Cyber Risk Management- Strong knowledge and experience in using ISO 27000 series or NIST Cyber Security Framework- Strong knowledge of Operational Technology (SCADA, PLCs) is advantageous- Strong scripting (PowerShell, Python) background is advantageous

Specialist Conditions:
This position is only open to Australian Citizens and Australian Permanent Residents.

What moves you?

At Toll, you can help play a vital role in delivering what matters. From food, fuel, medicine and rescue services, we keep businesses and communities thriving. Every day brings change. We see that as an opportunity. To be curious. To ask the right questions. And build meaningful connections. Because finding new ways to solve problems is what we do. With a bold vision to expand our global reach, our 16,000+ people bring a passion for progress. We collaborate in friendly, caring teams, supported by approachable leaders who give us the autonomy to quickly make decisions with impact. Learn and grow with industry-leading training, alongside talented experts. Feel empowered to take on diverse challenges and new responsibilities to move you, our customers, and our world further.

At Toll everyone is welcome including those of all ages, ethnicities, genders and abilities.

You must be entitled to work in Australia and be prepared to undertake pre-employment checks including a criminal history check and medical.



  • Sydney, New South Wales, Australia Commonwealth Bank Full time $120,000 - $180,000 per year

    Your RoleThe Cyber Security Team protects the bank and our customers from theft, losses and risk events through effective and proactive management of cyber security, privacy and operational risk.The Security Testing Centre of Excellence (COE) conducts simulated cyber-attacks to ensure systems are safe, sound, and secure by performing security assessments of...

  • Penetration Tester

    3 days ago


    Greater Sydney Area, Australia Robert Walters Full time $90,000 - $120,000 per year

    Location: Sydney, NSW Contract Duration: 6 months (with potential for extension) Agency Type: Government Agency Project: Cyber Security Maturity Uplift A leading Government Agency is seeking a skilled Application Penetration Tester to join a high-impact cyber security initiative aimed at uplifting application security maturity across critical systems. This...

  • Security Consultant

    1 week ago


    Sydney, Australia InfoTrust Full time

    **Exciting development opportunities and a competitive package working in the fast-growing Cyber Security Industry** - **Working for a young and innovative company that believes in working hard and celebrating success** - **Excellent centrally located modern offices in Sydney CBD** **About the company**: InfoTrust’s mission is the protection of our...


  • Sydney, New South Wales, Australia Phronesis Security Full time $80,000 - $120,000 per year

    Phronesis Security is Australia's first B Corp certified cyber security company, committed to delivering world-class cyber security consulting with a tangible social and environmental impact. To do so, we have built sharing our profits with some of Australia's highest impact charities into our core operating model.We provide tailored, pragmatic advice,...

  • Penetration Tester

    6 days ago


    Sydney, Australia Hamilton Barnes Associates Limited Full time

    A leading cybersecurity consultancy specializing in offensive security, red teaming, and ethical hacking is seeking an experienced Penetration Tester. This role provides the opportunity to conduct high-impact security assessments for enterprise clients across Australia, identifying vulnerabilities before attackers can exploit them. If you're an OSCP or...

  • Cyber Security

    7 days ago


    Sydney, New South Wales, Australia Deloitte Services Pty Ltd Full time $80,000 - $150,000 per year

    Learn from the best in the business Flexible work arrangements – work in a way that suits you best, including part-time options Access to free and confidential coaching for you and your family including wellbeing, financial and nutrition coachingWe're looking for talented Cyber Professionals from various backgrounds and levels to express their interest in...

  • Penetration Tester

    1 week ago


    Sydney, New South Wales, Australia NCS Group Australia Full time $120,000 - $180,000 per year

    At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.We are committed to creating an environment that prioritises innovation,...

  • Penetration Tester

    1 week ago


    Sydney, New South Wales, Australia NCS Full time $100,000 - $150,000 per year

    Company DescriptionAt NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.We are committed to creating an environment that...

  • Incident Responder

    2 days ago


    Sydney, Australia Quigly Cyber Full time

    Diverse, inclusive and supportive team - Proudly making a difference with the transition to renewable energy - You love Cyber Security Quigly are a boutique consultancy with a great network of clients across many industries. **Company Overview** Join one of Australia's top organizations. Our client improves the lives of millions - from lighting up sports...


  • Sydney, Australia AI Talent Full time

    We are looking for a seasoned and highly capable Senior Cyber Security Analyst to join our team. In this key role, you will be responsible for protecting the organisation’s systems, networks, and data against evolving cyber threats. Your deep knowledge of cyber security frameworks, risk management, incident response, and operational security will be...