Web Application Security Engineer

5 days ago


Australia CXM Direct LLC Full time $80,000 - $120,000 per year
Position Overview

We are seeking an experienced Web Application Security Engineer to join our team in a unique purple team capacity. This role represents a strategic blend of offensive penetration testing expertise and defensive blue team capabilities, with a specialized focus on securing our web applications and SD-WAN network infrastructure. The successful candidate will be responsible for conducting comprehensive security assessments of our web applications while simultaneously strengthening our defensive posture across our complex proxy and reverse proxy architecture.

This position is ideal for a security professional who thrives at the intersection of offensive and defensive security, possesses deep technical knowledge of web application vulnerabilities, and understands the nuances of securing modern SD-WAN environments. You will work collaboratively with development teams, network engineers, and operations staff to identify vulnerabilities, validate security controls, and drive continuous improvement in our security posture.

Core ResponsibilitiesOffensive Security (Penetration Testing)

The offensive component of this role involves conducting thorough and methodical penetration tests against our web applications, APIs, and network infrastructure. You will be responsible for identifying security vulnerabilities through manual testing techniques, automated scanning tools, and creative attack scenarios that simulate real-world threat actors. This includes testing authentication mechanisms, authorization controls, input validation, session management, and business logic flaws across our application portfolio.

You will perform security assessments of our SD-WAN infrastructure, with particular emphasis on proxy configurations, reverse proxy implementations, SSL/TLS termination points, and web application firewalls. This requires understanding how traffic flows through our network architecture and identifying potential attack vectors that could compromise confidentiality, integrity, or availability.

Defensive Security (Blue Team Operations)

On the defensive side, you will monitor security events, analyze logs from our WAF and proxy infrastructure, and respond to security incidents affecting our web applications. You will work closely with SOC protocols to investigate suspicious activities, perform root cause analysis of security breaches, and implement corrective measures to prevent recurrence.

You will be responsible for tuning and optimizing our security controls, including WAF rules, proxy access controls, rate limiting configurations, and DDoS mitigation strategies.

Purple Team Collaboration

As a purple team member, you will serve as a bridge between offensive and defensive security functions. You will design and execute purple team exercises that test both our detection capabilities and our defensive controls. After conducting penetration tests, you will work with blue team members to ensure that our monitoring systems can detect similar attacks in the future, creating detection rules and improving our reliability.

You will facilitate knowledge transfer and help defenders understand the techniques used by attackers. This collaborative approach ensures that our security program continuously evolves based on real-world testing and operational feedback.

Security Integration and Automation

You will develop automation scripts and tools to streamline repetitive security tasks, such as vulnerability scanning, configuration auditing, and security report generation. This automation will enhance the efficiency of security operations, allowing for more time to be devoted to complex analysis and strategic security initiatives.

Required Qualifications
  • Education Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related technical field; or equivalent practical experience
  • ExperienceMinimum 3-5 years of hands-on experience in web application penetration testing and security assessment
  • Technical Skills Deep understanding of OWASP Top 10 vulnerabilities, common web application attack vectors, and remediation strategies
  • Network Security Practical experience with SD-WAN technologies, forward proxies, reverse proxies (Nginx, HAProxy, Apache), and load balancers
  • Security Tools Proficiency with Burp Suite Professional, OWASP ZAP, Nmap, Metasploit, and vulnerability scanning platforms
  • Programming Strong scripting abilities in Python, Bash, or PowerShell; familiarity with JavaScript, PHP, Java, or .NET for code review
  • Blue Team Skills Experience with SIEM platforms, log analysis, incident response procedures, and threat hunting methodologiesWAF/IPS
  • Hands-on experience configuring and tuning web application firewalls and deep packet inspections
Preferred Qualifications

Experience with cloud security, particularly in AWS, Azure, and alternative cloud environments, is beneficial given the hybrid nature of modern infrastructure. Familiarity with container security (Docker, Kubernetes), API security testing (REST, GraphQL, SOAP), and mobile application security adds significant value to this role.

Previous experience in a purple team capacity, or demonstrated ability to work effectively across offensive and defensive security functions, is strongly preferred. Excellent written and verbal communication skills are essential, as you will be producing detailed security reports, presenting findings to technical and non-technical audiences, and collaborating with diverse stakeholders.

Competitive Compensation

Medical

Gym Allowance

Company Events

Personal Growth


  • Security Engineer

    7 days ago


    Melbourne, Victoria, , Australia XPT Software Australia Pty Full time $80,000 - $120,000 per year

    Operate, configure, and optimize Cisco network security solutions including: Cisco FMC (Firepower Management Center)Cisco ISE (Identity Services Engine)Cisco EWSA (Email/Web Security Appliance)Manage and fine -tune Imperva Web Application Firewall (WAF) policies and rules to protect public -facing applications.Contribute to micro -segmentation strategy using...


  • Church St, Richmond VIC , Australia endeavour group careers Full time $120,000 - $180,000 per year

    Company Description Let's create a more sociable future togetherAt Endeavour, we're totally into what we do. With a portfolio that includes Dan Murphy's, BWS, ALH Hotels, Pinnacle Drinks and more, we love to bring people together. Together we share our passion for our products and industry; it's what inspires us to dream big, and continue to create new...


  • Bundall, Queensland , Australia HealthCare Logic Pty Full time $120,000 - $180,000 per year

    About UsJoin the team transforming hospital intelligence.At HealthCare Logic, we're empowering executive, clinical and operational teams to optimise hospitals through improved data-led decision-making and processes. As the emerging leader in hospital intelligence, our flagship platform SystemView is installed in more than 170 hospitals across Australia,...


  • Adelaide, South Australia , Australia Opes Cyber Security Full time $80,000 - $120,000 per year

    Summary:As a Security Engineer, you'll play a crucial role in designing, implementing, and maintaining secure systems and infrastructure. You'll work collaboratively across IT, infrastructure, and operations teams to ensure environments remain resilient, compliant, and aligned with security best practices. This EOI is to identify potential candidates for...


  • Canberra, Australian Capital Territory , Australia Opes Cyber Security Full time $100,000 - $150,000 per year

    Closing on Tuesday the 11/11/2025Summary:The ICT Security Specialist will enable assessments of High Side environments within critical agencies while providing continuous assessments to other critical government agencies.Responsibilities:Assess Australian Government entities to determine the effectiveness of both prevention and detection security...


  • Melbourne, Victoria, , Australia XPT Software Australia Pty Full time $80,000 - $120,000 per year

    We'relooking for a sharp, driven Cyber Security Engineer to join a high -performing,fast -paced team. This is not a passive role, we need someone who thrives underpressure, solves problems independently, and brings strong networkingfundamentals to the table.Core Responsibilities· Manage and optimize Proxy and EmailSecurity platforms (Cisco WSA, ESA)·...


  • Canberra, Australian Capital Territory , Australia Opes Cyber Security Full time $80,000 - $120,000 per year

    Summary:We're looking for a Cyber Range Engineer to design, develop, and maintain cyber range environments. You'll play a key role in creating realistic network environments, deploying attack and defence scenarios, and supporting training operations.Responsibilities:Design and deploy virtualised network environments for cyber exercises and training.Develop...

  • Web Developer

    1 week ago


    Australia|United States Talent Guys Full time $60,000 - $120,000 per year

    DISCLAIMER: This job posting is for active candidate pooling to build our talent pool. Your qualifications will be considered for both current and future openings. If your profile aligns with a suitable role, our recruitment team will contact you. Please note that this does not guarantee immediate placement or contact. We only accept applications from...


  • Sydney, New South Wales , Australia Eatclub Pty Full time $80,000 - $120,000 per year

    Join the Food Tech Revolution at EatClubAbout UsEatClub is a fast-growing tech company with big global ambitions, co-founded by legendary chef Marco Pierre White and industry leaders. We're on a mission to revolutionise the hospitality industry, helping restaurants boost profitability through smart, dynamic pricing.We power thousands of venues across...

  • Staff Engineer

    5 days ago


    Cremorne, Australia SEEK Full time $150,000 - $250,000 per year

    Company Description NOTE: This is a *senior engineering role* requiring deep expertise in React applications, JavaScript bundling, and advanced tooling, working for a company with a high-performance culture that celebrates the diversity of its people.About SEEKSEEK's portfolio of diverse businesses make a positive impact on a truly global scale. Our...