Principal Penetration Tester
1 week ago
Your Role
The Cyber Security Team protects the bank and our customers from theft, losses and risk events through effective and proactive management of cyber security, privacy and operational risk.
The Security Testing Centre of Excellence (COE) conducts simulated cyber-attacks to ensure systems are safe, sound, and secure by performing security assessments of the Group's technology. This ensures our applications and infrastructure are adequately robust to resist cyber-attacks. Our work seeks to identify security weaknesses using real-world attack scenarios and provide recommendations to assist remediation efforts.
Do Work That Matters
You will lead and perform technical penetration testing activities designed to ensure the bank maintains its risk and security posture at desired levels. You will communicate security issues to both technical and non-technical stakeholders and provide subject-matter expertise across business units. You will mentor junior team members and contribute to the development of innovative solutions to complex technical challenges. This role reports directly to a Centre within the Penetration Testing team.
Your Responsibilities
- Lead and conduct penetration testing and security testing including (but not limited to) web applications, infrastructure, networks, cloud (especially AWS), SaaS, LLM, and mobile applications
- Develop Security Testing plans for business units. Coordinate squads of testers in delivering a large programme of testing engagements, using agile methodologies to track progress, and to resolve blockers.
- Carry out scoping and planning activities to determine components to be tested, approach, methodologies, and appropriate levels of test rigour
- Create comprehensive exploitation strategies that identify exploitable technical or operational vulnerabilities to demonstrate business impact and articulate risk.
- Report results of testing and their implications to stakeholders including suppliers, project owners, product crews, and leadership
- Drive advancements in attack techniques, hardware, software, and other technologies and their implications. Develop new testing methodologies and techniques, contributing to the penetration testing craft across the CoE. Provide technical mentorship and guidance to junior staff
- Mentor junior team members and graduates
- Ensure all tasks align with internal policies and external regulatory requirements
What You Will Need to Succeed
- Expert-level understanding of vulnerability identification and penetration testing methodologies
- Deep knowledge of software exploitation, security principles, and secure design, with experience conducting penetration testing safely in critical infrastructure environments
- Advanced industry accreditations such as Offensive Security Certified Professional (OSCP), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), or similar are desirable
- Experience in incorporating a broad range of automated tools such as Kali Linux, Burp Suite, Metasploit, and others to expand test coverage.
- Experience in vulnerability research, developing security testing tools and methodologies.
- Ability to develop or recommend analytic approaches to novel problems
- Ability to communicate complex information clearly and confidently
- Tertiary qualifications in Software Engineering, Computer Science, Cyber Security, or a related discipline
- Membership or participation in relevant industry associations
If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We're keen to support you with the next step in your career.
We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on
Advertising End Date: 06/11/2025-
Principal Penetration Tester
2 weeks ago
Sydney, New South Wales, Australia Decipher Bureau Full timeAre you technical and looking for an opportunity that can leverage your expertise?Maybe you've been pigeonholed into web app, after web app, or you're stuck in an organisation with limited career growth opportunities?If you're a seasoned penetration tester or red teamer, this role is worth exploring.About CompayWe're partnering with a fast-growing,...
-
Penetration Tester
2 weeks ago
Sydney, New South Wales, Australia Cyberlinx Full time $120,000 - $180,000 per yearCyberlinx | Full-Time | Remote (Australia-based)Cyberlinx is a fast-growing, pure-play cybersecurity consultancy delivering high-impact work across enterprise, government, and critical infrastructure. We're looking for a highly skilled Lead Penetration Tester and take the lead on advanced testing engagements across Australia.About the RoleAs a Lead Pen...
-
Senior Penetration Tester
1 week ago
Sydney, New South Wales, Australia Tech Aalto Full time $120,000 - $200,000 per yearSenior Penetration Tester – Job DescriptionRole Overview-The Senior Penetration Tester will lead and execute advanced penetration testing and vulnerability assessment activities across applications, networks, cloud, and infrastructure. This role requires deep technical expertise, hands-on testing skills, and the ability to communicate findings and...
-
Senior Penetration Tester
2 weeks ago
Sydney, New South Wales, Australia CareCone Group Full time $120,000 - $180,000 per yearRole:Senior Penetration TesterLocation:Sydney/ Melbourne/ CanberraEmployment Type:ContractDuration:9 monthsMust have:Full working rights. No sponsorship available.Role OverviewThe SeniorPenetration Testerwill lead and execute advanced penetration testing and vulnerability assessment activities across applications, networks, cloud, and infrastructure. This...
-
Lead Penetration Tester
1 week ago
Sydney, New South Wales, Australia Cyberlinx Full time $104,000 - $130,878 per yearCyberlinx | Full-Time | (Sydney)Cyberlinx is a fast-growing, pure-play cybersecurity consultancy delivering high-impact work across enterprise, government, and critical infrastructure. We're looking for a highly skilled Lead Penetration Tester and take the lead on advanced testing engagements across Australia.About the RoleAs a Lead Pen Tester, you'll be...
-
Penetration Tester
3 days ago
Sydney, New South Wales, Australia NCS Group Australia Full time $120,000 - $180,000 per yearAt NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.We are committed to creating an environment that prioritises innovation,...
-
Penetration Tester
3 days ago
Sydney, New South Wales, Australia NCS Full time $100,000 - $150,000 per yearCompany DescriptionAt NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.We are committed to creating an environment that...
-
Penetration Tester
2 weeks ago
Sydney, New South Wales, Australia Robert Walters Full time $120,000 - $160,000 per yearAn exciting opportunity has arisen for a Penetration Tester to join a well-established cyber security team within a large organisation. This role offers the chance to work on a variety of offensive security engagements in a complex environment, building your skills alongside experienced security professionals and contributing to high-profile projects.What...
-
Senior Penetration Testing Consultant
2 weeks ago
Sydney, New South Wales, Australia Cybertify Full time $120,000 - $180,000 per yearAbout CybertifyCybertify is Australia's premier compliance-first cybersecurity consulting firm, proudly Australian owned, fully independent, and sovereign in every respect. We specialise in protecting and enabling organisations in the country's most heavily regulated sectors: financial services, superannuation, legal, aged care, healthcare, banking,...
-
Cyber Assurance
1 week ago
Sydney, New South Wales, Australia AYAN INFOTECH PTY LTD Full time $120,000 - $180,000 per yearAYAN InfoTech is looking for Cyber Assurance - Consultant/Architect/ Analyst to join an exciting project based in Sydney / Melbourne / Canberra. The role offers you the opportunity to contribute towards an extremely well structured and mature environment, working on sophisticated enhancement projects. Role: Cyber Assurance - Consultant/Architect/...