Penetration Tester

2 weeks ago


Sydney, New South Wales, Australia Hays Full time

Penetration Tester

Your new company

A leading organisation committed to building secure, high‑quality software and infrastructure. You will join a team that values strong security practices, continuous improvement, and technical excellence across application, infrastructure, and cloud environments.

Your new role

As a Penetration Tester, you will conduct in‑depth security assessments across web applications, mobile apps, thick clients, networks, and infrastructure. You'll perform manual and automated penetration testing, secure code reviews, threat profiling, and vulnerability analysis. You'll collaborate closely with development and architecture teams, provide remediation guidance, and contribute to building a mature security posture across the organisation.

What you'll need to succeed

  • 9–12 years of total IT experience, with at least 9 years in penetration testing across applications, infrastructure, and mobile.
  • Strong hands‑on experience in:
  • Web and thick‑client penetration testing
  • Mobile application security testing
  • Infrastructure and network penetration testing
  • Secure code review across Java, ASP, .NET, C++, C#, PHP, etc.
  • Strong understanding of cryptography, authentication mechanisms, and secure development practices.
  • Ability to analyse application architecture, perform threat modelling, and conduct comprehensive manual reviews.
  • Deep knowledge of OWASP Top 10, SANS Top 25, and industry security standards.
  • Understanding of HTTP, SOAP/REST, SSL/TLS protocols.
  • Experience with relational databases: Oracle, MS‑SQL, MySQL.
  • Strong skills in vulnerability analysis, impact assessment, and risk determination.
  • Experience leading security testing engagements and mentoring junior testers.
  • Excellent written, verbal, and presentation communication skills.
  • Familiarity with secure SDLC processes and security consulting.

Tools proficiency:

  • Secure code review: Checkmarx, HP Fortify, AppScan Source
  • Web app scanning: AppScan, HP WebInspect, Burp Suite Pro
  • Programming languages: Java, C, C++, .NET
  • Development knowledge: ASP.NET, ASP, PHP, J2EE, JSP
  • Database scanning: NGS, Scuba
  • Vulnerability scanning: Qualys, Nessus

Good to have:

  • Hands‑on application development experience.
  • Experience using modern IDEs (Java/.NET/PHP); Eclipse is a plus.
  • Experience conducting network penetration testing and vulnerability assessments.
  • Exposure to Pre‑Sales / RFPs.
  • Knowledge of compliance frameworks: ISO 27001, PCI DSS, HIPAA, SOX.
  • Security certifications such as CEH, CISSP, CISA, ECSA, LPT.

What you'll get in return

A chance to work on challenging penetration testing engagements, influence security strategy, and strengthen the organisation's overall security posture. You'll gain exposure to a wide range of technologies, opportunities to lead and mentor, and a pathway to grow into advanced offensive security roles.


  • Penetration Tester

    1 week ago


    Sydney, New South Wales, Australia ALOIS Australia Full time

    Job Role: PenTesterJob Type: ContractLocation: SydneyMust have OSCP certificationStrong understanding of penetration testing methodologies and tools.Proficiency with Web services, mobile and thick client penetration testing.Ability to communicate complex technical findings effectively to both technical and non-technical stakeholders.Including liaising with...


  • Sydney, New South Wales, Australia ING Australia Full time

    At ING Australia, we're all about making life simpler and more rewarding – for our customers, our people, and the communities we support. Joining ING means stepping into an environment where your individuality isn't just welcomed – it's celebrated. We've built a culture that's fun, inclusive, and supportive, giving you the freedom to do your thing and...


  • Sydney, New South Wales, Australia ING Full time

    At ING Australia, we're all about making life simpler and more rewarding – for our customers, our people, and the communities we support. Joining ING means stepping into an environment where your individuality isn't just welcomed – it's celebrated. We've built a culture that's fun, inclusive, and supportive, giving you the freedom to do your thing and...


  • Sydney, New South Wales, Australia ING Full time

    REQ 16/01/2026Information Security ManagementSydney, AustraliëING BankAt ING Australia, we're all about making life simpler and more rewarding – for our customers, our people, and the communities we support. Joining ING means stepping into an environment where your individuality isn't just welcomed – it's celebrated. We've built a culture that's fun,...


  • Sydney, New South Wales, Australia Reserve Bank of Australia Full time

    12-month fixed term contractExposure to diverse technologies and applicationsOpportunity to perform purple team engagementsDo work that makes a difference This is an exciting opportunity to work in a highly mature cyber security team. This role sits within the Assessments and Testing team in the Bank's IT security services. As part of the role, you will be...


  • Sydney, New South Wales, Australia Microsoft Full time

    OverviewSecurity represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft 365 aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end,...

  • Ethical Hacker

    3 days ago


    Sydney, New South Wales, Australia Packetlabs Full time

    Packetlabs was built by an ethical hacker after seeing vulnerability assessments presented as penetration tests. Our slogan "Ready for more than a VA scan?" drives at the importance of not providing our clients with a false sense of security.We are a passionate team of highly trained, proactive, ethical hackers. We provide expert-level penetration testing...


  • Sydney, New South Wales, Australia MNI ELECTROSPARK Full time

    MNI Electrospark All Trade Services currently employing over 100 staff members provides a range of day-to-day, end-to-end all trade Solutions in order to maximize customer satisfaction. MNI Electrospark All Trades is a highly reputable Sydney based company that provides building maintenance and repairs to houses, units and town houses leased by Department of...

  • Cyber Security

    7 days ago


    Sydney, New South Wales, Australia Deloitte Services Pty Ltd Full time

    Learn from the best in the business Flexible work arrangements – work in a way that suits you best, including part-time options Access to free and confidential coaching for you and your family including wellbeing, financial and nutrition coachingWe're looking for talented Cyber Professionals from various backgrounds and levels to express their interest in...

  • Penetration Tester

    2 weeks ago


    Sydney Central Business District, Australia Mane Consulting Full time

    Permanent - Sydney CBD, New South Wales - Posted 2 hours ago - AU$120000 - AU$170000 per annum USD / Year - Salary: AU$120000 - AU$170000 per annum **Job Title: Penetration Tester** **Responsibilities**: - Identifying vulnerabilities and recommending corrective actions to clients - Preparing comprehensive reports detailing the results of penetration...

  • Penetration Tester

    2 weeks ago


    Council of the City of Sydney, Australia Triskele Labs Full time

    Overview The Offensive Security Consultant at Triskele Labs plays a key role in delivering high-quality penetration testing services. As a Subject Matter Expert (SME) in the security industry, the consultant is responsible for managing the entire lifecycle of offensive security engagements, from initial setup and information gathering to report generation...


  • Council of the City of Sydney, Australia Reserve Bank of Australia Full time

    Senior IT Security Penetration Tester page is loaded## Senior IT Security Penetration Testerlocations: Sydneytime type: Full timeposted on: Posted 4 Days Agojob requisition id: JR3549* 12-month fixed term contract* Exposure to diverse technologies and applications* Opportunity to perform purple team engagements**Do work that makes a difference**This...


  • Sydney, Australia Toll Group Full time

    About Toll Group At Toll, we do more than just logistics - we move the businesses that move the world. Our 16,000 team members can help solve any logistics, transport, or supply chain challenge - big or small. We have been supporting our customers for more than 130 years. Today, we support more than 20,000 customers worldwide with 500 sites in 27 markets,...


  • Sydney, Australia Security Centric Full time

    **Role**: Penetration Tester/Red Team - Various Levels **Location**: Sydney **Division**: Technical Assurance - Lab time to work on new techniques - Visibility into blue team view of your testing activity - get better at lurking and avoiding detection - Strong career development track - go further, faster - Mid/senior/lead roles available - Not just another...

  • Security Consultant

    2 weeks ago


    Sydney, Australia InfoTrust Full time

    **Exciting development opportunities and a competitive package working in the fast-growing Cyber Security Industry** - **Working for a young and innovative company that believes in working hard and celebrating success** - **Excellent centrally located modern offices in Sydney CBD** **About the company**: InfoTrust’s mission is the protection of our...

  • Security Tester

    7 days ago


    Sydney, Australia Carecone Full time

    **Key Responsibilities**: - Work as a technical SME for penetration testing for the organisation/assigned project. - Communicate security issues to a wide variety of internal and external “customers” to include technical teams, executives, risk groups, vendors and regulators. - Interfaces with several key stakeholders in the company to ensure quality...


  • Sydney, Australia Insignia Financial Full time

    Penetration Testing Lead - Be part of a team where everyone belongs, and individuality is celebrated - True Flexibility - 2 days in the office - Permanent Full Time, based anywhere in Australia Following the recent appointment of our General Manager Cyber Security, we are actively expanding our team within the newly created Cyber Security Business Unit to...


  • Sydney, Australia Insignia Financial Full time

    Be part of a team where everyone belongs, and individuality is celebrated - True Flexibility - 2 days in the office - Permanent Full Time, based anywhere in Australia Following the recent appointment of our General Manager Cyber Security, we are actively expanding our team within the newly created Cyber Security Business Unit to support our cyber vision as...


  • Sydney, Australia HUMANISED GROUP Full time

    **Job Purpose**: Looking for a Mid-Level Penetration Testing Consultant to join a reputable and global organization. **Main Responsibilities**: - Perform penetration testing, vulnerability assessment and provide mitigation recommendations - Prepare test plans, conduct tests, and report on tests - Maintain and enhance the Penetration Testing toolset -...