
Cyber Offensive Security Lead
1 week ago
Key role in Security maturity journey, uplifting Security Testing
- Hybrid, flexible working environment, with Alexandria (Sydney), Melbourne or Brisbane office options
**About Ampol**
Here at Ampol, we are proud of our heritage as Australia's only owned fuel brand. Fuel may be the foundation of our business, but our motivation and purpose come from the people, industries, and communities we engage with. From our origins until today, we've always been inspired by the role we can play in people's lives - to keep them moving, to make journeys happen.
In the next few years, Ampol will be evolving our energy offering to ensure we continue to meet the ongoing needs of our customers whilst best leveraging marketplace opportunities as they arise. We are investing in our infrastructure and people to ensure that we can continue to provide, safe, reliable, and competitive supply to our valued customers.
For over 100 years we have supported Australians to travel far and wide, and we'll be here for 100 more powering better journeys.
**The role**:
The Cyber Offensive Security Lead will be part of the Cyber Security Architecture team for Ampol Group, responsible for developing and delivering the Enterprise Cyber Security Testing standards, guidelines and procedures (incl. Application Security, penetration testing etc).
The Cyber Offensive Security Lead will also provide cyber risk consulting, compliance, advice/recommendations across the enterprise to support current & future requirements, propose Security Testing solutions and governance that deliver the desired security posture.
This is a permanent position that can be based from any of our Australian offices (Alexandria NSW, Brisbane or Melbourne) with flexible, hybrid work options available.
**Key duties**:
- Identify, influence, advise and recommend cyber security services and technology that will enable business solutions to be delivered in a pragmatic manner whilst preserving the integrity of the Ampol enterprise environment and ensure ongoing compliance with relevant regulatory requirements.
- Analysis/assessment of business requests whilst constructively challenging and negotiating the requirements to derive the underlying needs together with development or quality assurance of solution designs, vendor proposals, business cases and service implementation plans/documentation.
- Provide guidance and support to Project teams on cyber security architectural risks and aspects of infrastructure or system development and integration
- Build and maintain effective working relationships with business customers and external vendors/suppliers to support Ampol objectives
- Support education and awareness activities to optimise the use of existing technologies, services and controls (people, process and technology) to arrive at a "risk-informed" and pragmatic outcome.
- Development, and communication of the enterprise cyber security architecture including defining the relevant design standards and legislative requirements (ISO, NIST, PCI/DSS,), policies, key principles, technical strategies/standards, guidelines and procedures required to support it.
- Assist the evolution of the enterprise cyber security architecture by defining the risks, policies, methods, models, tools, processes, and procedures that describe the organisation's current and future cyber security state
**About you**:
- Strong influencing, collaboration and organisational skills
- Relevant certifications such as for security management (CISSP, CISM, or CISA); Offensive security (OSCP, CREST, CEH, GSEC); Architecture (SABSA, TOGAF); or technical and practical (GIAC / SANS) or vendor specific for Microsoft, are advantageous
**Demonstrated expertise and experience with**:
- SOA security design, controls and implementation
- A broad range of technical concepts: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy.
- Information/Cyber Security Frameworks and standards (ISO 27k, NIST, ITIL, SABSA, TOGAF, IRAP, COBIT, etc)
- IT information protection, security and regulatory policies and standards
- IT Systems Engineering Process and Engineering life cycles
**We'll take you further by**:
- Our total remuneration is competitive. This is across base salary, a performance incentive, employee share offers and a 25% discount on Fuel for two privately used cars
- We are flexible. Many of our teams have embraced hybrid work, balancing time spent remote working, with time spent at an office to connect and work together where it adds value.
- We value recognition. We have an internal recognition platform amplifying the achievements of those who do great work and demonstrate our capabilities and values.
- Career development and learning opportunities including LinkedIn Learning and other tailored training solutions.
- BabyCare Package - financial and flexible support for parents transitioning back
-
Lead Cyber Security Consultant
2 weeks ago
Sydney, New South Wales, Australia Skylight Cyber Security Full time $90,000 - $120,000 per yearAbout Skylight CyberAt Skylight Cyber, we're young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are...
-
Lead Cyber Security Consultant
2 weeks ago
Sydney, New South Wales, Australia Skylight Cyber Security Full timeOverviewSkylight Cyber is a young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are passionate about the...
-
Lead Cyber Security Consultant
2 weeks ago
Sydney, New South Wales, Australia Skylight Cyber Security Full timeOverviewSkylight Cyber is a young, transparent, and culture-focused boutique cyber security firm specialising in providing high-end services to enterprises globally. We provide our customers with world class expertise to build and continuously evolve an effective security stack across people, process, and technology.We thrive and are passionate about the...
-
Offensive Security Specialist
2 weeks ago
Sydney, New South Wales, Australia beBeeCybersecurity Full timeJob DescriptionThe Cyber Security division is responsible for protecting the bank and its customers from cyber intrusions, theft, and loss by effective and proactive management of cyber security, privacy and operational risk.As a Senior Purple Teamer, you will join the Purple Team which sits within the Red Team, and report to the Senior Manager of the Purple...
-
Cybersecurity Expert
1 week ago
Sydney, New South Wales, Australia beBeeoffense Full time $130,000 - $175,000Offensive Security SpecialistWe are seeking an experienced and skilled professional to join our cybersecurity team as an Offensive Security Specialist. The successful candidate will have a strong background in offensive security and be able to contribute to protecting our organization and its customers from cyber intrusions, theft, and loss.About the...
-
Senior Offensive Security Specialist
2 weeks ago
Sydney, New South Wales, Australia beBeeCyber Full time $175,000 - $225,000Offensive Security RoleWe are seeking an experienced and skilled professional to join our team in delivering high-impact offensive security engagements. As a key member of our Cybersecurity & Privacy team, you will play a crucial role in helping clients improve their cyber resilience by identifying vulnerabilities and developing strategies to mitigate...
-
Offensive Security Specialist
1 week ago
Sydney, New South Wales, Australia beBeeCybersecurity Full time $120,000 - $180,000Our organisation is building a secure digital society to protect the economy and businesses from cyber threats. We're seeking an experienced Red Teamer to join our Offensive Security capability. In this role, you'll deliver technical services including red teaming, purple teaming, and penetration testing for leading organisations.Key ResponsibilitiesDeliver...
-
Chief Offensive Security Strategist
1 week ago
Sydney, New South Wales, Australia beBeeCybersecurity Full time $150,000 - $200,000Red Team LeaderAre you a cybersecurity professional seeking to advance your career in offensive security? We are looking for an experienced Red Teamer to join our team.The role involves delivering technical red team (adversary simulation), purple team (attack replay) and penetration testing services to various organizations. You will be 'on the tools',...
-
Cyber Security Specialist
5 days ago
Sydney, New South Wales, Australia beBeeSecurity Full time $120,000 - $160,000Offensive Security ProfessionalAn exciting opportunity has arisen for an Offensive Security Professional to join our cyber security team.This role offers the chance to work on a variety of complex engagements in a challenging environment, building your skills alongside experienced security professionals and contributing to high-profile projects.Key...
-
Offensive Security Specialist
1 week ago
Sydney, New South Wales, Australia beBeeSecurity Full time $160,000 - $190,000Job Title: Security StrategistAbout the RoleWe are seeking a seasoned security professional to lead complex offensive security engagements and contribute to our security practices on a tactical and strategic level.Key Responsibilities:Design, scope, and execute penetration tests to identify vulnerabilities and provide actionable recommendations for...