Manager Offensive Security

1 week ago


Melbourne, Australia Deloitte Full time

Job Requisition ID: 34883 

About the role

As part of the Deloitte Offensive Security team, you'll be responsible for defining, carrying out, and overseeing penetration testing projects to uncover security vulnerabilities in client's IT systems. You will be required to report on the identified vulnerabilities and provide recommendations for their remediation. Additionally, you will play a crucial role in the team, and other members will look to you as a subject matter expert for guidance and mentorship.

In this role you will respond to client requests, anticipating and meeting client problems and needs using innovative approaches when applicable. You will be involved in all aspects of security and vulnerability management engagements which include but are not limited to:

  • Network and host layer penetration tests and vulnerability assessments
  • Firewall, networking, and security device reviews
  • Web application assessments
  • API assessments
  • Mobile application assessments
  • Red Teaming - targeting technical, physical and human layers of an organisation’s security controls.
  • Source code reviews using manual and automated tools.
  • Malware reverse engineering
  • Wireless Assessments
  • Closing meetings to present findings to the client.
  • Detailed reporting and proposal writing

About the team
Positioned first globally in Security Consulting Services for the 6th year in a row. Yep, that’s Deloitte. The cyberspace is constantly evolving and so are the threats that it brings. That’s why our work is more meaningful (and exciting) than ever. Always one step ahead, we predict risks and safeguard our clients through end-to-end solutions. More importantly, we help clients unlock new opportunities through safer and more secure systems and policies.

Enough about us, let’s talk about you.
We are currently looking for experienced Penetration Testers at Senior Analyst, Manager and Senior Manager levels with the following experience and qualifications:
•    Hold a current OSCP or CREST Certified Tester (CCT) in either Infrastructure or Web Applications or similar certification or be in a position and level to pass the exam for the certification
•    For more senior roles, experience in Red Team engagements. With a capability in line with the CORIE framework or similar (e.g. CBEST, TIBER)
•    Experience in working with applications that perform a wide range of business functions - ideally across multiple industries
•    Ability to understand and assess applications from both a technical and business function perspective
•    Good experience in performing web application penetration testing and development of supporting business and technical-level reporting
•    Innovative and analytical in your approach to performing penetration testing, particularly of novel devices and environments
•    Capable of working to strict deadlines and prioritising work appropriately
•    The ability to develop scripts or code to automate testing and develop bespoke attacks
•    Good communication skills with an ability to explain complex technical issues to non-technical business clients
•    Excellent written skills with demonstrated ability to write reports and proposals. Including the ability to discuss findings from a risk perspective with clear remediation advice specific to the client’s environment.

Experience in one or more of the following:
•    Reverse engineering
•    Web Applications
•    API’s and Microservices
•    Exploit Development
•    Application vulnerability assessment
•    Mainframe systems
•    Mobile platforms (iOS/Android/Windows/etc)
•    Social Engineering
•    Endpoint protection
•    Practical exposure to security appliances such as firewalls, proxies, NIPS/HIPS and network security applications
•    Working knowledge of web concepts such as Ajax, XML, SOAP, and WS-Security
•    Familiarity with the Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP) and National Institute of Standards and Technology (NIST) Special Publications.
•    Familiarity with penetration testing and vulnerability tools such as Cobalt Strike, Kali Linux, dsniff, nessus, nmap, MetaSploit, CoreImpact, Qualys, tcpdump, wireshark, Nikto, Aircrack-ng, Hailstorm, Burp Suite, etc.
•    Strong programming experience with Visual Basic and C/C++ or Java languages
•    Networking: LAN, WAN, interworking technologies
•    Good understanding of IaaS environments like Azure, AWS and GCP

Why Deloitte?
 

At Deloitte, we focus our energy on interesting and impactful work. We’re always learning, innovating and setting the standard; making a positive difference to our clients and our society. We put coaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.  

We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone’s perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong. 

We prioritise flexibility and choice. At Deloitte, you get trust on Day 1. We know our people get their best work done when they’re in control of where and how they work, designing their work week around their client, team and personal commitments.

We help you live and work well. To support your personal and professional life, we offer a range of perks and benefits, including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package. 

Next Steps
Sound like the sort of role for you? Apply now.

By applying for this job, you’ll be assessed against the Deloitte Talent Standards. We’ve designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.



  • Melbourne, Australia Naviro Pty Ltd Full time

    Join a growing cyber security organisation - Improve on your penetration testing capabilities - Work on technical security projects across various industries! Sekuro Operations is hiring for the position of Offensive Security Analyst (also termed OffSec Analyst) in Melbourne. There are multiple positions available. The role is suited for experienced cyber...


  • Melbourne, Australia Deloitte Full time

    Job Requisition ID:  34883  About the role As part of the Deloitte Offensive Security team, you'll be responsible for defining, carrying out, and overseeing penetration testing projects to uncover security vulnerabilities in client's IT systems. You will be required to report on the identified vulnerabilities and provide recommendations for their...


  • Melbourne, Australia Deloitte Full time

    Job Requisition ID:  34883  About the role As part of the Deloitte Offensive Security team, you'll be responsible for defining, carrying out, and overseeing penetration testing projects to uncover security vulnerabilities in client's IT systems. You will be required to report on the identified vulnerabilities and provide recommendations for their...


  • Melbourne, Australia TESSERENT Full time

    Company Overview- Tesserent is an extraordinary home-grown cybersecurity success story. Founded in Melbourne, originally focusing on Managed Security Services and funded entirely by local investors, we have since grown to become one of Australia’s largest cybersecurity providers. Now with offices across Australia and New Zealand, we partner with clients to...


  • Melbourne, Australia Sekuro Full time

    **About us**: We are the challenger in the cybersecurity market both in Australia and Southeast Asia. We are founder-led and have a fresh and direct approach to working with our clients, breaking away from the older/traditional models, and are well respected for that. We’re on a mission to be the most trusted security partner. Through the delivery of...


  • Melbourne, Australia Naviro Pty Ltd Full time

    Remote role in Australia! - Join a fun team of red teamers - Get involved in the cyber security community **About us** We are the challenger in the cybersecurity market both in Australia and Southeast Asia. We are founder-led and have a fresh and direct approach to working with our clients. Over our journey we have helped many organisations of different...


  • Melbourne, Australia Caleb and Brown Pty Ltd Full time

    Caleb & Brown is the world’s leading cryptocurrency brokerage, providing a professional service by which our clients can safely buy, sell and swap cryptocurrencies through their very own personal broker. Founded by a small team of crypto experts in 2016, we have grown to a team of 55 staff with offices in Australia and Europe, serving 20,000 clients across...

  • Security Officer

    2 weeks ago


    Melbourne, Australia Guard1 Security Full time

    Guard1 Security is currently seeking Security Officers in the Melbourne region to fill various positions. Applicants must be professional, well presented, excellent verbal and written communication skills, customer focused and a team player. Applicants must be available to work on rotating hours including weekends, night shift and public holidays. Minimum...

  • Security Officer

    2 months ago


    Melbourne, Australia Guard1 Security Full time

    Guard1 Security is currently seeking Security Officers in the Melbourne region to fill various positions. Applicants must be professional, well presented, excellent verbal and written communication skills, customer focused and a team player. Applicants must be available to work on rotating hours including weekends, night shift and public holidays. Minimum...


  • Melbourne, Australia Certis Security Full time

    **About Certis Security Australia** **About the Opportunity** To provide asset protection and ensure all stakeholders attending any Scentre Group sites are within a safe and incidentfree environment. Complying with site relevant rosters. Conduct routine vehicle and foot patrols of client premises. Respond to and attend sites for the purpose of...


  • Melbourne, Australia Wilson Security Full time

    Monday - Friday 10.00am - 6.00pm - CBD Based - Must have control room experience! Wilson Security is the leading provider in the provision of security services across Australia and New Zealand. Our services are supported by a highly experienced management team, industry-leading expertise and a strong local and national structure. We are committed to...

  • Security Guard

    1 month ago


    Melbourne, Australia All Time Security Full time

    **Job Title: Luxury Brand Store Security Guard with Customer Service Skills** **Location**: Collins Street, Melbourne We are seeking a highly motivated and professional male Security Guard with exceptional customer service skills to join our team at a prestigious luxury brand store on Collins Street, Melbourne. **Key Responsibilities**: - Greet customers...


  • Melbourne, Australia SOS Security Full time

    About Us :Social Outcomes Security (SOS) is Australia’s first social enterprise to operate within the security industry. We seek to provide ethical security services while creating pathways to employment for those from disadvantage, in particular people from refugee and migrant backgrounds. SOS offers people from diverse cultural backgrounds security guard...


  • Melbourne, Australia SOS Security Full time

    About Us :Social Outcomes Security (SOS) is Australia’s first social enterprise to operate within the security industry. We seek to provide ethical security services while creating pathways to employment for those from disadvantage, in particular people from refugee and migrant backgrounds. SOS offers people from diverse cultural backgrounds security guard...

  • Security Guard

    2 weeks ago


    Melbourne, Australia Security Management Full time

    Job Title: Day-time Security Guard Location: Echuca **Job Type**: Casual - Permanent Hours Shift Timings: Monday - Friday (0830 hrs - 1700 hrs) **Salary**: Competitive hourly rate based on experience **Job Description**: Key Responsibilities: - Patrol and monitor the premises to prevent theft or other safety threats - Monitor and control access to the...


  • Melbourne, Australia Wilson Security Full time

    Corporate Guards wanted across well-reputable CBD sites - 24-7 flexibility is essential - Attractive pay rates Wilson Security is the leading provider in the provision of security services across Australia and New Zealand. Our services are supported by a highly experienced management team, industry-leading expertise and a strong local and national...

  • Ethical Hacking

    5 days ago


    Melbourne, Australia Latitude IT Full time

    Brand new role on greenfield cyber transformation program - ASX50 company offering handsome remuneration & a learning & development - Hybrid or remote working possible, open to all Australia. **Ethical Hacking / Pentesting Lead** On behalf of our client, an iconic ASX50 company, we are seeking a seasoned Ethical Hacking / Pentesting Lead, the first of its...


  • Melbourne, Australia Wilson Security Full time

    Tullamarine Airport - Rotating 24-7 rosters - MUST HAVE 24-7 AVAILABILITY!! - Fulltime positions available Wilson Security is the leading provider in the provision of security services across Australia and New Zealand. Our services are supported by a highly experienced management team, industry-leading expertise and a strong local and national structure. We...


  • Melbourne, Australia Wilson Security Full time

    Tullamarine Airport - Rotating 24-7 rosters - MUST HAVE 24-7 AVAILABILITY!! - Fulltime positions available - Level 1 roles Wilson Security is the leading provider in the provision of security services across Australia and New Zealand. Our services are supported by a highly experienced management team, industry-leading expertise and a strong local and...


  • Melbourne, Australia Challenger Security Full time

    **Join Our Team at Challenger Security: Where Safety Meets Luxury** **About Us**: At Challenger Security, we're more than just a security company - we're a team of dedicated individuals committed to safeguarding our clients across Australia. As an ISO accredited industry leader, we specialise in providing top-tier security services for high-end luxury...