Manager Offensive Security

1 month ago


Melbourne, Australia Deloitte Full time

About the role

As part of the Deloitte Offensive Security team, you'll be responsible for defining, carrying out, and overseeing penetration testing projects to uncover security vulnerabilities in client's IT systems. You will be required to report on the identified vulnerabilities and provide recommendations for their remediation. Additionally, you will play a crucial role in the team, and other members will look to you as a subject matter expert for guidance and mentorship.

In this role you will respond to client requests, anticipating and meeting client problems and needs using innovative approaches when applicable. You will be involved in all aspects of security and vulnerability management engagements which include but are not limited to:

Network and host layer penetration tests and vulnerability assessments Firewall, networking, and security device reviews Web application assessments API assessments Mobile application assessments Red Teaming - targeting technical, physical and human layers of an organisation’s security controls. Source code reviews using manual and automated tools. Malware reverse engineering Wireless Assessments Closing meetings to present findings to the client. Detailed reporting and proposal writing

About the team
Positioned first globally in Security Consulting Services for the 6th year in a row. Yep, that’s Deloitte. The cyberspace is constantly evolving and so are the threats that it brings. That’s why our work is more meaningful (and exciting) than ever. Always one step ahead, we predict risks and safeguard our clients through end-to-end solutions. More importantly, we help clients unlock new opportunities through safer and more secure systems and policies.

Enough about us, let’s talk about you.
We are currently looking for experienced Penetration Testers at Senior Analyst, Manager and Senior Manager levels with the following experience and qualifications:
• Hold a current OSCP or CREST Certified Tester (CCT) in either Infrastructure or Web Applications or similar certification or be in a position and level to pass the exam for the certification
• For more senior roles, experience in Red Team engagements. With a capability in line with the CORIE framework or similar (e.g. CBEST, TIBER)
• Experience in working with applications that perform a wide range of business functions - ideally across multiple industries
• Ability to understand and assess applications from both a technical and business function perspective
• Good experience in performing web application penetration testing and development of supporting business and technical-level reporting
• Innovative and analytical in your approach to performing penetration testing, particularly of novel devices and environments
• Capable of working to strict deadlines and prioritising work appropriately
• The ability to develop scripts or code to automate testing and develop bespoke attacks
• Good communication skills with an ability to explain complex technical issues to non-technical business clients
• Excellent written skills with demonstrated ability to write reports and proposals. Including the ability to discuss findings from a risk perspective with clear remediation advice specific to the client’s environment.

Experience in one or more of the following:
• Reverse engineering
• Web Applications
• API’s and Microservices
• Exploit Development
• Application vulnerability assessment
• Mainframe systems
• Mobile platforms (iOS/Android/Windows/etc)
• Social Engineering
• Endpoint protection
• Practical exposure to security appliances such as firewalls, proxies, NIPS/HIPS and network security applications
• Working knowledge of web concepts such as Ajax, XML, SOAP, and WS-Security
• Familiarity with the Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP) and National Institute of Standards and Technology (NIST) Special Publications.
• Familiarity with penetration testing and vulnerability tools such as Cobalt Strike, Kali Linux, dsniff, nessus, nmap, MetaSploit, CoreImpact, Qualys, tcpdump, wireshark, Nikto, Aircrack-ng, Hailstorm, Burp Suite, etc.
• Strong programming experience with Visual Basic and C/C++ or Java languages
• Networking: LAN, WAN, interworking technologies
• Good understanding of IaaS environments like Azure, AWS and GCP



  • Melbourne, Australia Sekuro Full time

    **About us**: We are the challenger in the cybersecurity market both in Australia and Southeast Asia. We are founder-led and have a fresh and direct approach to working with our clients, breaking away from the older/traditional models, and are well respected for that. We’re on a mission to be the most trusted security partner. Through the delivery of...


  • Melbourne, Australia SOS Security Full time

    About Us :Social Outcomes Security (SOS) is Australia’s first social enterprise to operate within the security industry. We seek to provide ethical security services while creating pathways to employment for those from disadvantage, in particular people from refugee and migrant backgrounds. SOS offers people from diverse cultural backgrounds security guard...


  • Melbourne, Australia Challenger Security Full time

    **Join Our Team at Challenger Security: Where Safety Meets Luxury** **About Us**: At Challenger Security, we're more than just a security company - we're a team of dedicated individuals committed to safeguarding our clients across Australia. As an ISO accredited industry leader, we specialise in providing top-tier security services for high-end luxury...


  • Melbourne, Australia GSS security Full time

    As a Stage Barrier and Mosh Pit Security Guard, you will play a crucial role in ensuring the safety and security of music events in Melbourne CBD. Your duties will include monitoring the stage barrier and mosh pit area, managing crowd control, and responding to any incidents or emergencies that may arise. You will be working as part of a team of experienced...


  • Port Melbourne, Australia Brave Security Full time

    **Security Technician** We are a small business installing high end access control, CCTV, alarm and intercom systems servicing our customers all over Victoria and on occasion Australia. We seek a 'hands-on' energetic Security Service professional experienced with Security technologies. You will enjoy working in a team and alone. You will be responsible for...

  • Ethical Hacking

    4 weeks ago


    Melbourne, Australia Latitude IT Full time

    Brand new role on greenfield cyber transformation program - ASX50 company offering handsome remuneration & a learning & development - Hybrid or remote working possible, open to all Australia. **Ethical Hacking / Pentesting Lead** On behalf of our client, an iconic ASX50 company, we are seeking a seasoned Ethical Hacking / Pentesting Lead, the first of its...


  • Melbourne, Australia Advent Security Full time

    **About the Business** Advent Security Services operate on a national scale and offer our employees job security, opportunities for career progression and continual training and development. With a large client base, including retail, logistics and corporate sites, we can provide you with stability and variety in your role. **About the Role** We are...


  • Melbourne, Australia Amzn Commercial Srvcs Pty Ltd Full time

    a. Must fulfill Government background checks to qualify for an ASIC (Aviation Security Identification Card); b. Must be able to secure appropriate airport authority and/or Customs security badges, if applicable; c. Writes effective communications (e.g., Mission, Tenets, PR/FAQ, etc.), influence and negotiate priorities, determines where to simplify or extend...


  • Melbourne, Australia Interactive Pty Ltd Full time

    **LOCATION(S)** - Melbourne **POSITION** - Permanent - **DEPARTMENT** - Defence / Emergency / Security - At Interactive, we’re not just a tech company; we’re a dynamic force in the tech landscape, constantly growing and evolving. Our customers trust us to hold their most important data, support their critical devices, and secure their systems. **About...


  • Melbourne, Australia MyDeal.com.au Full time

    **Discover an online shopping experience like no other with MyDeal - the premier Australian retail marketplace that has been bringing shoppers the best deals, discounts and sales on home and lifestyle products since 2011.** **We pride ourselves on offering a curated selection of quality products from trusted retailers, so our customers can shop with...


  • Melbourne, Australia StraightUp Full time

    2IC to the Head of Cyber Security - Running Cyber Risk Resilience committee - 3 days a week in the office - 2 days WFH This is a newly created Cyber Security Manager position within an established Aussie financial services company who have recently begun a significant Security uplift program. As the 2IC to the Head of Cyber Security, you will develop and...


  • Melbourne, Australia Technology People Australia Full time

    A Victorian not for profit organisation in the healthcare space has a newly created role for an Information Security Manager to take ownership of their Cyber GRC program.  Reporting directly to the CISO this (second in command) role will see you creating an information security GRC program to safeguard the assets of this healthcare business.   This role is...


  • Melbourne, Australia Insignia Financial Full time

    Security Operations Manager - Growing organisation where you can make a significant impact on the Cybersecurity landscape - Benefit from exceptional support and leadership in your role Seize the opportunity to enter the Financial Services industry, with a leading organisation that is dedicated to enhancing Australians' financial well-being through...


  • Melbourne, Australia Insignia Financial Full time

    Growing organisation where you can make a significant impact on the Cybersecurity landscape - Benefit from exceptional support and leadership in your role Seize the opportunity to enter the Financial Services industry, with a leading organisation that is dedicated to enhancing Australians' financial well-being through superannuation, investments, and...


  • Melbourne, Australia Swinburne University of Technology Full time

    As the Security and Services Manager, you will be responsible for providing customer focused, cost-effective security, parking, fleet, and mail centre services including leading and overseeing the day-to-day management of the large-scale security services contract and other services within Facility Management relating to parking, fleet, and the mail...


  • Melbourne, Australia Crown Melbourne Full time

    **Job Number**: MEL14192) **Security Services Manager** CROWN MELBOURNE | FULL TIME At Crown Resorts, our purpose is simple. Together, we create exceptional experiences with respect and care for our communities. Our employees embrace our company values through our behaviours. We act with integrity, we care, we strive for excellence and we work together. We...


  • Melbourne, Australia Open Door Recruitment & Development Full time

    **Open Door is dedicated to helping organisations achieve gender balance within their leadership teams.** We are working with a well reputed energy and utilities brand who utilise cutting edge technology and innovation of their products and services to create sustainable impacts on individuals, communities and businesses across Australia. The **Incident...


  • Melbourne, Australia Corporate Security Full time

    Job Title: Morning Concierge Security Location: Melbourne CBD **Job Type**: Permanent Hours - Monday - Friday (Mornings only) Shift Timings: Every Week Monday - Friday (0700 hrs - 1500 hrs) **Salary**: Competitive hourly rate based on experience **Job Description**: Key Responsibilities: - Maintain a friendly presence at the front desk - Monitor and...


  • Melbourne, Australia Australian Bureau of Meteorology Full time

    Executive Level 2 Lower, Ongoing - $125,428 - $140,871 + 15.4% super - Melbourne An experienced and suitably qualified ICT infrastructure security team lead is sought with a track record of managing and coaching staff and expertise relevant to Cyber Security. The lead will work with the Infrastructure Services Manager to realise this capability by building...


  • Melbourne, Australia Suburban Rail Loop Authority Full time

    Location: Melbourne | CBD Job type: Full time Organisation: Suburban Rail Loop Authority **Salary**: $175,731 - $238,997 Occupation: Technology Reference: 1674 **About the opportunity** The Cyber Security Manager will be responsible for providing cyber security leadership and guidance across the organisation working closely with IT Services,...