Application Security Lead

Found in: Talent AU C2 - 3 weeks ago


Sydney, Australia UNSW Australia Full time

Why Your Role Matters

:
The Application Security Lead will play a crucial role in strengthening the organisation’s security position by leading secure development lifecycle practice (SDLC). This role will collaborate closely with the Cyber Security team and use expertise to develop and drive practices that embed secure-by-design across the full technology stack for applications. This role leads application security compliance across the Student, Academic and Research domain.

The Application Security Lead role will lead the organisation with strong development processes and work with various teams and stakeholders to provide consultation and guidance across the business. This includes promoting awareness of the University’s internal and external environment for emerging cyber security threats and supporting the independent audits of cyber security controls.

This role reports into the Technology Manager and has no direct reports.

Responsibilities:

Lead the development and implementation of application security best practice processes that ensure security throughout the application lifecycle. Provide expert guidance and leadership on secure development practices and technologies to IT teams and stakeholders across UNSW to embed security practices. Collaborate with the Cyber Security team to establish and advance sustainable secure coding processes, platforms, tools, monitoring, and automation including hands-on set-up and management of application security tooling. Lead a capability uplift and embed a culture of security across application teams through the development of standards, guidelines and identifying team needs and opportunities. Develop and deliver application development training with respect to security and guide the team autonomously on department strategy and approach.

Skills and Experience Summary:

Preferably 10+ years work experience in software engineering or related roles, at least 2 of which within a similar role focused on application security. In-depth understanding of the most common application security risks and demonstrated experience in secure development practices required to mitigate those risks (e.g., OWASP Top 10). Hands-on experience in designing, implementing, and managing secure software delivery pipelines by integrating application security tooling (such as SAST, DAST and dependency vulnerability management) into CI/CD pipelines. Understanding of architecture and security concerns specific to web technologies and frameworks (e.g., secure password storage, encryption, security headers, content security policy, CSRF, OIDC, oAuth2, hash algorithms, one-time codes, password reset, rate limiting, security logging, etc), API security and identity and authorisation standards. AWS (preferable) or Azure security knowledge and experience Strong problem-solving and analytical skills, with the ability to translate data into valuable information for management. Strong cyber security GRC fundamentals and knowledge of cyber security principles and practices. Excellent understanding of industry-wide security standards and compliance frameworks such as ISO 27001, NIST 800-53, CSA, Essential 8, PCI DSS, COBIT 5, Mitre ATT&CK etc. Relevant industry certification(s) such as SANS certifications, CEH, OSCP, CompTIA Security+, and cloud platform certifications such as AWS Security Speciality, Microsoft Azure (highly desirable). Excellent communication and interpersonal skills, with the ability to effectively convey complex security concepts to technical and non-technical stakeholders

Benefits and Culture:  People are at the core of everything we do. We recognise it is the contributions of our staff who make UNSW one of the best universities in Australia and the world. Our benefits include: 

Career development opportunities  17% Superannuation contributions and additional leave loading payments  Additional 3 days of leave over Christmas period  Discounts and entitlements (retail, education, fitness)

Get in Touch:  For queries regarding the recruitment process contact Lucy Gerondis, Talent Acquisition Consultant, UNSW

E: (Applications sent via email will not be accepted, please apply online via the portal)

UNSW is committed to evolving a culture that embraces equity and supports a diverse and inclusive community where everyone can participate fairly, in a safe and respectful environment. We welcome candidates from all backgrounds and encourage applications from people of diverse gender, sexual orientation, cultural and linguistic backgrounds, Aboriginal and Torres Strait Islander background, people with disability and those with caring and family responsibilities. UNSW provides workplace adjustments for people with disability, and access to flexible work options for eligible staff.

The University reserves the right not to proceed with any appointment.

Advertised: 18 Apr 2024 AUS Eastern Standard Time
Applications close: 02 May 2024 AUS Eastern Standard Time

  • Sydney, Australia Security Centric Full time

    **Location**: Sydney **Division**: Service Delivery - Advise and shape client cyber security journeys - Reporting to a Managing Director that wants to hear and support your ideas Lead a skilled team delivering services and solutions across projects and long-term managed services clients. About us Not all cybersecurity consultancies are alike. At Security...


  • Sydney, Australia The Argyle Network Full time

    Competitive Contract Day Rate - Agile Environment - Hybrid Work The Argyle Network is currently looking for a DevSecOps / Application Security/ AppSec Lead to manage a small AppSec team in Sydney within one of Australia’s major financial institutions. 12 month daily rate contract. **Responsibilities** - Lead a small team of Application Security...


  • Sydney, Australia HUB24 & Class Limited Full time

    HUB24 leads the wealth industry as the best provider of integrated platform, technology and data solutions. At HUB24, we know the smartest investments start with our people. We are innovative and ambitious, and we move fast. At HUB24, we empower our employees to bring their ideas and creativity to work. Rather than getting bogged down in bureaucracy and red...


  • Sydney, Australia Challenger Security Full time

    **Join Our Team at Challenger Security: Where Safety Meets Luxury** **About Us**: At Challenger Security, our impeccable Australia wide client list and teams of dedicated highly skilled professionals ensures we are the standout company in the industry. We are an ISO accredited industry leader specialising in providing top-tier security services for high-end...


  • Sydney, Australia Challenger Security Full time

    **Join Our Team at Challenger Security: Where Safety Meets Luxury** **About Us**: At Challenger Security, our impeccable Australia wide client list and teams of dedicated highly skilled professionals ensures we are the standout company in the industry. We are an ISO accredited industry leader specialising in providing top-tier security services for high-end...

  • Application Security Specialist

    Found in: Talent AU C2 - 2 weeks ago


    Sydney, Australia West Recruitment Full time

    - Work with exciting technology- Excellent office location- Above market salaryThe CompanyWest Technology are partnered with a well-established Cyber Security Consultancy based in North Sydney. Our client works with some of the most well-known brands in the market which will give you an opportunity to further grow your skills as an Application Security...


  • Sydney, Australia E Group Security Full time

    **The company** EGroup is a National Australian Owned company with over 18 years' experience in tailoring and delivering high quality security solutions to many private, corporate, retail and government organisations. By being part of the Egroup experience, you will be supported by a team that are passionate and dedicated and who care about YOU. **The...

  • Team Lead/manager

    4 days ago


    Sydney, Australia TikTok Full time

    Responsibilities About TikTok TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo. Why Join Us Creation is the core of TikTok's purpose. Our platform is built to help...


  • Sydney, Australia Golden Eagle Security Full time

    CASUAL / PART-TIME / FULL-TIME SECURITY GUARDS WANTED!!! GOLDEN EAGLE SECURITY is a recognized driving force behind the various industries in Australia. GOLDEN EAGLE SECURITY is seeking qualified Security Guards to join our team on a casual, part-time, or full-time basis. Security Applicants must have: + Current Valid Security Licence + Current First Aid...


  • Sydney, Australia Security Careers at Mantel Group Full time

    **About us** Mantel Group is an Australian-owned technology consulting business with capabilities across Cloud, Digital, Data & Security. Since our inception in November 2017, we have experienced remarkable growth across Australia & New Zealand and are honoured to be recognised as a Great Place to Work for 4 years in a row! We hire smart and talented...

  • Cyber Security Lead

    4 days ago


    Sydney, Australia Protecht Group Full time

    Protecht is redefining the way the world thinks about risk. Our cloud-based SaaS platform - Protecht.ERM - is what makes us really stand out. It’s one of the most comprehensive, flexible and dynamic risk management solutions available today. **Join us at Protecht!** We are seeking an exceptional Cyber Security professional with a commercial focus with...


  • Sydney, Australia Latitude IT Full time

    Full-time strategic position within the organisation - Be the voice and driver for the organisation's SaaS Applications portfolio stack - Genuine work from home flexibility on offer We have an outstanding opportunity available for an **Key responsibilities include**: - Lead the ongoing delivery of the Application portfolio and SaaS based products of the...

  • Technical Program Manager

    Found in: Talent AU C2 - 3 weeks ago


    Sydney, Australia Microsoft Full time

    OverviewAzure Networking operates one of the largest networks in the world! Our Application Delivery product suite comprises of Azure Content Delivery Network (CDN), Azure Front Door, Azure Application Gateway and Azure Web Application Firewall (WAF) products, focused on solving performance, reliability and scale needs for the largest internal Microsoft...

  • Lead Information Security Analyst

    Found in: Talent AU C2 - 3 weeks ago


    Sydney, Australia Appian Corporation Full time

    Description Here at Appian, our core values of Respect, Work to Impact, Ambition, and Constructive Dissent & Resolution define who we are. In short, this means we constantly seek to understand the best for our customers, we go beyond completion in our work, we strive for excellence with intensity, and we embrace candid communication. These values...

  • Lead Information Security Advisor

    Found in: Talent AU C2 - 2 days ago


    Sydney, Australia Appian Corporation Full time

    Description Here at Appian, our core values of Respect, Work to Impact, Ambition, and Constructive Dissent & Resolution define who we are. In short, this means we constantly seek to understand the best for our customers, we go beyond completion in our work, we strive for excellence with intensity, and we embrace candid communication. These values...

  • Lead Networks

    7 days ago


    Sydney, Australia Continuum Recruitment Full time

    **Network & Security Lead** - **Perm Role**: - **North Sydney based.**: - **Manage a global communication network**: - **Hybrid working model.** **About the Company** *** My client is a globally recognised workforce who is committed to creating a rewarding, inclusive workplace and who actively encourages personal/ professional development, fostering...


  • Sydney, Australia Challenger Security Full time

    **Join Our Team at Challenger Security!** Challenger Security stands as an industry leader in security services across Australia, holding ISO accreditation and specialising in high-end luxury retail, commercial, education, tech, and government sectors. Our brand is built on a deep understanding of our clients' needs, providing top-tier protection and...

  • SAP Basis/Security

    Found in: Talent AU C2 - 3 weeks ago


    Sydney, Australia IAG Full time

    Have meaningful impact as an SAP Basis/Security - Lead Join the largest insurance group in Australia and New Zealand, we’re here for you. Are you ready? YOUR ROLE We are looking for an outstanding SAP Basis/Security – Lead to manage SAP environments providing technical support and expertise to the SAP Basis team and systems. You will be...


  • Sydney, Australia Microsoft Full time

    OverviewAzure Networking operates one of the largest networks in the world! Our Application Delivery product suite comprises of Azure Content Delivery Network (CDN), Azure Front Door, Azure Application Gateway and Azure Web Application Firewall (WAF) products, focused on solving performance, reliability and scale needs for the largest internal Microsoft...


  • Sydney, Australia Bluefin Resources Full time

    Newly created role - flexible work arrangements - people leader role A leading insurance company in Sydney is seeking an Information Security Lead to join their team on a permanent basis. This is a newly created role. The primary purpose of this role is oversight of the related ISMS activities, risk identification and assessment, prevention and advice to...