Offensive Security Engineer
Core
Identify exploitable weaknesses, validate security controls, and support safer delivery across the technology environment by embedding security early in the SDLC.
Role type
Senior IC offensive security engineer (penetration testing & automation)
Builds
Secure software delivery, resilient cloud environments, and validated security controls for an Australian member-owned services group
Domain
Cybersecurity, application security, cloud security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, SAST/DAST/CSPM tooling, CI/CD integration, threat modeling, vulnerability lifecycle management, cloud security posture management, adversary emulation, Python/PowerShell scripting, OWASP Top 10, PCI DSS, MITRE ATT&CK
Preferred skills
DevSecOps practices, secure AI development, automation of security testing and remediation tracking
Technologies
SAST, DAST, CSPM, CI/CD pipelines, Python, PowerShell, OWASP Top 10, PCI DSS, MITRE ATT&CK, ISO 27001, NIST
Responsibilities
Plan and perform authorized security testing across web apps, APIs, infrastructure, and cloud; Operate and optimize security testing platforms; Embed security testing in SDLC and CI/CD pipelines; Conduct penetration testing, threat modeling, and control validation; Validate, triage, and document security findings; Automate discovery, testing, and remediation tracking; Produce evidence-based reports for governance and audit.
Seniority
Mid-to-Senior, hands-on IC
