Offensive Security Engineer
Sydney Olympic Park - Australia
Job Summary
We have an exciting opportunity for an Offensive Security Engineer to join our Technology team based in Sydney Olympic Park. This role plays an important part in protecting the confidentiality integrity availability and resilience of NRMA technology and data by identifying exploitable weaknesses before they cause harm validating the effectiveness of security controls and supporting safer delivery across our technology environment.
Reporting to the Senior Manager Security Compliance & Governance youll work closely with engineering cloud platform infrastructure architecture and security teams to embed security early in the software development lifecycle reduce vulnerabilities reaching production and provide evidence-based assurance across applications APIs cloud environments and security controls.
This is a hands-on role for someone who enjoys practical security testing automation threat emulation vulnerability lifecycle management and working with technical teams to improve security outcomes in a complex enterprise environment.
This 9-12 month maximum term contract role offers a hybrid work arrangement across our Sydney Olympic Park Sydney CBD offices and working from home as agreed and required for the role.
What Youll Do
- Plan and perform authorised risk-based security testing across web applications APIs infrastructure networks identity services and cloud-hosted workloads.
- Operate administer and optimise security testing platforms including SAST DAST CSPM and attack simulation tooling.
- Embed security testing early in the software development lifecycle and support secure development practices across engineering teams.
- Integrate application security dependency open-source risk DAST and API security testing controls into code repositories IDEs and CI/CD pipelines.
- Conduct authorised penetration testing technical security assessments security design reviews and threat modelling for material changes.
- Validate triage and document security findings including severity business impact accountable owners target remediation dates and closure evidence.
- Track remediation progress retest resolved vulnerabilities and escalate overdue or material findings where required.
- Use cloud security posture management tooling to assess cloud vulnerabilities misconfigurations attack paths and compliance posture.
- Conduct MITRE ATT&CK-aligned control validation adversary emulation and purple team activities across key security controls.
- Provide practical remediation advice to engineering and technology teams including guidance aligned to OWASP Top 10 PCI DSS secure coding requirements and secure AI development practices.
- Automate repeatable discovery testing ticketing evidence collection reporting remediation tracking and validation activities where practical.
- Produce evidence-based reports service metrics and control-effectiveness insights to support operational executive audit and governance reporting.
What Youll Bring
- Experience in cybersecurity application security penetration testing security engineering or DevSecOps.
- Strong knowledge of web application API and cloud security.
- Hands-on experience with security testing tools such as SAST DAST and CSPM platforms.
- Understanding of secure software development and CI/CD environments.
- Experience identifying validating and remediating security vulnerabilities.
- Knowledge of security frameworks including OWASP Top 10 MITRE ATT&CK ISO 27001 NIST and PCI DSS.
- Ability to automate tasks using scripting languages such as Python or PowerShell.
- Strong analytical and problem-solving capabilities.
- Excellent stakeholder engagement and communication skills.
- Ability to provide practical risk-based security advice to technical and business teams.
- Relevant cybersecurity qualifications certifications or equivalent industry experience.
- A passion for emerging security technologies automation and continuous improvement.
Whats in it for you
At the NRMA we arent just about discounts (although you do get these too). We offer benefits to help make work and life just right for you!
- Progressive flexibility leave and well-being benefits to balance all of lifes priorities
- Travel discounts on SIXT car rental cruises and accommodation at our award-winning NRMA Holiday Parks and Resorts
- Complimentary myNRMA Rewards membership including free Roadside Assistance & discounts on groceries movie tickets gift cards gym memberships attractions restaurants and much more
- Discounts on a range of NRMA personal insurance products including car home & travel
- Grow progress or relocate your career and move around the NRMA Group or different locations with us.
Know you belong
Were for inclusion diversity and representing the members guests customers and communities we serve. Thats why we welcome applications from First Nations people with disability those from diverse cultural backgrounds people of all genders members of the LGBTQI community and anyone else who wants to be a part of our team.
Join the NRMA and grow your career with us. Apply now we cannot wait to hear from you or visit our careers site to find out more!
Our Talent Acquisition Team and Hiring Leaders kindly request no unsolicited resumes or approaches from Recruitment Agencies. The NRMA is not responsible for any fees related to unsolicited resumes.
Remote Work :
No
Employment Type :
Full-time
About Company
With properties in some of Australia’s most iconic locations, NRMA Parks & Resorts provide accommodation that suits every budget and style – from campsites to luxury resorts. We connect holidaymakers with over 50 incredible natural destinations that offer more than a change of scenery ... View more