Now hiring

Offensive Security Lead (Victoria, Australia) @ AusNet Electricity Services Pty Ltd

Victoria, AustraliaOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><img src="https://dmscdn.successfactors.com/6c21fc77f2bdc66db5fce613de25f9ea7e4f875d404d9776235066bce2edf396/static_content/8d1f5251dd6c4edfa30c/SuccessFactors_Landing_Page.jpg" alt="" width="" height=""></p><p style="margin:6.0pt 0.0cm;text-align:left;background-color:transparent;line-height:115%;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;line-height:115%;font-family:'Century Gothic', sans-serif">We bring the energy!</span></strong></p> <p style="margin:0.0cm;text-align:left;line-height:normal;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif"> </span></strong></p> <p style="margin:0.0cm;text-align:left;line-height:normal;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Through purpose and people - </span></strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">not just through the infrastructure we operate, but through the way we show up for each other, our customers’ and our communities. The future of energy is in our hands. Let’s shape it together.</span></p> <p style="margin:0.0cm;text-align:left;line-height:normal;background-color:transparent;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif;color:windowtext"> </span></strong></p> <p style="margin:0.0cm;text-align:left;line-height:normal;background-color:transparent;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif;color:windowtext">Are you ready to shape the future of energy?</span></strong></p> <p style="margin:0.0cm;line-height:normal;font-size:9.0pt;font-family:'Century Gothic', sans-serif">This is a great opportunity for someone who wants to work in critical infrastructure, leading a team of experts in implementing vital policies and establishing and leading AusNet’s Offensive Security capability.</p> <p style="margin:0.0cm;line-height:normal;font-size:9.0pt;font-family:'Century Gothic', sans-serif"> </p> <p style="margin:0.0cm;line-height:normal;font-size:9.0pt;font-family:'Century Gothic', sans-serif"><span style="color:black">We are looking for an<strong> Offensive Security Lead </strong>to ensure security controls are continuously assessed against current and emerging threats, driving risk informed remediation and improving the organisation’s cyber resilience through continuous security testing and secure development practices.</span></p> <p style="margin:0.0cm;line-height:normal;font-size:9.0pt;font-family:'Century Gothic', sans-serif"> </p> <p style="margin:6.0pt 0.0cm;font-size:9.0pt;font-family:'Century Gothic', sans-serif"><span style="color:black">The Offensive Security Lead is responsible for establishing and leading AusNet’s Offensive Security capability, providing strategic and technical leadership across penetration testing, red teaming, application security and exposure management to proactively identify, validate and reduce cyber security risk across IT and OT, cloud platforms and applications. </span></p> <p style="margin:0.0cm;line-height:normal;font-size:9.0pt;font-family:'Century Gothic', sans-serif"> </p> <p style="margin:0.0cm;line-height:normal;font-size:9.0pt;font-family:'Century Gothic', sans-serif"><span style="color:black">As the technical authority for Offensive Security, the role balances hands-on technical leadership with people leadership, vendor management and strategic planning to ensure security assurance activities deliver measurable reductions in organisational cyber risk.</span></p> <p style="margin:0.0cm;line-height:normal;font-size:9.0pt;font-family:'Century Gothic', sans-serif"> </p> <p style="margin:0.0cm;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">What you’ll be doing in this role:</span></strong></p> <p style="margin:0.0cm;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif"> </span></strong></p> <ul style="margin-bottom:0.0cm;margin-top:0.0px"> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Lead and oversee the organisation’s penetration testing, red teaming and adversary emulation program, validating the effectiveness of preventative, detective and responsive security controls across IT, OT, cloud and critical business applications. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Have accountability of day-to-day operational outcomes of the function, as well as developing and driving the strategic direction, aligning people and processes to achieve business and cyber department goals.</span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Own the Exposure Management capability, including vulnerability management, security validation and remediation governance, ensuring security risks are accurately prioritised, effectively communicated and remediated within agreed risk tolerances. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Lead the Application Security function by embedding security-by-design principles throughout the software development lifecycle, providing security guidance, code reviews, testing and developer enablement to reduce software security risk. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Develop and maintain an intelligence-led offensive security program, leveraging threat intelligence, adversary tradecraft and frameworks such as MITRE ATT&amp;CK to continuously evolve testing methodologies and emulate relevant threat actors. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Technical hands-on red teaming and penetration testing as required, complementing the work provided by our partners. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Establish and maintain a differentiated OT security testing methodology, ensuring all penetration testing, red teaming and adversary emulation activity against OT/ICS environments follows a safety-first, non-disruptive approach appropriate to live operational technology. This includes defining clear boundaries between passive and active testing techniques, determining where live-fire testing is and isn&apos;t permitted on production OT assets, and establishing mandatory coordination and sign-off with OT Engineering and Asset Management teams prior to any testing activity that could impact operational safety or grid reliability.</span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Partner with Cyber Defence, Network Security, OT Security, Enterprise Architecture, IAM, GRC and technology delivery teams to validate security controls, improve detection capabilities through purple team activities and strengthen the organisation’s overall cyber resilience. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Lead the management of third-party security service providers, including penetration testing, application security and vulnerability management partners, ensuring contractual obligations, service levels and quality standards are consistently achieved. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Liaise with external entities, such as cybersecurity advisory bodies, threat intelligence entities, law enforcement agencies, and external partners, to maintain a strong security posture and stay ahead of relevant security threats.</span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Provide authoritative technical advice and risk-based recommendations to senior leadership, supporting investment decisions, security architecture, technology initiatives and strategic cyber security programs. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Establish and evolve meaningful performance metrics, reporting and dashboards that measure offensive security effectiveness, exposure reduction and remediation performance, providing regular insights to management. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Support the development of the cyber security strategy, roadmap, budgetary and business cases.</span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Instil a high-performance, collaborative culture with a “one team” approach with multiple partners, providing leadership, guidance, and technical expertise, and a strong accountability and outcome focus to achieve business outcomes.</span></li> </ul> <p style="margin:0.0cm 0.0cm 0.0cm 36.0pt;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"> </p> <p style="margin:0.0cm;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"> </p> <p style="margin:0.0cm;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">You don’t need to check every box, however we’re looking for a good combination of:</span></strong></p> <p style="margin:0.0cm;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif"> </span></strong></p> <ul style="margin-top:6.0pt;margin-bottom:3.0pt"> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Extensive experience in cyber security including recent experience as a technical lead in Offensive Security, Penetration Testing, Application Security or Red Team within a large or complex environment. </span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Strong knowledge of offensive security methodologies, adversary emulation, penetration testing, app sec, vulnerability management and exposure management</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Demonstrated experience leading and developing high-performing technical teams, with 3-5 years of people leadership experience preferred. </span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Experience applying industry frameworks and standards including MITRE ATT&amp;CK, OWASP, NIST, Essential Eight or CIS Controls</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Experience managing third-party security service providers, commercial contracts and service delivery outcomes</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Strong analytical problem solving and decision-making skills, with the ability to balance cyber security risk, business priorities and operational requirements. </span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Relevant industry certification such as OSCP, OSCE, GPEN, GWAPT or equivalent for penetration testing and application security; CRTO, CRTP or OSEP for red teaming and adversary emulation; and GICSP or equivalent OT/ICS-specific security training (e.g. SANS ICS courses) given the role&apos;s scope across operational technology environments</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">A leadership-oriented certification such as CISSP or CISM is also highly regarded, reflecting the role&apos;s dual accountability for technical authority and people leadership. </span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Familiarity with or accreditation against CREST standards is advantageous, given the role&apos;s responsibility for quality-assuring third-party penetration testing and application security providers.</span></li> </ul> <p style="margin:6.0pt 0.0cm 3.0pt;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"> </p> <p style="margin:6.0pt 0.0cm 3.0pt;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">In this role you’ll need to demonstrate some key attributes:</span></strong></p> <ul style="margin-top:6.0pt;margin-bottom:3.0pt"> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Proven ability to influence senior stakeholders and communicate complex technical risks and recommendations to technical and executive audiences. </span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Critical thinker with a methodological approach to enterprise architecture.</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Results-oriented with a focus on achieving measurable business outcomes.</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Adaptable and resilient in a fast-paced, ever-changing digital landscape.</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Strong convictions balanced against the need to be a team player.</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Build and manage positives relationships with business units across the organisation and with our services and technology partners.</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Build and develop a high-performance team culture, aligned to the AusNet’s values, through effective leadership, support and feedback.</span></li> <li style="margin:6.0pt 0.0cm 3.0pt 0.0px;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Promote and foster collaborative team and stakeholder relationships based on mutual trust, integrity, accountability and inclusion.</span></li> </ul> <p style="margin:6.0pt 0.0cm 3.0pt;line-height:normal;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"> </p> <p style="margin:0.0cm;text-align:left;line-height:normal;background-color:transparent;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">The AusNet experience is all about… </span></strong></p> <ul style="margin-bottom:0.0cm;margin-top:0.0px"> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;text-align:left;line-height:normal;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Growing your impact</span></strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">: W</span><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">e’ll support you to build your career through real opportunities and strong connections.</span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;text-align:left;line-height:normal;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Solving some of the most complex energy challenges of our time</span></strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">: </span><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">We love unpacking complex challenges in clever ways and looking at things differently. </span></li> <li style="margin:0.0cm 0.0cm 0.0cm 0.0px;text-align:left;line-height:normal;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">Building an energy future to be proud of: </span></strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">We’re a trusted leader, with deep expertise, driven to do what’s right for our communities and customers.<strong> </strong></span></li> </ul> <p style="margin:0.0cm;text-align:left;line-height:normal;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif"> </span></strong></p> <p style="margin:0.0cm;text-align:left;line-height:normal;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">We’re committed to building an inclusive culture and a diverse workforce. We believe different perspectives are essential to our success, and we encourage all applicants to apply. If you need any adjustments during the recruitment process, we&apos;re happy to discuss how we can support you.</span></p> <p style="margin:0.0cm;text-align:left;line-height:normal;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"> </p> <p style="margin:0.0cm;line-height:13.0pt;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">At AusNet, we bring the energy! Ready to make your impact? Apply now!</span></strong></p> <p style="margin:0.0cm;line-height:13.0pt;text-align:justify;background-color:white;font-size:10.5pt;font-family:Calibri, sans-serif;color:black"><strong><em><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">We will not be engaging with Recruitment agencies for this role, so please appl</span></em></strong><strong><span style="font-size:9.0pt;font-family:'Century Gothic', sans-serif">y directly.</span></strong></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores