Senior Security Consultant
Position Summary
The Penetration Tester is responsible for carrying out penetration testing, vulnerability assessment activities, and any other security activities with oversight/support from a more senior team member and providing security expertise to CyberCX clients.
Key Responsibilities
- Deliver application, network, systems, and infrastructure penetration tests for customers, using creative and outside the box solutioning to explore unconventional attack paths.
- Able to perform the top five and emerging STA services offered by the Practice to a high standard with adequate supervision.
- Prepare high-quality reports detailing security issues, make recommendations, and identify solutions, contribute to presentations and discussions with customers around testing performed, key results, recommendations, and the next steps.
- Build and promote strong, long-lasting relationships with a diverse range of customers, and identify and explore opportunities within existing and new customers.
- Contribute to a culture of empowerment, collaboration, and accountability through consistent employee engagement.
- Assist with R&D, innovation, and practice improvement activities, under supervision.
- Stay current with emerging threats, tools, and techniques in the cybersecurity landscape.
- Maintain utilization targets and ensure on-budget delivery.
- Travel: Up to 10%
Preferred Qualifications, Experience & Skills
- Proficiency in penetration testing tools such as Metasploit, Burp Suite, Nmap, and custom scripting in Python, Bash, or JavaScript.
- Penetration testing certifications such as OSCP preferred but not essential.
- A minimum of 2 years as a security testing practitioner / cyber practitioner in which you have developed capability in managing client expectations, time management, technical delivery and report writing.
- Excellent written and verbal communication skills with the ability to explain technical findings to both technical and non-technical stakeholders.
- Strong knowledge of networking, operating systems (Linux, Windows, Active Directory), and web application security.
- Tertiary qualification in information systems, software development or a similar field, or equivalent industry experience.
About CyberCX
CyberCX is the leading provider of professional cyber security and cloud services across Australia and New Zealand. We are a trusted partner to private and public sector organisations helping our customers confidently manage cyber risk, respond to incidents and build resilience in an increasingly complex and challenging threat environment. Through our end-to-end range of cyber and cloud capabilities, CyberCX empowers our customers to securely accelerate opportunities in the digital economy. Our services include: consulting and advisory, governance, risk and compliance, incident response, penetration testing and assurance, network and infrastructure solutions, cloud security and solutions, identity and access management, managed security services and cyber security training.