Mô Tả Công Việc
We are seeking motivated Lead Pen Tester (Group Security) to be part of a Big Rocket team that evaluates a wide range of NAB group products and services – to identify security weaknesses and exposures that pose a risk to the enterprise, and work with teams to understand their risk and path to remediation.
Your Job Responsibilities
Technical
- Work with project stakeholders to identify assets and define test scopes – evaluating the breadth and depth on which testing should take place based on varying factors;
- Execute penetration tests, either in a team or individually, to identify vulnerabilities and weaknesses that could impact bank systems;
- Including testing of web applications, mobile applications, web APIs, Infrastructure, Cloud technologies, and hardware.
- Triage vulnerabilities and justify risk in alignment with common vulnerability scoring systems, considering the environment and context;
- Report testing results to key project stakeholders in varying formats (i.e. traditional report, bug tickets), including verbal communication;
- Be involved with internal projects and initiatives to uplift team capabilities;
- Provide QA reviews for testing scopes and reports from your peers to ensure high quality and accuracy of testing;
- Work with larger technical programs across the bank to understand and construct testing requirements;
- Where required, work as an embedded penetration tester on large programs;
- Assist with other offensive security activities within the team (e.g. red team activity);
- Self-manage security testing projects from end-to-end;
- Participate in ‘run the business’ activities, such as maintenance and uplift of the penetration testing environment.
Leadership
- Maintains and increases motivation within team by regularly checking in on motivation levels, and making adjustments quickly where needed (e.g. QCI, team meeting, team engagement activity).
- Creates and maintains an equally safe environment for all members of team to ‘test and learn’, share learning, challenge thinking, team development and explore new ideas.
- Sets effective and meaningful goals and timelines for each team member that supports them to achieve beyond what is expected (e.g. align with Peak performance framework).
- Provides input to Engineering Manager in making decision of Prioritising and ensuring resources for the right work and making trade-offs between current and future performance to balance immediate goals with longer-term growth for the team.
- Supports the team to cut through complexity and create clarity by simplifying practices and processes.
- Be responsible for team engagement & relations.
Yêu Cầu Công Việc
Your Experience & Qualifications
Must-have
- 8+ years of experience in IT/Security industry, and at least 3 years as a penetration tester;
- Experience testing various technologies and platforms, including but not limited to; Web applications, web APIs, mobile applications (iOS, Android), network and server technologies, cloud services (AWS, Azure), and hardware;
- Experience writing and conveying complex security findings through reports;
- A comprehensive understanding of Penetration Testing frameworks and methodologies (OWASP, OSSTMM, WAHH);
- Methodical, analytical approach with outstanding attention to detail. The ability to construct and execute testing within a controlled environment that complies with methodologies, policies, and best practice;
- A clear understanding of both manual and automated penetration testing techniques, including knowledge of common penetration testing tools and the impacts they have on systems;
- A good understanding of risk mitigation strategies when working in highly sensitive environment;
- Proven ability to work both individually and within a team environment (at times with little guidance), build strong relationships and maintain rapport with internal NAB stakeholders and 3rd party service providers;
- Strong team working skills are essential;
- Excellent verbal and written communication skills;
- Ability to attend to the detail on multiple concurrent tasks while meeting various deadlines;
- Ability to work semi-autonomously and organise/prioritise own work schedule on a short-term basis;
- Proven ability to develop scripts and tools to enhance manual processes and existing tooling.
Nice to have:
- Experience working with large corporations.
- Training on self-development platforms (i.e. HackTheBox, Pentesterlabs, wechall, etc.);
- Participation in Bug Bounty programs;
- Undergraduate (minimum) in technical degree (Computer Science, Software Engineer, Cyber Security);
- Standard Industry certifications such as OSCP, CREST (CRT, CCT) or equivalent.
Hình thức
Quyền Lợi
THE BENEFITS AND PERKS
1. Generous compensation and benefit package
- Attractive salary and benefits
- 20-day annual leave and 7-day sick leave, etc.
- 13th month salary and Annual Performance Bonus
- Premium healthcare for yourself and family members
- Monthly allowance for team activities
- Premium welcome kit and frequent appreciation gifts
- Extra benefits for long-term employees
2. Exciting career and development opportunities
- Large scale products with modern technologies in banking domain
- Clear roadmap for career advancement in both technical and leadership pathways
- Well-structured learning and development programs (technical and soft skills)
- Sponsored certificates in both IT and banking/finance
- Premium accounts on Udemy/A Cloud Guru/Coursera/LinkedIn, etc.
- English learning with native teachers
- Opportunity for traveling & training in Australia
3. Professional and engaging working environment
- Hybrid working model and excellent work-life balance
- Well-equipped & modern Agile office with fully-stocked pantry
- Special programs to improve your physical and mental health
- Annual company trip and events
- A solid talented team behind you – great people who love what they do
CLOUD-FIRST
NAB is undergoing an exciting "Cloud First" technology transformation by taking advantage of the latest tools and techniques used by leading technology and digital companies globally. But it’s not just about the Tech, we are also investing heavily in our people, so if you have an appetite to learn, grow and elevate others around you, this is the place for you!
If this excites you, let's have a chat over a cup of coffee!