Offensive Security Engineer at My NRMA | AU | Rezi

Offensive Security Engineer at My NRMA

Offensive Security Engineer

My NRMA · AU

1 weeks ago

Offensive Security Engineer

My NRMA · AU

11 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

This role plays an important part in protecting the confidentiality, integrity, availability, and resilience of NRMA technology and data by identifying exploitable weaknesses, validating security controls, and supporting safer delivery across the technology environment. You will work closely with various teams to embed security early in the software development lifecycle, reduce vulnerabilities, and provide assurance across applications, APIs, cloud environments, and security controls. This is a hands-on role for someone who enjoys practical security testing, automation, threat emulation, and vulnerability lifecycle management.

Responsibilities

  • Plan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services, and cloud-hosted workloads.
  • Operate, administer, and optimise security testing platforms, including SAST, DAST, CSPM, and attack simulation tooling.
  • Embed security testing early in the software development lifecycle and support secure development practices across engineering teams.
  • Integrate application security, dependency, open-source risk, DAST, and API security testing controls into code repositories, IDEs, and CI/CD pipelines.
  • Conduct authorised penetration testing, technical security assessments, security design reviews, and threat modelling for material changes.
  • Validate, triage, and document security findings, including severity, business impact, accountable owners, target remediation dates, and closure evidence.
  • Track remediation progress, retest resolved vulnerabilities, and escalate overdue or material findings where required.
  • Use cloud security posture management tooling to assess cloud vulnerabilities, misconfigurations, attack paths, and compliance posture.
  • Conduct MITRE ATT&CK-aligned control validation, adversary emulation, and purple team activities across key security controls.
  • Provide practical remediation advice to engineering and technology teams, including guidance aligned to OWASP Top 10, PCI DSS secure coding requirements, and secure AI development practices.
  • Automate repeatable discovery, testing, ticketing, evidence collection, reporting, remediation tracking, and validation activities where practical.
  • Produce evidence-based reports, service metrics, and control-effectiveness insights to support operational, executive, audit, and governance reporting.

Requirements

  • Experience in cybersecurity, application security, penetration testing, security engineering, or DevSecOps.
  • Strong knowledge of web application, API, and cloud security.
  • Hands-on experience with security testing tools such as SAST, DAST, and CSPM platforms.
  • Understanding of secure software development and CI/CD environments.
  • Experience identifying, validating, and remediating security vulnerabilities.
  • Knowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST, and PCI DSS.
  • Ability to automate tasks using scripting languages such as Python or PowerShell.
  • Strong analytical and problem-solving capabilities.
  • Excellent stakeholder engagement and communication skills.
  • Ability to provide practical, risk-based security advice to technical and business teams.
  • Relevant cybersecurity qualifications, certifications, or equivalent industry experience.
  • A passion for emerging security technologies, automation, and continuous improvement.

Skills

  • SAST
  • DAST
  • CSPM
  • Attack simulation tooling
  • Application security
  • Dependency security
  • Open-source risk assessment
  • API security testing
  • Penetration testing
  • Technical security assessments
  • Security design reviews
  • Threat modelling
  • Cloud security posture management
  • MITRE ATT&CK
  • OWASP Top 10
  • PCI DSS
  • Python
  • PowerShell

Location

  • Sydney Olympic Park, Sydney CBD

Work Type

  • Hybrid
  • Maximum term contract

Experience Level

  • Cybersecurity
  • Application security
  • Penetration testing
  • Security engineering
  • DevSecOps

Education Level

  • Relevant cybersecurity qualifications, certifications or equivalent industry experience

Benefits

  • Progressive flexibility, leave and well-being benefits
  • Travel discounts on SIXT car rental, cruises, and accommodation at award-winning NRMA Holiday Parks and Resorts
  • Complimentary myNRMA Rewards membership including free Roadside Assistance & discounts on groceries, movie tickets, gift cards, gym memberships, attractions, restaurants and much more
  • Discounts on a range of NRMA personal insurance products including car, home & travel
  • Opportunities to grow, progress or relocate career within the NRMA Group

About the Company

  • We’re one of Australia’s most trusted brands. Being Member-owned, every decision we make has people and our community at its heart.
  • From our legendary Roadside assistance to electric vehicle charging networks, holiday parks and lodges, car rentals, harbour transport, and ocean cruising we are striving to make a difference that contributes to a brighter shared future for all Australians.
  • Life with us is more than just a job – it’s your chance to make a difference together.

Equal Opportunity

  • We’re for inclusion, diversity and representing the members, guests, customers and communities we serve. That’s why we welcome applications from First Nations, people with disability, those from diverse cultural backgrounds, people of all genders, members of the LGBTQI+ community, and anyone else who wants to be a part of our team.