Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Director, Offensive Security role.
Rezi rewrites your resume against Grant Thornton Australia's job description. Free.

Tailor your resume to this Director, Offensive Security role.
Rezi rewrites your resume against Grant Thornton Australia's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Director, Offensive Security posting at Grant Thornton Australia — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Director, Offensive Security posting at Grant Thornton Australia — free, in seconds.
About the Role
Grant Thornton is seeking a commercially minded and forward-thinking Director, Offensive Security to build, lead, and scale its offensive security capability within the Cyber Resilience practice. This role involves shaping an AI-enabled delivery model, working with global teams, partners, and clients to address evolving cyber threats.
Responsibilities
- Build and lead the offensive security practice, establishing strategy, service offerings, operating model, methods, quality standards, and growth plan.
- Develop an AI-enabled and partner-led delivery model to improve speed, quality, consistency, and reach.
- Lead go-to-market activity, shaping propositions, campaigns, client conversations, and commercial models.
- Deliver trusted client outcomes by leading senior client relationships and translating technical findings into executive-level risk insight.
- Modernize offensive security delivery by identifying how AI, automation, and continuous validation can evolve testing.
- Grow vulnerability and exposure management services, extending into Continuous Threat Exposure Management (CTEM).
- Lead people and capability by recruiting, developing, coaching, and retaining a high-performing team.
- Collaborate across the firm with various teams and alliance partners to create integrated solutions.
Requirements
- Significant experience in offensive security, penetration testing, red teaming, adversary simulation, security assurance, or cyber consulting, including leading complex client engagements.
- Proven ability to build trusted client relationships, originate and shape opportunities, develop proposals, lead pursuits, manage commercial outcomes, and deliver high-quality client work.
- Ability to see market trends, understand client demand, assess delivery economics, and build differentiated, scalable, and commercially sustainable offerings.
- Strong understanding of offensive security methods across various environments (application, infrastructure, cloud, identity, network, endpoint, emerging technologies).
- Practical understanding of how AI, automation, agentic workflows, and modern tooling are changing cyber-attack techniques and offensive security delivery.
- Strong understanding of vulnerability management, attack surface management, exposure prioritisation, exploitability validation, and remediation mobilisation, including CTEM programs.
- Familiarity with platforms such as Qualys, Tenable, Horizon3.ai, Rapid7, Microsoft Defender Vulnerability Management, CrowdStrike Falcon Exposure Management, Wiz, Orca Security, XM Cyber, Cymulate, Pentera, and Nucleus Security.
- Strong awareness of the Australian cyber market, buyer expectations, procurement drivers, and relevant standards (APRA CPS 234, ISM, Essential Eight, ISO 27001, PCI DSS, privacy obligations).
- Demonstrated ability to lead technical and consulting teams, develop talent, set clear expectations, manage quality, and create an inclusive, high-performing team culture.
- Experience working with global teams, delivery centres, alliance partners, or specialist providers to deliver consistent client outcomes across markets.
Skills
- Offensive Security
- Penetration Testing
- Red Teaming
- Adversary Simulation
- Security Assurance
- Cyber Consulting
- Client Relationship Management
- Business Development
- Proposal Development
- Commercial Management
- AI
- Automation
- Vulnerability Management
- Attack Surface Management
- Continuous Threat Exposure Management (CTEM)
- Cloud Security
- Application Security
- Infrastructure Security
- Identity and Access Management
- Network Security
- Endpoint Security
- Leadership
- Team Development
- Collaboration
- Strategic Planning
- Commercial Acumen
- Technical Credibility
- Market Awareness
- Regulatory Awareness
Location
- Australia
Work Type
- Hybrid
Experience Level
- Director
- Senior
Education Level
- CREST credentials (Practitioner Security Analyst, Registered Penetration Tester, Certified Tester, Certified Red Team Specialist or Manager)
- Offensive security qualifications (OSCP, OSCE3, OSEP, OSWE, CRTO, GIAC GPEN or equivalent)
- Security leadership qualifications (CISSP, CISM, CCSP, SABSA, TOGAF or similar)
- Cloud and platform certifications (Microsoft Azure, AWS, Google Cloud)
- Experience working to recognised testing methodologies, rules of engagement, ethical standards, secure handling of client data, and Australian regulatory expectations
Benefits
- 9-day fortnight with no salary reduction
- Flexible working options
- Fully funded gym membership
- Mental health support
- Financial and wellbeing coaching
About the Company
- Grant Thornton Australia is one of Australia’s leading professional services firms, providing audit, tax, and advisory services.
- Culture is underpinned by a commitment to clients, people, and communities, with a promise to ‘Reach for Remarkable’.
- Supports the careers of more than 1,500 people across six Australian offices and a global network spanning more than 150 markets.
- Offers scale, connections, and opportunities to shape career futures.
Equal Opportunity
- Encourages applications from individuals from diverse backgrounds including Aboriginal and/or Torres Strait Islanders, those in the LGBTQI+ community, and individuals who identify as having disability or are neurodivergent.
- Commitment to ensuring the recruitment process is inclusive and accessible.