Penetration Tester (Multiple Positions)
Summary
Offensive Security Specialist performing penetration tests, vulnerability assessments, red teaming, and scenario-based security assessments across applications, networks, and mobile platforms for a boutique Brisbane cyber security consultancy. Day-to-day work blends hands-on technical testing with executive-level reporting, using tools and frameworks aligned to OWASP, NIST, and ISO standards.
Salary: $80,000 – $120,000 per year
Division 5 is recruiting both entry level and experienced penetration testers for several positions available.
About Our Business
Division 5 is a boutique cyber security consultancy based in Brisbane, Queensland Australia. Our mission is to build world-class cyber security in Australia, and our vision is to be a global leader by revolutionising cyber security within Australia. To achieve this, we believe that it is vital we create a culture that encourages quality, integrity, respect, camaraderie, and technical excellence, while nurturing innovation and creativity within our employees. Our Assurance stream is growing, and we are looking for an Offensive Security Specialist to join our team.
We work closely with customers all around Australia to deliver high-quality cyber security services with a goal of safeguarding their businesses against the threats of a modern world. We deliver a holistic approach to cyber security through three key service areas – assurance, defence, and strategy.
With our history working inside Australian business, we understand that not all customer environments are the same. Our experience and exposure working with organisations of all sizes, from large local and state government agencies to small boutique businesses, means we can tailor our services to meet our customer’s needs. It can be hard to navigate the world of cyber security and determine what you do and do not need – we will continue to support our customers through these challenging times.
Division 5 is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.
Primary Purpose of the Role
The role of Offensive Security Specialist within Division 5 will be responsible for the successful delivery of security assurance work, including but not limited to active security assessments such as penetration testing, vulnerability assessments, red teaming, and other scenario-based assessments. The role will also be required to support team members within a differing stream to ensure a successful and quality outcome for Division 5 customers, this may include security incident response activities, as well as other structured paper-based assessments such as threat and risk assessments.
Key Responsibilities and Accountabilities
The following details a list of key accountabilities with respect to the role of Offensive Security Specialist at Division 5.
Operate a hands-on and active role involving penetration testing and vulnerability assessment activities of complex applications, operating systems, wired and wireless networks, mobile applications, and other technologies as required.
Review cyber security technical controls, and provide recommendations, based on current and emerging better practice, as well as communicate responses and mitigation for identified weaknesses.
Prepare executive management level, analytical reports, discussion papers and memos in plain-English, to inform, assess alternatives, recommend actions, and promote new ideas or strategies in relation to cyber security.
Provide support in other areas of delivery, including scoping for new assessments, contributing to the quality assurance processes, and offering guidance for associate-level testers as they gain experience in the industry.
Build and maintain healthy relationships with key stakeholders, whether current or future customers, industry professionals, or other internal staff.
Contribute to a positive workplace culture through personal commitment to Respect, Equity and Diversity principles as well as the Division 5 code of conduct.
Key Challenges
Effectively working on simultaneous outcomes to the required standards and timeframes. This may include overlap in customer engagements due to unforeseen circumstances.
Translating highly technical and technically based concepts into the business context and obtaining support from stakeholders and other staff as required.
Staying abreast of emerging issues and maintaining up to date knowledge on cyber security, offensive security tooling, cyber risk, and relevant ICT trends, while providing timely and relevant advice on emerging topics or issues.
Continually building knowledge of better practice regarding cyber security preparedness and awareness techniques.
Key Perks
Up to 3 paid volunteer days a year for your favourite cause.
An annual training allowance to support learning and growth within the industry.
Participate in the incentivised Division 5 research program for the purpose of CVE discovery or security tool development.
Positive work culture driven by a young and energetic team with a strong focus on diversity and equality for all.
Ability to salary package motor vehicles, portable electronics, and superannuation.
Membership to industry bodies such as AISA, ISACA, and OWASP.
Regular team building and bonding sessions, whether in-person or virtual – for example:
Team participation in virtual capture the flag type events
Cyber Security conference and meetup attendance
Other social events
Fresh fruit, coffee, and a weekly laundry service.
CBD based office very close to public transport.
Flexible work-from-home schedule
Capabilities
Division 5 will consider the following capabilities across personal attributes, relationships, results, and business enabler categories. While all are relevant for this role, those in bold are focus capabilities:
Displays resilience and courage
Acts with integrity
Values diversity and inclusion
Communicates effectively
Commitment to customer service and satisfaction
Works collaboratively
Ability to influence and negotiate
Delivers quality results
Ability to plan and prioritise
Think and solve problems
Demonstrates accountability
Further to the list above, the following technical competencies are preferred:
Advanced computer skills – extensive computer skills and an understanding of networking. For example, experience with complex ICT infrastructure, web application architecture, database design, operating systems, wireless technologies, and cryptography.
Scripting and programming – exposure to active development of applications, security tools, or automation tasks to better support quality outcomes – this includes experience in the use of Python, PowerShell, and Ruby.
Knowledge of common industry tools, frameworks, methodologies, and terms, including but not limited to CVSS, OWASP ASVS, NIST Frameworks, ISO 9000, 27000, and 31000 series.