Information Security Consultant (Penetration Testing) at Westpac Group
Sydney, New South Wales, Australia -
Full Time


Start Date

Immediate

Expiry Date

06 May, 26

Salary

0.0

Posted On

05 Feb, 26

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Information Security, Penetration Testing, Vulnerability Management, Security Policies, Risk Management, Web Application Testing, Infrastructure Testing, Mobile Testing, Security Documentation, Security Awareness, Training Programs, Regulatory Frameworks, Automated Security Testing, Software Development, Risk Analysis, Threat Modelling

Industry

Financial Services

Description
Create your best future and join Westpac as an Information Security Consultant (Penetration Testing). What’s the role? This role will be responsible for conducting penetration testing, managing vulnerabilities, and supporting the development and implementation of security policies and governance frameworks. It will ensure compliance through accurate security documentation, while responding to and resolving security incidents based on risk. The role will also drive security awareness across employees and developers, and support training programs to uplift capability. Additionally, it will partner with business units and third‑party providers to ensure effective security controls and provide clear reporting to executive stakeholders. What do I need? Experience in information security, information technology, risk management, or equivalent role. Experience performing Web Application, infrastructure, application, mobile and infrastructure level penetration testing. Formal education or certification in Penetration Testing (such as OSCP, OSCE, CREST or Advanced SANS Penetration Testing) is a mandatory requirement for this position. Experience identifying and documenting security requirements. Experience in writing Penetration Testing reports and communicating identified vulnerabilities to the internal stakeholders. Ability to work both individually and within a team environment and build strong relationships with the internal stakeholders. Solid understanding of one or more of the following platforms: Windows, Linux, Infrastructure, Networking and Cloud/Virtualisation. Working knowledge of regulatory frameworks (such as OWASP, OSSTMM) related to information security. Experience implementing automated security testing tools and processes. Software development experience is favourable. A good understanding of information security best practice standards and guidelines (e.g. ISO 27001). Risk analysis/Threat modelling experience. Why join us? We’re obsessed with becoming our customers' #1 banking partner for life and we’re looking for people who are passionate about helping us achieve that goal. In return, we’re committed to making Westpac the best place to work in the country. Here are just a few of the ways we’re already doing that: Special offers on banking products and discounts from top brands, including generous employee-only mortgage rates! Flexible work arrangements to help you achieve a greater work/life balance, and a variety of leave options including Culture, Lifestyle and Wellbeing leave. Tailored learning and development opportunities to help your grow your career within the bank. Lots of opportunities to ‘give back’ to the Community by getting involved in our many volunteering initiatives. Create your future today To get started, simply click on the APPLY or APPLY NOW button We’re all about creating a supportive and inclusive community. We welcome everyone – no matter your age, gender, background, or abilities. We also provide additional support to welcome our veterans, Indigenous Australians and neurodiverse community. If you need any adjustments during the recruitment process, you can find out more information and additional contact details by visiting the "People with Disability and/or needing Accessibility Requirements" page on our website. #LI-Hybrid.
Responsibilities
The role involves conducting penetration testing, managing vulnerabilities, and supporting the development of security policies. It also includes responding to security incidents and driving security awareness across the organization.
Loading...