
Offensive Security Engineer
UST
Visa & sponsorship
- AU CSOL: this role is on the national occupation list. The posting doesn't state a salary we could check against the threshold.
Job description
Role Description
We are looking for an Offensive Security Engineer to join team on a short-term contract. This role is ideal for a technical professional who excels at practical security testing, threat emulation, automation, and vulnerability lifecycle management in enterprise environments.
Key Responsibilities
-
Conduct authorised, risk-based security testing across cloud workloads, identity services, networks, infrastructure, web applications, and APIs.
-
Manage, administer, and optimise core security testing platforms, including CSPM, SAST, DAST, and attack simulation tools.
-
Drive secure development practices by embedding security testing early in the SDLC.
-
Integrate open-source risk, dependency, AppSec, API, and DAST security controls into CI/CD pipelines, code repositories, and IDEs.
-
Execute authorised penetration testing, threat modeling, security design reviews, and technical assessments for material changes.
-
Document, triage, and validate security findings, capturing critical details such as business impact, severity, accountable owners, remediation targets, and closure evidence.
-
Monitor remediation progress, retest resolved issues, and escalate material or overdue vulnerabilities.
-
Utilise CSPM tooling to evaluate compliance posture, attack paths, misconfigurations, and cloud vulnerabilities.
-
Execute MITRE ATT&CK-aligned adversary emulation, control validation, and purple team initiatives.
-
Supply actionable remediation guidance to technology teams, utilising standards like the OWASP Top 10, secure AI development practices, and PCI DSS coding requirements.
-
Automate repetitive tasks across testing, discovery, ticketing, remediation tracking, validation, and reporting.
-
Develop evidence-based metrics, reports, and control-effectiveness insights for audit, executive, operational, and governance stakeholders.
Required Skills And Experience
-
Professional background in DevSecOps, application security, penetration testing, security engineering, or cybersecurity.
-
Knowledge of cloud, API, and web application security.
-
Practical experience operating security testing platforms such as CSPM, SAST, and DAST.
-
Solid understanding of CI/CD environments and secure software development practices.
-
Demonstrated experience in discovering, validating, and remediating security vulnerabilities.
-
Working knowledge of major security frameworks, including NIST, ISO 27001, PCI DSS, MITRE ATT&CK, and the OWASP Top 10.
-
Scripting proficiency (e.g., Python or PowerShell) to automate workflows & tasks.
-
Strong communication abilities with a proven track record of effective stakeholder engagement.
B
enefits & Perks
-
Flexible/hybrid working arrangements.
-
Health insurance.
-
Novated Car Lease.
-
Access to UST Perks (Reward Gateway), which offers discounts across major retailers.
O
ur commitment to Diversity, Equity and Inclusion
Diversity and Inclusion are among the founding blocks of how UST as an organisation translates its values of Humility, Humanity, and Integrity into practice.
About UST
For more than 25 years, UST has worked side by side with the world's best companies to make a real impact through digital transformation. Together, with over 30,000 employees in 30+ countries, we build for boundless impact—touching billions of lives in the process.
Skills
Application Security, Security Engineering, Vulnerability Management, Vulnerability Assessment and Penetration Testing, Threat Modeling, SAST, DAST, Python, PowerShell, DevSecOps, ISO 27001