Penetration Testing Manager
Job Summary
When you join ASX youre joining a company with a strong purpose to power a stronger economic future by enabling a fair and dynamic marketplace for all.
In your new role youll be part of a leading global securities exchange with a strong brand. We are known for being a trusted market operator and an exciting data hub.
Want to know why we are a great place to work click on the link to learn more.
are more than a securities exchange!
The ASX team brings together talented people from a diverse range of disciplines.
We run critical market infrastructure with 1 in 3 people employed within technology. Yet we have a unique complexity of roles across a range of disciplines such as operations program delivery financial products investor engagement risk and compliance.
Were proud to foster a workplace where diversity is celebrated and inclusion is part of our everyday culture. Our employee-led networks champion LGBTIQ inclusion promote gender equality accessibility and wellbeing inspire giving and volunteering and celebrate cultural and religious events creating a sense of belonging for all. As an AWEI Bronze employer and member of the Champions of Change Coalition for gender equality were committed to a fair and inclusive workplace where everyone can thrive.
Your Team
The Cyber Architecture and Assurance team provides independent assurance over ASXs cyber control environment helping protect the integrity availability and resilience of market-critical services.
The team works across Cyber Security Technology and business stakeholders to establish assurance standards govern testing activity coordinate specialist external providers drive accountability for remediation and provide evidence over the effectiveness of controls across penetration testing Red/Purple Team coordination control validation and risk-based security assessment activities.
Coordinate ASXs end-to-end penetration testing program including annual planning project-based testing engagement governance vendor delivery reporting closure and remediation follow-up.
Coordinate Red Team and Purple Team activities ensuring exercises are appropriately scoped governed safely executed and translated into actionable control improvement opportunities.
Own the scope definition and rules of engagement for penetration testing ensuring coverage is risk-based complete agreed by accountable system and project owners and aligned to system criticality project risk technology change and threat exposure.
Manage relationships with external penetration testing providers ensuring engagements are appropriately planned governed delivered and assessed against agreed quality expectations.
Support budget allocation forecasting and tracking for penetration testing and related assurance activities including provider spend planned testing demand and delivery risks.
Drive internal readiness for regular and project-based penetration tests holding project system and platform owners accountable for providing testable environments required access approved connectivity stakeholder support test windows and safe execution constraints.
Establish and manage engagement governance including readiness criteria go/no-go decision points escalation paths daily status reporting issue management SOW coordination and closure criteria.
Act as the central escalation and decision point during live testing removing blockers coordinating rapid issue resolution tracking coverage against agreed scope and ensuring high or critical findings are communicated promptly.
Hold technology application cloud infrastructure business and vendor teams accountable for triaging findings agreeing remediation actions tracking closure and escalating material risks where obligations are not being met.
Evaluate pilot and integrate AI-enabled or automated penetration testing capabilities into the broader cyber assurance and security testing strategy.
Communicate testing outcomes themes delivery risks and risk insights clearly to technical teams senior stakeholders and non-technical audiences.
Your experience and qualifications
Must have:
Background in information security penetration testing principles vulnerability assessment and risk-based security assurance.
Exposure to the delivery lifecycle for security testing or assurance engagements including planning scope governance readiness management execution oversight reporting or remediation follow-up.
Experience working with external security vendors or penetration testing service providers including delivery coordination quality review or performance follow-up.
Ability to translate project system and control risk into clear testing objectives rules of engagement readiness expectations and remediation priorities.
Exposure to penetration testing across complex technology environments such as applications APIs infrastructure cloud platforms and critical business systems.
Ability to influence stakeholders and drive accountability across technology project application infrastructure cloud business and vendor teams.
Working knowledge of engagement governance including roles and responsibilities readiness criteria escalation paths reporting cadence and quality expectations.
Working knowledge of contemporary security testing methodologies common vulnerability classes and relevant cyber security frameworks or regulatory expectations.
Nice to have:
Hands-on penetration testing experience noting ASX primarily uses a panel of specialised providers for delivery.
Experience with Red Team or Purple Team exercises including exercise planning coordination debriefs and translation of outcomes into control improvements.
Experience with AI-driven automated or continuous security testing tools including safe adoption governance and integration into assurance workflows.
Relevant security certifications such as OSCP GPEN CISSP CISM or equivalent practical experience in security testing or cyber assurance.
Experience working in financial services critical infrastructure or another highly regulated technology environment. What you need to enjoy and be good at
Highly organised detail-oriented and able to switch context across varied assurance delivery stakeholder and operational
tasks.
Negotiating mutually acceptable outcomes while clearly asserting non-negotiable security process and control requirements.
Building strong relationships with internal and external stakeholders including technology teams business owners and specialist security providers.
Taking ownership of issues and driving them through to closure balancing the bigger picture with the ability to dive into detail when required.
Communicating clearly in writing and verbally with a continuous improvement mindset and strong risk focus in an environment where control effectiveness cannot be compromised.
We make hiring decisions based on your skills capabilities and experience and how youll help us to live our values. We encourage you to apply even if you dont meet all the criteria of this role.
If you need any adjustments during the application or interview process to help you present your best self please let us know at
At ASX Group our diverse workforce is essential to build and maintain a fair and dynamic marketplace. We support flexible working and offer hybrid working options. Even if our roles are advertised as full-time we encourage you to apply if you are interested in part-time or other flexible working arrangements.
We will arrange for successful candidates to have background checks including reference and police checks completed as part of the on-boarding process.
To be considered for this position candidates must be legally authorised to work in Australia on a permanent basis without any restrictions.
Required Experience:
Manager