Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailMaximum hours 7 hours per day
Security clearance Must be able to obtain Negative Vetting Level 1
Penetration Testers analyse IT systems to determine configuration weaknesses and faults that would impact on security and business then produce reports detailing the findings and recommendations for improved network security.
Key duties and responsibilities As part of our ongoing security assurance efforts and in alignment with Australian Government cybersecurity standards we are seeking external penetration testing services for a cloud-hosted web application deployed within Microsoft Azure infrastructure. The assessment will cover both the UAT and Production environments and will focus on identifying vulnerabilities across the external attack surface including both unauthenticated and authenticated access vectors. The testing should specifically assess web-layer exposures and associated backend services including Azure App Service Azure SQL Database Azure Key Vault private endpoints and Azure Storage Accounts. While no API testing is required the application includes third-party integrations such as Chatpa code embedded within a web form which should be included in the assessment scope.
Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters.
Essential criteria
Penetration testing: Level 5 (SFIA) Plans and drives penetration testing within a defined area of business activity. Delivers objective insights into the existence of vulnerabilities the effectiveness of defences and mitigating controls. Takes responsibility for the integrity of testing activities and coordinates the execution of these activities. Provides authoritative advice and guidance on all aspects of penetration testing. Identifies needs and implements new approaches for penetration testing. Contributes to security testing standards.
Penetration Testing and conducting Simulated Attack Exercises: Level 5 (CIISEC) Uses commercial and bespoke tools to conduct complex penetration testing without close supervision and/or leads teams undertaking complex penetration tests. Undertakes penetration exploits as part of a simulated attack exercise under direction. Appropriate and relevant certifications include CHECK Team Leader CREST Certified Tester (Infrastructure or Web Applications) or equivalents.
Education
Pen Tester
Full Time