Permanent
25 Aug 2026 11:59pm
Penetration-Tester
Job Summary
As a Security Testing - Specialist, you have a passion for security and ethical hacking and thrive on helping to identify and resolve security weaknesses that pose a risk to Telstra and our customers. In this role, you set up and perform the technical coordination of vulnerability assessments and penetration testing. You ensure tests are run according to test plan templates and identify and address any areas of risk. Your analytical thinking and continuous learning mindset are critical to success in this role, as you continue to deepen your knowledge and expertise in the Security Testing Domain.
Who We Are
We're an iconic Aussie brand with a global footprint. Our purpose is to build a connected future so everyone can thrive. We're all about providing the best experience and delivering the best tech on the best network.
This includes making Telstra the place you want to work. For you, that means a having career that grows with you and working with a team powered by human connection that prioritises wellbeing and choice
Focus of the role:
The Security Testing Specialist’s primary focus is to perform Penetration Tests, Vulnerability Assessments and reviews of source code authored by Telstra, as well as providing specialist review and advice for developers within Telstra.
Secondary purposes of the role include developing and mentoring other staff, improving our testing processes and methodologies, and implementing automation into our security testing program of work.
Telstra’s Security Testing team is responsible with conducting all Vulnerability Assessments, Penetration Tests and Source Code Security Reviews across Telstra’s products, applications, and services - assessing the corresponding level of risk and developing and/or recommending appropriate mitigation countermeasures of products, applications, and technology within Telstra
Role scope:
This role will be responsible for delivering source code security reviews, penetration tests and vulnerability assessments, as well as deliver improvements to tooling and assessment capabilities, to effectively identify security vulnerabilities within Telstra’s systems and networks throughout their lifecycle. Additionally, this role will have a focus on delivering knowledge and skill to enable software developers to work securely.
The role will need to draw on capabilities from the broader Security Testing and Cyber Security team to help identify and resolve root cause issues to minimise opportunities for repeat findings.
What We Offer
Additional Telstra day off
Additional 30% off Telstra products and services
Toolkit provided (laptop + mobile phone + plan paid for)
What you’ll do:
Conduct source code security reviews of systems and utilise a suite of assessment tools to expose threats, vulnerabilities, and potential attack vectors in applications
Act as a technical subject matter expert in application security testing and secure source code development.
Identify security vulnerabilities by generating various attack scenarios for target systems to enable development of countermeasures for identified security vulnerabilities
Conduct authorised penetration testing of systems and utilise a suite of network monitoring and vulnerability scanning tools to expose threats, vulnerabilities, and potential attack vectors in a system
Execute vulnerability scans, document, and interpret results to identify security lapses in the system
Identify security lapses in the system or security mechanisms, based on issues documented from vulnerability scan s and penetration test results
Work collaboratively with the Security Testing – Senior Lead and other team members to drive forward the Security Testing strategy, including providing direction and input into future capability, resourcing, roadmaps, and operations.
Evaluate the extent to which systems can protect the organisation's data and maintain functionality as intended and make recommendations for changes and improvements
Assess current security practices and controls against expected performance parameters / guidelines and identify and recommend solutions where required
Develop security testing reports, highlighting key threats and areas for improving system security
HSE Responsibility: Take reasonable care for your own safety and the safety of others, comply with and implement any reasonable Telstra HSE instruction, policy, standard, minimum requirement or procedure, and support Telstra to meet its duties under the relevant safety and environmental legislation.
About you:
A minimum of 3 years’ experience in an Security Testing role, including experience in both an Application Security/Secure Code and Penetration Testing role
Experience and exposure to a variety of software delivery models, including DevOps and Waterfall
Experience in performing manual security assessments, including penetration testing and code review
Experience in creating technical reports, and executive reports from highly technical content
Working knowledge of security assessment toolsets, such as vulnerability scanners, SAST, DAST and SCA
Ability to review and provide guidance and feedback on security assessment reports.
Understanding of security fundamentals including transport security, authentication, authorisation, threat modelling, and logging and monitoring.
Tertiary qualifications in Electrical/Electronic, Computer, Network or Software Engineering; Information/Cyber Security; IT or a related discipline
Industry Certifications, or demonstratable skillset equal to or exceeding : Offensive Security – OSCP
Good to have:
Prior experience as a developer / software engineer.
Experience in developing security policy, standards, and development guidelines
Experience in performing in depth penetration testing across a variety of domains, as well as experience in identifying zero-day exploits.
Significant experience in a complementary assessment discipline, such as Penetration Testing or other domain areas of Cyber Security
Experience in implementing automated security assessment tools into CI/CD pipelines
Experience in training and developing people
A strong understanding of adjacent security dependencies including endpoints, application platforms, databases, network security technologies, development frameworks.
Current industry certification, including but not limited to:
Experience in managing engagements with external security vendors
As part of your application with Telstra, you may receive communications from us on +61 440 135 548 (for job applications in Australia)
When you join our team, you become part of a welcoming and inclusive community where everyone is respected, valued and celebrated. We actively seek individuals from various backgrounds, ethnicities, genders and disabilities because we know that diversity not only strengthens our team but also enriches our work. We have zero tolerance for harassment of any kind, and we prioritise creating a workplace culture where everyone is safe and can thrive.
As part of the hiring process, all identified candidates will undergo a background check, and the results will play a role in the final decision regarding your application.
We work flexibly at Telstra. Talk to us about what flexibility means to you. When you apply, you can share your pronouns and / or any reasonable adjustments needed to take part equitably during the recruitment process.
We are aware of current limitations with our website accessibility and are working towards improving this. Should you experience any issues accessing information or the application form, and require this in an alternate format, please contact our Talent Acquisition team on [email protected] or via the additional contact options found at www.telstra.com.au/careers/diversity-equity-and-inclusion/disability-employment .