Penetration Tester

AustraliaPosted Jul 23, 2026
Vulnerability Discovery & Exploitation: Find and validate security vulnerabilities through hands-on penetration testing, code review, and proof-of-concept exploit development. Tooling & Automation: Build and maintain automated and autonomous tooling to scale offensive security testing and vulnerability discovery. Research & Threat Analysis: Investigate emerging attack techniques, exploit classes, and AI/agentic system threats. Feed findings into testing priorities and architectural improvements. Security Architecture Collaboration: Work with Security Architecture and service teams to assess design-level risks, review threat models, and inform platform hardening based on offensive findings. Reporting & Remediation: Write technical reports that clearly describe what's broken, the impact, and how to fix it. Track findings through to resolution with service owners. Detection & Blue Team Partnership: Work with detection engineering and blue teams to validate coverage and close detection gaps from offensive findings. Bachelor's Degree in Statistics, Mathematics, Computer Science or related field OR 3+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection. 3+ years of experience in security research, penetration testing, or offensive security roles. Hands-on experience discovering and exploiting vulnerabilities in AI systems and platforms. Proficiency in Python with experience in AI frameworks and security testing tools. Ability to read and analyze code across multiple languages and codebases. Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in security or related field OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in security or related field OR equivalent experience. 5+ years of experience in penetration testing web applications, APIs, cloud infrastructure, or identity/authentication systems. Published security research or conference presentations on offensive security topics. Background in software engineering with distributed systems expertise. Security certifications such as OSCP, OSWE, GWAPT, or similar. Knowledge of service-to-service authentication, authorization models, and cloud-native architectures.

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free