ironquill.tech/board

$ cat jobs/offensive-security-engineer-mynrma-306fda50a4e2.json

Offensive Security Engineer

Mynrma·Worldwide·Sydney Olympic Park, AU·mid
Apply on smartrecruiters → Get AI match score →
We’re one of Australia’s most trusted brands. Being Member-owned, every decision we make has people and our community at its heart. From our legendary Roadside assistance to electric vehicle charging networks, holiday parks and lodges, car rentals, harbour transport, and ocean cruising we are striving to make a difference that contributes to a brighter shared future for all Australians. Forget what you thought you knew about the NRMA – take a look on the inside and you’ll discover that life with us is more than just a job – it’s your chance to make a difference together. We have an exciting opportunity for an Offensive Security Engineer to join our Technology team based in Sydney Olympic Park . This role plays an important part in protecting the confidentiality, integrity, availability and resilience of NRMA technology and data by identifying exploitable weaknesses before they cause harm, validating the effectiveness of security controls, and supporting safer delivery across our technology environment. Reporting to the Senior Manager, Security Compliance & Governance, you’ll work closely with engineering, cloud, platform, infrastructure, architecture and security teams to embed security early in the software development lifecycle, reduce vulnerabilities reaching production, and provide evidence-based assurance across applications, APIs, cloud environments and security controls. This is a hands-on role for someone who enjoys practical security testing, automation, threat emulation, vulnerability lifecycle management and working with technical teams to improve security outcomes in a complex enterprise environment. This 9-12 month maximum term contract role offers a hybrid work arrangement across our Sydney Olympic Park, Sydney CBD offices and working from home, as agreed and required for the role. What You’ll Do Plan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services and cloud-hosted workloads