CyberCX logo

CyberCX - Penetration Tester - Canberra

CyberCX โ€ข Canberra, Australia

onsitefull-time
Posted Sep 25, 2026Apply by Oct 25, 2026

**Role & seniority: ** Penetration Tester (mid-level); performs tests with oversight/support from a more senior team member and provides security expertise to clients.

**Stack/tools: **

  • Penetration testing and vulnerability assessment tooling (not specified)

  • Security testing certifications (e.g., OSCP preferred)

  • Reporting/communication artifacts for clients (tooling not specified)

**Top 3 responsibilities: **

  • Deliver application, network, systems, and infrastructure penetration tests (top STA services and emerging offerings) to a high standard with adequate supervision.

  • Produce high-quality penetration test reports: document findings, recommendations, and remediation guidance; discuss results and next steps with customers.

  • Manage delivery performance: meet KPIs (quality, deadlines, expectation management) and conduct quality management; support utilization/on-budget delivery.

**Must-have skills: **

  • 2+ years as a security/cyber practitioner with capability in client expectation management, time management, technical delivery, and report writing.

  • Stakeholder engagement & communication.

  • Analytical/problem-solving skills.

  • Ability to respond to setbacks with agile/resilient execution.

**Nice-to-haves: **

  • OSCP (or similar) penetration testing certification.

  • Tertiary qualification in information systems/software development (or equivalent experience).

  • Support k

Full Description

The Penetration Tester is responsible for carrying out penetration testing, vulnerability assessment activities, and any other security activities with oversight/support from a more senior team member and providing security expertise to CyberCX clients.

Key Roles & Responsibilities

Deliver application, network, systems, and infrastructure penetration tests for customers. Able to perform the top five and emerging STA services offered by the Practice to a high standard with adequate supervision Prepare high quality reports detailing security issues, making recommendations, and identifying solutions, contribute to presentations and discussions with customers around testing performed, key results, recommendations, and the next steps Build and promote strong, long-lasting relationships with a diverse range of customers, and identify and explore opportunities within existing and new customers Ensure that KPIs around client expectation management, delivery deadlines, quality of work and deliverables etc are met, including conducting quality management Share knowledge and support STA team members to up/cross skill in hard and soft skills Contribute to a culture of empowerment, collaboration, and accountability through consistent employee engagement Assist with R&D, innovation, and practice improvement activities, under supervision Actively collaborate across CyberCX, and continuously look for ways to add value. Facilitate communication, partnerships and cross-pollination across the business to allow teams to better engage and service customers Meet utilisation targets and ensure on-budget delivery

Preferred Qualifications, Experience & Skills

Tertiary qualification in information systems, software development or a similar field, or equivalent industry experience Penetration testing certifications such as OSCP preferred but not essential A minimum of 2 years as a security testing practitioner / cyber practitioner in which you have developed capability in managing client expectations, time management, technical delivery and report writing Effective stakeholder engagement and communication skills Strong analytical and problem-solving skills Skilled in responding to setbacks in an agile and resilient manner

Penetration TestingVulnerability AssessmentApplication Security TestingNetwork Security TestingSystems Security TestingInfrastructure Security TestingSecurity ReportingClient Relationship ManagementStakeholder EngagementCommunicationAnalytical ThinkingProblem-SolvingTime ManagementQuality ManagementAgile ResilienceKnowledge Sharingmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.