Job no: 542410
Work type: Full Time
Location: Sydney, NSW
Categories: Cyber
- Full time continuing role within UNSW IT, Cyber Directorate – Cyber Security Assurance Testing Lead
- Starting Salary $153,933 plus generous superannuation and leave loading
- Kensington, Sydney location, 2-3 days in the office, Hybrid working
About UNSW:
UNSW isn’t like other places you’ve worked. Yes, we’re a large organisation with a diverse and talented community; a community doing extraordinary things. Together, we are driven to be thoughtful, practical, and purposeful in all we do. Taking this combined approach is what makes our work matter. It’s the reason we’re one of the top 20 universities in the world (QS top 20) and a member of Australia’s prestigious Group of Eight. If you want a career where you can thrive, be challenged and do meaningful work, you’re in the right place.
The Cyber Security Assurance Testing Lead maintains, delivers and administers Cyber Security Assurance Services within a fit-for-purpose and adaptive Cyber Security Risk Management framework. The role is responsible for the assurance testing of ICT services and IT initiatives, and the provision of cyber security subject matter expertise, controls assurance, and reporting services to university stakeholders. The Cyber Security Assurance Testing Lead reports to the Cyber Security Controls Assurance Manager and has no direct reports.
Accountabilities:
- Ensure that high and medium cyber risk rated information resources and services are regularly subjected to security testing which includes penetration tests, web application scanning, dynamic application security testing and API testing.
- Proactively conduct automated penetration testing and vulnerability assessments of new and existing applications, systems, and networks using relevant tools.
- Facilitate annual controls assurance testing including but not limited to annual penetration testing of high cyber risk rated assets, red teaming exercises, etc, with the support of cyber security analysts, internal team members and external testing partners.
- Review, validate and triage findings from the manual and automated penetration tests, vulnerability scans, app security testing, CSPM tools, API testing, etc.
- Update the cyber risk register with risks from controls assurance tests.
- Communicate and report on controls assurance testing findings and associated risks, and work with business owners, control owners and operators to remediate and close findings/issues as per vulnerability remediation timeframes stipulated in in the University’s security standards.
- Ensure the accurate and timely release of controls assurance testing reporting and metrics.
- Regularly review threat and vulnerability advisories from various sources (e.g. ACSC, NCSC, CISA) and, where a high priority response is required across the organisation, collaborate with the Cyber Security Operations teams.
- Contribute to the ongoing development and execution of a continuous control’s assurance testing approach, including monitoring, control uplift (incl. automation) and rationalisation.
- Support the independent audit of cyber security controls on behalf of the University, including statutory audits completed by the Audit Office of NSW.
- Maintain awareness of changes to legal, regulatory compliance and contractual obligations that are relevant to the University’s management of cyber security risks.
- Promote awareness of the University’s internal and external environment for emerging cyber security threats.
- Build effective working relationship with internal and external stakeholders to develop innovative solutions that meet business needs.
- Promote a culture of continuous improvement, championing professional standards, innovation, and methods.
- Other duties appropriate and in line with to this position as requested by the Cyber Security Controls Assurance Manager or the Cyber Security leadership team.
- Align with and actively demonstrate the Code of Conduct and Values
- Cooperate with all health and safety policies and procedures of the university and take all reasonable care to ensure that your actions or omissions do not impact on the psychosocial or physical health and safety of yourself or others.
- Ensure hazards and risks psychosocial and physical are identified and controlled for tasks, projects, and activities that pose a health and safety risk within your area of responsibility.
Who you are:
- 6+ years of IT security services experience, 3+ years of experience in penetration testing, vulnerability management, application security testing, source code review.
- Experience in 1st line assurance role, working with vulnerability management and scanning systems.
- Scripting in PowerShell, Python, Bash, etc is advantageous.
- AWS, Azure and Microsoft365 security experience desirable but not mandatory.
- A relevant degree with extensive experience in cyber security operations or assurance teams within major organisations or an equivalent level of knowledge gained through any other combination of education, training, and experience.
- Excellent understanding of industry-wide security standards and compliance frameworks such as ISO 27001, NIST 800-53, OWASP, CSA, Essential 8, PCI DSS, COBIT 5, Mitre ATT&CK etc.
- Relevant industry certification(s) such as SANS certifications, CEH, OSCP, CompTIA Security+, and cloud platform certifications such as, AWS Security Speciality, Microsoft Azure (highly desirable).
- Strong interpersonal, communication and negotiation skills including ability to develop effective relationships and influence key stakeholders at all levels in the organisation.
- Analytical ability to present with credibility and translate technical and complex information concisely for diverse audiences using strong analytical and problem-solving skills.
- Demonstrated high level of personal motivation, resilience, and ability to work effectively individually or in teams.
- Experience in the use of automated vulnerability scanning, security validation, penetration testing, static and dynamic application security testing, and cloud posture management tools e.g. such as Pentera, Tenable.io, Checkmarx, Lacework, GuardDuty etc.
- Ability to code in PowerShell, Python, Bash, etc is advantageous.
- An understanding of and commitment to UNSW’s aims, objectives and values in action, together with relevant policies and guidelines.
- Knowledge of health & safety (psychosocial and physical) responsibilities and commitment to attending relevant health and safety training. Pre-employment checks required for this position
Benefits and Culture
- Flexible Working Options (work from home, flexible hours etc)
- Career development opportunities
- 17% Superannuation contributions and additional leave loading payments
- Additional 3 days of leave over Christmas period
- Discounts and entitlements (retail, education, fitness)
For further details on the benefits, please visit https://www.jobs.unsw.edu.au/lifestyle-benefits
To apply:
Please submit your CV, Cover Letter and responses addressing the required Who you are criteria.
Please note: Sponsorship is not available for this role; valid Australian working rights are required on application.
Pre-Employment Checks
As part of our recruitment process candidates may be required to undergo pre-employment screening, which may include reference checks, qualification verification, right-to-work verification, and criminal history screening where relevant to the role.
Contact: Jen MacLachlan - Talent Acquisition Partner- e: j.maclachlan@unsw.edu.au
Please apply through the application portal as we do not accept direct applications to the email above.
Applications close: Thursday 10th of September at 11.30pm
UNSW is committed to equity diversity and inclusion. Applications from women, people of culturally and linguistically diverse backgrounds, those living with disabilities, members of the LGBTIQ+ community; and people of Aboriginal and Torres Strait Islander descent, are encouraged. UNSW provides workplace adjustments for people with disability, and access to flexible work options for eligible staff.
The University reserves the right not to proceed with any appointment.
Advertised: 28 Aug 2026 AUS Eastern Standard Time
Applications close: 10 Sep 2026 AUS Eastern Standard Time
Find Your Best Opportunity
Tell them AcademicJobs.com sent you!

