About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security Technical Lead based in Australia.
This is a hands-on leadership opportunity to own and continuously improve application security across a diverse technology environment.
Responsibilities
- Own and operate application security practices across the full software development lifecycle.
- Identify, assess, prioritise, and manage application security risks while partnering with Engineering teams to drive effective remediation.
- Conduct secure code reviews, primarily across C#, .NET, and web applications, and promote secure development practices.
- Lead threat modelling exercises and security assessments across applications, development workflows, and automation processes.
- Adapt application security practices to different team maturity levels, balancing risk reduction, standardisation, and delivery requirements.
- Own, operate, and continuously optimise SAST, DAST, and SCA tooling across CI/CD pipelines.
- Establish effective security testing practices that provide strong assurance without unnecessarily slowing engineering delivery.
- Maintain visibility of application vulnerabilities, establish appropriate prioritisation, and provide clear security reporting.
- Define, maintain, and apply secure design and secure development standards across engineering teams.
- Establish and support Security Champions within development teams to strengthen security ownership.
- Mentor developers and help uplift secure coding knowledge and application security capability across the organisation.
- Engage effectively with technical and business stakeholders to communicate security risks, priorities, and recommendations.
Requirements
- 5+ years of experience in software engineering, including at least 2 years working in an application security role.
- Strong practical experience with DevSecOps principles and CI/CD environments.
- Hands-on experience implementing and managing Application Security tools, including SAST, DAST, and SCA solutions.
- Strong experience working with Microsoft Azure environments and Azure DevOps pipelines.
- Comfortable performing secure code reviews across C#, .NET, and modern web applications.
- Strong understanding of the OWASP Top 10, secure software development, and secure design principles.
- Experience working across multiple applications, teams, or platforms with varying levels of application security maturity.
- Ability to adapt security strategies according to risk, technical complexity, team maturity, and delivery context.
- Strong analytical and problem-solving skills, with the ability to translate technical security risks into practical remediation actions.
- Self-driven, accountable, and comfortable taking ownership of an established security capability.
- Strong stakeholder engagement and communication skills, with the ability to influence engineering teams and build collaborative relationships.
- A continuous improvement mindset and willingness to mentor others and share application security knowledge.
Conditions
- Opportunity to own and run a mature Application Security capability.
- Exposure to a diverse application landscape and multiple engineering teams.
- Opportunity to work in an environment with a strong focus on cybersecurity and secure software development.
- Culture that values continuous improvement, learning, and knowledge sharing.
- Balance of working from home and office-based collaboration.
- Inclusive working environment that welcomes people with diverse backgrounds, experiences, skills, and perspectives.
- Recruitment process adjustments available to support accessibility needs.