
Offensive Security | Senior Manager
- Sydney, NSW
- Permanent
- Full-time
Experience in working with applications that perform a wide range of business functions - ideally across multiple industriesAbility to understand and assess applications from both a technical and business function perspectiveGood experience in performing web application penetration testing and development of supporting business and technical-level reportingInnovative and analytical in your approach to performing penetration testing, particularly of novel devices and environmentsCapable of working to strict deadlines and prioritising work appropriatelyThe ability to develop scripts or code to automate testing and develop bespoke attacksGood communication skills with an ability to explain complex technical issues to non-technical business clientsExcellent written skills with demonstrated ability to write reports and proposals. Including the ability to discuss findings from a risk perspective with clear remediation advice specific to the client's environment.Experience in one or more of the following:Reverse engineeringWeb ApplicationsAPI's and MicroservicesExploit DevelopmentApplication vulnerability assessmentMainframe systemsMobile platforms (iOS/Android/Windows/etc)Social EngineeringEndpoint protectionPractical exposure to security appliances such as firewalls, proxies, NIPS/HIPS and network security applicationsWorking knowledge of web concepts such as Ajax, XML, SOAP, and WS-SecurityFamiliarity with the Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP) and National Institute of Standards and Technology (NIST) Special Publications.Familiarity with penetration testing and vulnerability tools such as Cobalt Strike, Kali Linux, dsniff, nessus, nmap, MetaSploit, CoreImpact, Qualys, tcpdump, wireshark, Nikto, Aircrack-ng, Hailstorm, Burp Suite, etc.Strong programming experience with Visual Basic and C/C++ or Java languagesNetworking: LAN, WAN, interworking technologiesGood understanding of IaaS environments like Azure, AWS and GCPWhy Deloitte?At Deloitte, we focus our energy on interesting and impactful work. We're always learning, innovating and setting the standard; making a positive difference to our clients and our society. We put coaching at the heart of what we do, helping our people grow their careers in any direction - whether it be up, moving into something new, or even moving across the world.We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone's perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong.We prioritise flexibility and choice. At Deloitte, you get trust on Day 1. We know our people get their best work done when they're in control of where and how they work, designing their work week around their client, team and personal commitments.We help you live and work well. To support your personal and professional life, we offer a range of , including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.Next Steps Sound like the sort of role for you? Apply now.By applying for this job, you'll be assessed against the Deloitte Talent Standards. We've designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.