660,302open jobs
38,440companies
97,349added this week
Browse all
Salary
$107k – $257k per year (Estimated)
Location
Remote/Hybrid (Sydney, Australia)
Seniority
Senior
Employment
Contractor
Overview
Company
Impact
Profile match
NCS Australia is the Australian arm of the Singapore technology services group NCS, itself owned by Singtel, and it was assembled from 2021 onwards through the acquisitions of ARQ Group, Eighty20 Solutions, Riley and several other local firms. It delivers cloud and platform engineering, data and artificial intelligence, cybersecurity, application development and managed services to Australian government agencies, banks, telecommunications operators and utilities. Headquartered in Sydney with offices across the eastern states, it employs several thousand people and competes against the global integrators for federal and state government work.

At NCS Australia, we believe in doing technology services better. Our commitment to quality, focus on people, and willingness to challenge traditional thinking set us apart. Our team brings this belief to life by partnering with our clients and communities to make tomorrow together.

We are committed to creating an environment that prioritises innovation, collaboration, and purposeful work. Our diverse team is empowered to make a meaningful impact with curiosity, creativity and resilience to shape better outcomes. Join us and accept the challenge of creating a better tomorrow.

We are seeking a highly specialized Lead DevSecOps & AI Security Specialist to bridge business analysis, security architecture, and hands-on application security tooling across our enterprise software delivery pipelines.

This role is ideal for a senior practitioner who combines the technical capability of a DevSecOps Subject Matter Expert (SME) with the analytical depth to drive security standards, AI-driven governance, and end-to-end policy implementation at scale.

Core Focus Areas

1. DevSecOps SME & Code Scanning Implementation

  • Hands-on Tooling Roll-Out: Lead the end-to-end implementation, configuration, and integration of code scanning platforms across the enterprise-going beyond operational usage to build the toolchain architecture from the ground up.

  • Security Testing Standards: Define, implement, and enforce SAST, SCA, and DAST scanning standards directly within automated CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Azure DevOps).

  • Operational Rules & Triage: Establish baseline scanning rulesets, triage workflows, vulnerability remediation SLAs, and false-positive reduction strategies for development squads.

2. AI-Driven DevSecOps Governance

  • AI Security Architecture: Pioneer and implement DevSecOps governance frameworks and security guardrails utilizing AI capabilities and LLM tools.

  • Automated Enforcement: Establish automated policy enforcement, AI-assisted code remediation guidance, and smart threat modeling workflows for software engineering teams.

  • AI Tooling Standards: Define policies and standards for secure AI deployment, AI code-assistant usage, and data privacy governance within modern development environments.

3. Technical Business Analysis & Delivery

  • Requirements & Governance: Translate complex application security, compliance, and regulatory requirements into actionable user stories, engineering epics, and implementation roadmaps.

  • Cross-Squad Collaboration: Work closely with software engineers, security architects, DevOps specialists, and product leaders to embed security seamlessly into the SDLC.

  • Runbooks & Metrics: Develop operational runbooks, technical governance documentation, and metrics dashboards to monitor platform adoption, pipeline health, and overall security posture.

Essential Skills & Experience:

  • Proven DevSecOps Implementation: Demonstrated track record of implementing and deploying (not just using) enterprise SAST, SCA, and DAST tooling (e.g., Checkmarx, SonarQube, Veracode, Snyk, Fortify, or OWASP ZAP).

  • AI Security & Governance: Practical experience leveraging AI/LLM technologies to enhance DevSecOps governance, automated code review, or security policy enforcement.

  • Business Analysis Capability: Strong BA background with demonstrated experience writing technical requirements, mapping workflows, and defining security standards for enterprise delivery teams.

  • CI/CD Pipeline Integration: Deep experience embedding automated security scanning stages into modern CI/CD systems.

  • Communication & Stakeholder Management: Excellent communication skills with the ability to influence engineering culture, articulate security risks, and drive adoption across cross-functional squads.

Why NCS?

This is a place for people who like to get stuck in, bring ideas to life and make things happen. You'll work alongside experienced people who care about what they do, contribute to meaningful work and have the support to keep learning and grow your career. Whether you want to deepen your expertise, explore something new or take your career in a different direction, there's room to make it your own. We value Adventure, Excellence, Integrity, Ownership and Unity - bringing curiosity, collaboration and accountability to the way we work with our clients and each other.

Ready to make extraordinary happen?

We'd love to hear from you.

We celebrate diversity and inclusion

We value different perspectives, experiences and strengths our people bring. We're committed to an inclusive workplace where everyone has the opportunity to contribute, grow and succeed, and to providing equal employment opportunities and reasonable adjustments throughout the recruitment process.

Important information

Applicants will need valid Australian work rights and may be required to undergo relevant background, probity and police checks.

Agencies: NCS accepts candidate submissions only from agencies on our preferred supplier panel through the NCS Agency Portal.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
660,302 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sydney
$27k – $57k per year (Estimated) • In office • 3+ years exp • Moscow
Python
Databases
PostgreSQL
Redis
ClickHouse
Apache Kafka
DevOps
Terraform
Ansible
Helm
Jaeger
Prometheus
VictoriaMetrics
GitLab CI
CI/CD
GitOps
ArgoCD
Kubernetes
Grafana
SLI/SLO/SLA
Amazon S3
Cybersecurity
Kyverno
Apply
$28k – $73k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Pune
JavaScript
SQL
C#
Visual Basic
C#
ASP.NET Core
WPF
Databases
Db2
AI/ML
Copilot
Prompt Engineering
RAG
OpenAI
Mobile
MAUI
DevOps
Azure DevOps
Azure
CI/CD
GitHub
Apply
$15k – $33k per year (Estimated) • Remote/Hybrid • 3+ years exp • Saint Petersburg
Python
DevOps
GitLab CI
CI/CD
Jenkins
Git
Game Dev
Unity
Unreal Engine
QA
Appium
Pytest
XCUITest
Apply
In office • Full-Time • Sydney • Melbourne
JavaScript
Java
Kotlin
TypeScript
C#
Node JS
Swift
Objective-C
C#
.NET
Frontend
Next.js
React.js
Mobile
Combine
DevOps
Terraform
GitHub Actions
CloudFormation
CI/CD
AWS
Apply
$15k – $43k per year (Estimated) • In office • Bachelor's Degree • Minsk
Python
Bash
DevOps
Prometheus
CI/CD
Jenkins
Docker
Kubernetes
Grafana
GitLab
Apply
$88k – $199k per year (Estimated) • Remote/Hybrid • Contractor • Bachelor's Degree • Sydney
DevOps
Rest API
Cybersecurity
Okta
Auth0
Management
Confluence
Agile
Apply
$62k – $137k per year (Estimated) • In office • Full-Time • Sydney
Apply
$103k – $216k per year (Estimated) • Remote/Hybrid • Contractor • Sydney
Cybersecurity
Okta
Ping Identity
Auth0
Apply
$83k – $193k per year (Estimated) • Remote/Hybrid • Contractor • Sydney
Management
Agile
Apply
$88k – $205k per year (Estimated) • Remote/Hybrid • Contractor • Sydney
Cybersecurity
Okta
Auth0
Management
Agile
Apply
$92k – $185k per year (Estimated) • Remote • 5+ years exp • Sydney
Apply
$46k – $93k per year (Estimated) • In office • Full-Time • 2+ years exp • Sydney
AI/ML
AI Agents
Marketing
Salesforce
LinkedIn
Apply
$82k – $179k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Sydney
Cybersecurity
GDPR
QA
Rest-Assured
Apply
$69k – $183k per year (Estimated) • Remote • Full-Time • Sydney
Python
Go
C++
Lua
C++
CMake
Databases
Aerospike
Cassandra
ActiveMQ
Apache Kafka
DevOps
gRPC
Docker
Kubernetes
Apply
$105k – $245k per year (Estimated) • Remote • Full-Time • 12+ years exp • Sydney
Apply
See all jobs
This is one of many
660,302 more open roles from verified company boards, updated every day.