{"id":1521357,"url":"https://alion.io/job/nrma-offensive-security-engineer","title":"Offensive Security Engineer","company":{"id":1993099,"name":"NRMA","domain":"mynrma.com.au","url":"https://alion.io/company/mynrma","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Schema","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Sydney, Australia"],"countries":["AU"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":75000,"max_usd":207000,"period":"year","method":null,"sample_n":2929},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"ISO 27001","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"PCI DSS","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false}],"status":"live","first_seen_at":"2026-08-19T04:49:34Z","employer_posted_date":"2026-08-19","last_verified_at":"2026-09-30T22:22:03Z","board_verified":true,"closed_at":null,"days_open":42,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":42},"description":"Company Description\nWe’re one of Australia’s most trusted brands. Being Member-owned, every decision we make has people and our community at its heart. From our legendary Roadside assistance to electric vehicle charging networks, holiday parks and lodges, car rentals, harbour transport, and ocean cruising we are striving to make a difference that contributes to a brighter shared future for all Australians.\nForget what you thought you knew about the NRMA - take a look on the inside and you’ll discover that life with us is more than just a job - it’s your chance to make a difference together.\nJob Description\nWe have an exciting opportunity for an Offensive Security Engineer to join our Technology team based in Sydney Olympic Park. This role plays an important part in protecting the confidentiality, integrity, availability and resilience of NRMA technology and data by identifying exploitable weaknesses before they cause harm, validating the effectiveness of security controls, and supporting safer delivery across our technology environment.\nReporting to the Senior Manager, Security Compliance & Governance, you’ll work closely with engineering, cloud, platform, infrastructure, architecture and security teams to embed security early in the software development lifecycle, reduce vulnerabilities reaching production, and provide evidence-based assurance across applications, APIs, cloud environments and security controls.\nThis is a hands-on role for someone who enjoys practical security testing, automation, threat emulation, vulnerability lifecycle management and working with technical teams to improve security outcomes in a complex enterprise environment.\nThis 9-12 month maximum term contract role offers a hybrid work arrangement across our Sydney Olympic Park, Sydney CBD offices and working from home, as agreed and required for the role.\nWhat You’ll Do\nPlan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services and cloud-hosted workloads.\nOperate, administer and optimise security testing platforms, including SAST, DAST, CSPM and attack simulation tooling.\nEmbed security testing early in the software development lifecycle and support secure development practices across engineering teams.\nIntegrate application security, dependency, open-source risk, DAST and API security testing controls into code repositories, IDEs and CI/CD pipelines.\nConduct authorised penetration testing, technical security assessments, security design reviews and threat modelling for material changes.\nValidate, triage and document security findings, including severity, business impact, accountable owners, target remediation dates and closure evidence.\nTrack remediation progress, retest resolved vulnerabilities and escalate overdue or material findings where required.\nUse cloud security posture management tooling to assess cloud vulnerabilities, misconfigurations, attack paths and compliance posture.\nConduct MITRE ATT&CK-aligned control validation, adversary emulation and purple team activities across key security controls.\nProvide practical remediation advice to engineering and technology teams, including guidance aligned to OWASP Top 10, PCI DSS secure coding requirements and secure AI development practices.\nAutomate repeatable discovery, testing, ticketing, evidence collection, reporting, remediation tracking and validation activities where practical.\nProduce evidence-based reports, service metrics and control-effectiveness insights to support operational, executive, audit and governance reporting.\nWhat You’ll Bring\nExperience in cybersecurity, application security, penetration testing, security engineering or DevSecOps.\nStrong knowledge of web application, API and cloud security.\nHands-on experience with security testing tools such as SAST, DAST and CSPM platforms.\nUnderstanding of secure software development and CI/CD environments.\nExperience identifying, validating and remediating security vulnerabilities.\nKnowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST and PCI DSS.\nAbility to automate tasks using scripting languages such as Python or PowerShell.\nStrong analytical and problem-solving capabilities.\nExcellent stakeholder engagement and communication skills.\nAbility to provide practical, risk-based security advice to technical and business teams.\nRelevant cybersecurity qualifications, certifications or equivalent industry experience.\nA passion for emerging security technologies, automation and continuous improvement.\nWhat's in it for you?\nAt the NRMA we aren’t just about discounts (although you do get these too). We offer benefits to help make work and life just right for you!\nProgressive flexibility, leave and well-being benefits to balance all of life's priorities\nTravel discounts on SIXT car rental, cruises, and accommodation at our award-winning NRMA Holiday Parks and Resorts\nComplimentary myNRMA Rewards membership including free Roadside Assistance & discounts on groceries, movie tickets, gift cards, gym memberships, attractions, restaurants and much more\nDiscounts on a range of NRMA personal insurance products including car, home & travel\nGrow, progress or relocate your career and move around the NRMA Group or different locations with us.\nKnow you belong\nWe’re for inclusion, diversity and representing the members, guests, customers and communities we serve. That’s why we welcome applications from First Nations, people with disability, those from diverse cultural backgrounds, people of all genders, members of the LGBTQI+ community, and anyone else who wants to be a part of our team.\nJoin the NRMA and grow your career with us. Apply now, we cannot wait to hear from you or visit our careers site to find out more!\nOur Talent Acquisition Team and Hiring Leaders kindly request no unsolicited resumes or approaches from Recruitment Agencies. The NRMA is not responsible for any fees related to unsolicited resumes.","description_format":"text","description_chars":5996,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Gym membership","Hybrid work"],"hiring_locations":[{"name":"Australia","iso":"AU","kind":"country"}],"hiring_excludes":[],"relocation_offered":true,"industries":["Penetration Testing","Application Security"],"lifecycle":[{"event":"open","at":"2026-09-30T11:59:19Z"}],"liveness":{"score":17,"band":"cold","label":"Long shot","p_open":1,"p_active":0.488,"p_room":0.35,"age_days":42,"expected_fill_days":21,"reasons":["conf:2","win:tail"],"computed_at":"2026-10-01T00:56:34Z"},"pay":null,"html_url":"https://alion.io/job/nrma-offensive-security-engineer","json_url":"https://alion.io/job/nrma-offensive-security-engineer.json","meta":{"generated_at":"2026-10-01T00:56:34Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":667,"day_limit":5000,"remaining_today":4333,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}