{"id":1133366,"url":"https://alion.io/job/rest-application-security-analyst-18-month-fixed-term-contract","title":"Application Security Analyst - 18 Month Fixed Term Contract","company":{"id":695623,"name":"Rest","domain":"rest.com.au","url":"https://alion.io/company/rest-5","size_band":"201-500","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"SmartRecruiters","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":"contractor","work_mode":"hybrid","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Sydney, Australia"],"countries":["AU"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":76000,"max_usd":199000,"period":"year","method":null,"sample_n":2443},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"CI/CD","optional":false},{"name":"NIST CSF","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP ASVS","optional":false},{"name":"OWASP SAMM","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Rest API","optional":false}],"status":"live","first_seen_at":"2026-09-23T02:28:22Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-23T05:05:25Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"We’ve been around since 1988, and today we’re one of Australia’s largest profit-to-member super funds.\nThat means everything we do is focused on delivering better outcomes for our members - not shareholders.\nClosing date: 30th September 2026\nPlease note Rest does not accept speculative resumes from recruitment agencies\nRest will review applications prior to the closing date and may close the role earlier \n Shape and strengthen application security across Rest, one of Australia's largest profit-to-member super funds\nDrive secure-by-design practices across modern cloud, API and DevSecOps environments\nPartner with engineering, architecture and product teams to improve security outcomes at scale\nSydney or Melbourne Located - Hybrid Working - Blend of CBD Office and Remote\nAt Rest, we help more than 2 million Australians to build a better financial future. With around $112 billion in funds under management, we focus on delivering strong long-term outcomes for our members - from their first job through to retirement*. Your best at Rest means focusing on what matters, being trusted to get on with it, and knowing your work genuinely makes a difference. That’s how we operate every day, guided by our values: Be Daring, Keep It Simple, Take Action and Have Grit.\nJoin us as an Application Security Analyst on an 18 Month Fixed Term Contract. This is your opportunity to make a real contribution to the financial wellbeing of millions of Australians.\nAbout the role\nAt Rest, we're committed to helping our members achieve a better retirement. As our Application Security Analyst, you'll play a critical role in strengthening the security of our applications, APIs and software delivery practices.\nWorking closely with engineering, architecture, product and technology teams, you'll lead application security initiatives, embed security into the development lifecycle, and provide pragmatic, risk-based guidance that supports secure delivery and innovation.\nWhat you'll do\nLead application security assessments across web applications, APIs and cloud-based services, identifying risks and recommending appropriate treatment plans.\nPartner with engineering and architecture teams to embed security into solution design through threat modelling and secure-by-design practices.\nValidate, prioritise and manage application security findings, providing risk-based remediation guidance and distinguishing genuine risks from false positives.\nDrive the effectiveness and continuous improvement of application security tooling, including SAST, DAST, SCA, API security testing and secrets detection.\nPromote secure SDLC and DevSecOps practices, integrating security controls into CI/CD pipelines and software delivery processes.\nCoordinate penetration testing activities, validate findings and oversee remediation outcomes.\nDevelop and maintain application security standards, guardrails and secure development practices.\nProvide security guidance, education and enablement to developers, engineers and security champions.\nSupport security incident investigations where application vulnerabilities or insecure design may be contributing factors.\nDeliver application security reporting, metrics and insights, highlighting emerging risks, remediation performance and overall security posture.\n Bachelor's degree in computer science, Information Technology, or a related field (relevant work experience may be considered).\nRequired experience, understanding or credentials including:\nExperience in application security, DevSecOps or secure software development within a complex enterprise environment, together with:\nExperience conducting application security assessments across web applications, APIs and cloud-native environments.\nStrong knowledge of OWASP Top 10, secure coding principles, threat modelling, vulnerability management and secure SDLC practices.\nHands-on experience with application security tools including SAST, DAST, SCA, API security testing and secrets detection.\nKnowledge of application security assurance frameworks and standards such as OWASP ASVS, OWASP SAMM, NIST CSF and APRA CPS 234.\nUnderstanding of CI/CD pipelines, software delivery practices and cloud platforms, ideally AWS.\nFamiliarity with modern application architectures, including APIs, microservices and cloud-native environments.\nAwareness of software supply chain risks, open-source dependency management and security considerations for AI-enabled solutions.\nStrong analytical and communication skills, with the ability to translate technical findings into clear, practical recommendations.\nExperience partnering with developers, engineers, architects and delivery teams to improve security outcomes while supporting business objectives.\nRelevant security certifications are welcomed but not essential.\nWhy Rest?\nAt Rest, you'll be part of a collaborative and inclusive culture where your work has meaningful impact. You'll have the opportunity to influence how security is embedded across our technology landscape while helping protect the services and experiences our members rely on every day.\n .What you'll find at Rest\nHybrid working\n5 Rest Days (wellbeing days) each year in addition to annual leave\nEligible employees are entitled to 22 weeks paid parental leave (gender neutral)\nContinued super contributions during parental leave\nLearning and development opportunities, including AI & Data Academy, leadership programs, LinkedIn Learning, study assistance and professional memberships\nIncome Protection Insurance\nOption to purchase additional leave\nRecognition through our Rest Excellence Awards\nIf you share our values and this sounds like the kind of place you’d do your best work, we’d like to hear from you. Apply now.\nRest is committed to creating a flexible work environment and culture that embraces diversity, equity, and inclusion - where people feel welcome, safe to be themselves and inspired to do their best.\nWe value the different backgrounds, lived experiences and abilities our diverse team brings. We welcome and encourage applications from candidates of all ages, cultural backgrounds, faiths, gender identities, sexual orientations and thinking styles. This includes people with disability, neurodiverse individuals, Aboriginal & Torres Strait Islander peoples and those with disrupted work history due to career or other breaks.\nWe welcome applications from all candidates. To be considered, you will need the right to work in Australia.\n*Funds under management as at 30 June 2026. Rest is recognised as a superannuation leader across a range of areas including performance, responsible investment and member value. Find out more at https://rest.com.au/why-rest/awards.","description_format":"text","description_chars":6685,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Annual leave","Equity","Flexible schedule","Hybrid work","Parental leave"],"hiring_locations":[{"name":"Australia","iso":"AU","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security"],"lifecycle":[{"event":"open","at":"2026-09-23T05:05:25Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":0,"expected_fill_days":32,"reasons":["conf:0","velocity","win:early"],"computed_at":"2026-09-23T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/rest-application-security-analyst-18-month-fixed-term-contract","json_url":"https://alion.io/job/rest-application-security-analyst-18-month-fixed-term-contract.json","meta":{"generated_at":"2026-09-23T13:54:35Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}