997,024open jobs
59,481companies
165,643added this week
Browse all
Salary
≈ $76k – $212k per year (Estimated)
Location
Hybrid (Sydney, Australia)
Employment
Contractor

Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Sep 29, 2026.

Overview
Company
Impact
Profile match

We’ve been around since 1988, and today we’re one of Australia’s largest profit-to-member super funds.

That means everything we do is focused on delivering better outcomes for our members - not shareholders.

Closing date: 14 October 2026

Please note Rest does not accept speculative resumes from recruitment agencies

Rest will review applications prior to the closing date and may close the role earlier

  • Join a purpose-led organisation where your expertise contributes to protecting member data, platforms and digital experiences.

  • Twelve-month opportunity to make a visible impact while helping advance Rest's application security maturity.

  • Sydney CBD Office Location, Hybrid Working

At Rest, we help more than 2 million Australians to build a better financial future. With around $112 billion in funds under management, we focus on delivering strong long-term outcomes for our members - from their first job through to retirement*. Your best at Rest means focusing on what matters, being trusted to get on with it, and knowing your work genuinely makes a difference. That’s how we operate every day, guided by our values: Be Daring, Keep It Simple, Take Action and Have Grit.

Join us as an Application Security Engineer - CTEM on a 12 Month Fixed Term Contract. This is your opportunity to make a real contribution to the financial wellbeing of millions of Australians.

About the Role

Embed within API and Platform Engineering to strengthen its mature application security and engineering practices, then scale those practices across Data Engineering, Investment Engineering and Digital Engineering. Provide risk-based cross-functional support that ensures application security findings are prioritised, remediated and tracked through to validated closure.

Accountabilities/Responsibilities

  • Analyse and triage findings from SAST, DAST, SCA, secrets, API, container, infrastructure-as-code and other application security tooling, validating impact and identifying false positives, duplicates and systemic issues.
  • Prioritise application security findings using severity, exploitability, asset criticality, exposure and business context, aligned to the vulnerability management process.
  • Provide clear, practical remediation guidance and maintain end-to-end traceability between source findings, remediation tickets, accountable owners, due dates, exceptions and closure evidence.
  • Own and coordinate secure SDLC controls across design, development, testing, release and ongoing maintenance, including control requirements, implementation guidance, evidence expectations and effectiveness reviews.
  • Govern GitHub source-control security and application security integrations, including repository baselines, access reviews, branch protection, pull-request controls, code ownership, secrets protection, scanning, status checks, ticketing and exception handling.
  • Monitor and report remediation backlog health, risk and trends; escalate overdue or blocked work; validate completed remediation; update security records; and coordinate risk exemptions through approval, review and expiry.

Experience, skills and qualifications

  • Strong analytical capability and demonstrated experience triaging and prioritising application security findings.
  • Working knowledge of SAST, DAST, SCA, secrets, API, container and infrastructure-as-code scanning, together with OWASP Top 10, API Security Top 10, common CWEs and software supply-chain risks.
  • Experience defining, implementing and assessing secure SDLC controls across design, development, testing, release and ongoing maintenance.
  • Ability to translate technical findings into clear, actionable remediation guidance for engineering teams.
  • Experience with vulnerability management workflows, ticketing systems, backlog management, reporting and evidence-based closure.
  • Strong GitHub source-control security knowledge, including repository governance, access models, branch protection, pull-request controls, code ownership, GitHub security features and application security integrations.

.What you'll find at Rest

  • Hybrid working
  • 5 Rest Days (wellbeing days) each year in addition to annual leave
  • Eligible employees are entitled to 22 weeks paid parental leave (gender neutral)
  • Continued super contributions during parental leave
  • Learning and development opportunities, including AI & Data Academy, leadership programs, LinkedIn Learning, study assistance and professional memberships
  • Income Protection Insurance
  • Option to purchase additional leave
  • Recognition through our Rest Excellence Awards

If you share our values and this sounds like the kind of place you’d do your best work, we’d like to hear from you. Apply now.

Rest is committed to creating a flexible work environment and culture that embraces diversity, equity, and inclusion - where people feel welcome, safe to be themselves and inspired to do their best.

We value the different backgrounds, lived experiences and abilities our diverse team brings. We welcome and encourage applications from candidates of all ages, cultural backgrounds, faiths, gender identities, sexual orientations and thinking styles. This includes people with disability, neurodiverse individuals, Aboriginal & Torres Strait Islander peoples and those with disrupted work history due to career or other breaks.

We welcome applications from all candidates. To be considered, you will need the right to work in Australia.

*Funds under management as at 30 June 2026. Rest is recognised as a superannuation leader across a range of areas including performance, responsible investment and member value. Find out more at https://rest.com.au/why-rest/awards.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
997,024 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Sydney
$85k – $95k per year • Hybrid • Full-Time • Bachelor's Degree • Sydney
DevOps
Azure
AWS
Cybersecurity
ISO 27001
NIST 800-53
Apply
≈ $73k – $203k per year (Estimated) • Hybrid • Sydney
PowerShell
DevOps
Azure
Cybersecurity
CyberArk
Microsoft Entra ID
Delinea
Active Directory
Apply
≈ $103k – $233k per year (Estimated) • In office • Full-Time • 5+ years exp • Australia
Apply
≈ $102k – $230k per year (Estimated) • In office • Full-Time • Australia
Java
Java
Apache Tomcat
Databases
MySQL
DevOps
Azure
CI/CD
AWS
Kubernetes
Unix
Cybersecurity
Active Directory
Apply
≈ $96k – $217k per year (Estimated) • In office • Full-Time • Richmond
DevOps
CI/CD
AWS
Cybersecurity
ISO 27001
PCI DSS
SOC 2
Apply
$160k – $175k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Frisco
Python
JavaScript
AI/ML
Prompt Engineering
LLM
OpenAI
Frontend
GraphQL
DevOps
Rest API
Terraform
Jenkins
Git
AWS
AWS Lambda
Amazon S3
Amazon CloudWatch
API Gateway
SOAP
Management
Power Apps
QA
Postman
Apply
≈ $15k – $25k per year (Estimated) • Hybrid • 2+ years exp • Moscow
DevOps
GitHub
Management
Telegram
Marketing
LinkedIn
Apply
$102k – $179k per year • In office • Full-Time • Irving • Chicago
SQL
Databases
PostgreSQL
Databricks
AI/ML
Knowledge Graph
DevOps
Azure
CI/CD
Docker
Kubernetes
Platform Engineering
Azure AKS
Linux
Apply
≈ $16k – $37k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Taguig
Python
JavaScript
PowerShell
DevOps
Rest API
Azure
IAM
SOAP
Cybersecurity
Okta
CyberArk
GDPR
HIPAA
Active Directory
LDAP
Apply
≈ $67k – $161k per year (Estimated) • In office • Full-Time • Manchester
Java
TypeScript
C++
DevOps
CI/CD
AWS
Ubuntu
GitHub
Linux
Unix
Apply
≈ $74k – $207k per year (Estimated) • Hybrid • Contractor • Bachelor's Degree • Sydney
DevOps
Rest API
CI/CD
AWS
Cybersecurity
NIST CSF
OWASP Top 10
OWASP ASVS
OWASP SAMM
OWASP
Apply
≈ $71k – $199k per year (Estimated) • Hybrid • Contractor • Sydney
PowerShell
DevOps
Rest API
Windows
Cybersecurity
CIS Benchmarks
Microsoft Entra ID
SIEM
Apply
≈ $75k – $207k per year (Estimated) • Hybrid • Full-Time • Sydney
Python
DevOps
Rest API
GCP
GitHub Actions
CloudFormation
Azure
CI/CD
Git
AWS
IAM
Cybersecurity
ISO 27001
SIEM
Apply
≈ $92k – $217k per year (Estimated) • Hybrid • Part-Time • Sydney
DevOps
Rest API
Management
Confluence
Agile
Waterfall
Apply
Hybrid • Contractor • Sydney
Python
JavaScript
TypeScript
Node JS
DevOps
Rest API
GitHub Actions
CI/CD
Platform Engineering
GitHub
Cybersecurity
OWASP Top 10
Apply
≈ $104k – $235k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Sydney
DevOps
AWS
Incident Management
Management
ITIL
Apply
≈ $89k – $211k per year (Estimated) • In office • Full-Time • Sydney
JavaScript
PowerShell
C#
AI/ML
Copilot
Copilot Studio
Management
Power Automate
Power Apps
Microsoft Teams
OneDrive
SharePoint
Agile
ITIL
Apply
$52k – $66k per year • In office • Full-Time • 3+ years exp • Sydney
AI/ML
AI Agents
Marketing
Salesforce
LinkedIn
Apply
≈ $52k – $135k per year (Estimated) • In office • Full-Time • Sydney
Apply
≈ $43k – $109k per year (Estimated) • In office • Contractor • 2+ years exp • Sydney
Python
SQL
SAS
Analytics
Power BI
Apply
See all jobs
This is one of many
997,024 more open roles from verified company boards, updated every day.