Our client is a high-profile Australian Government organisation responsible for protecting Australia’s national interests against sophisticated global and cyber threats. Operating within a highly secure and technically complex environment, the organisation delivers critical intelligence, cyber security and security capabilities that support the Australian Government.
This is an opportunity to contribute to nationally significant work while collaborating with experienced cyber security and technical professionals.
About the Role
The Lead Penetration Tester will assess complex ICT systems, applications and gateway infrastructure to identify configuration weaknesses, security vulnerabilities and faults that could affect organisational security and operations.
Operating at CIISEC Level 5, you will conduct complex penetration testing with a high degree of independence and may lead teams undertaking sophisticated testing engagements and simulated attack exercises.
Key responsibilities will include:
- Conducting penetration testing across ICT applications and gateway infrastructure
- Using commercial and bespoke penetration testing tools, techniques and frameworks
- Leading or contributing to complex penetration testing engagements
- Participating in simulated attack exercises under appropriate direction
- Developing detailed penetration test plans, procedures and testing methodologies
- Identifying configuration weaknesses, technical vulnerabilities and security faults
- Safely validating vulnerabilities through controlled exploitation techniques
- Recording testing approaches, techniques, evidence and results
- Producing clear and comprehensive penetration testing reports
- Recommending practical technical solutions for identified vulnerabilities
- Communicating findings and remediation priorities to technical stakeholders
- Supporting improvements to network, application and infrastructure security
The Successful Candidate
The successful candidate will be an experienced penetration testing professional with demonstrated capability to independently deliver complex security testing engagements or lead teams performing advanced penetration tests.
You will bring demonstrated experience in:
- Conducting complex penetration tests across ICT systems and applications
- Testing gateway infrastructure and identifying network security weaknesses
- Using commercial and bespoke penetration testing tools
- Applying contemporary penetration testing frameworks and techniques
- Developing structured test plans, procedures and testing approaches
- Conducting controlled exploitation and simulated attack activities
- Accurately documenting testing methods, evidence and outcomes
- Producing detailed reports with practical remediation recommendations
- Explaining technical vulnerabilities and business impacts to stakeholders
- Operating effectively within highly secure or classified environments
- Working independently while contributing to broader cyber security objectives
- Leading or supporting technical teams during complex testing engagements
Relevant certifications may include:
- CHECK Team Leader
- CREST Certified Tester for Infrastructure
- CREST Certified Tester for Web Applications
- Comparable advanced penetration testing or offensive security certifications
Candidates must also be willing to undergo an Organisational Suitability Assessment (OSA) prior to engagement.
Why partner with Whizdom?
We’re Whizdom. We view you as an extension of our strong, dependable brand and have differentiators which really are different! The Whizdom way:
- We pay our contractors same day you submit your timesheet!
- We are Level 3, DISP certified and have signed the Veteran Employment Commitment and been awarded the highest level of compliance to this important initiative, proactively assisting veterans transitioning from the forces to civilian roles. We’ve been lucky enough to win industry awards for our high level of process compliance and are ISO 9001 certified. Our commitment to reducing Greenhouse Gas Emissions has been accredited in line with large global organisations.
- We value diversity and welcome applications from Indigenous Australians, people from diverse cultural and linguistic backgrounds and people living with a disability.
Location: The role is based in Canberra ACT.
Contract terms: 12 months from commencement date, plus 2x 12 month extensions
Experience Level: EL1 Equivalent
Security Requirements: Candidates must hold an active or reactivatable Top Secret Positive Vetting (TSPV) Security Clearance on submission. Our client is not looking to upgrade an existing clearance for this position. An OSA(Organisational Suitability Assessment) will be required for this position.
How to Apply: Please upload your resume to apply. Please note you will need to complete selection criteria to complete this application process. We will be in touch with instructions for suitably skilled candidates.
Candidates will need to be willing to undergo pre-employment screening checks which may include, ID and work rights, security clearance verification and any other client requested checks.
Applications open until 8am 24 September 2026.
Reach Damien on 0480 002 503 or damienm@whizdom.com.au for any further information.


