À propos de ce poste Offensive Security Consultant chez Triskele Labs
Triskele Labs is seeking an experienced offensive security consultant (penetration tester) to join our Offensive Security practice. We are an Australian-owned and operated cyber security firm delivering sovereign security services to clients across Australia, including managed detection and response, digital forensics and incident response, offensive security, and governance, risk and compliance services.
Our Offensive Security team operates within a CREST-accredited environment, providing clients with confidence that engagements are delivered to recognised industry standards by skilled consultants using mature, repeatable methodologies. This role is suited to someone who values technical excellence, trusted client relationships, and contributing to a sovereign Australian cyber security capability.
The Offensive Security Consultant will deliver penetration testing engagements end to end, from set-up and information gathering, execution, through to reporting and close-out. You will test web applications, APIs, mobile applications, thick client applications, internal and external infrastructure, cloud environments, wireless networks, and modern attack surfaces, working to established methodologies and recognised industry frameworks. You will manage client communication throughout each engagement and produce reports that are accurate, practical, and useful to both technical and executive audiences.
Requirements
Key Responsibilities:
- Execute penetration tests across web, mobile, thick client applications and APIs, internal and external infrastructure, cloud environments, AI/LLM systems, and wireless networks.
- Contribute to red team, purple team, adversary simulation, and social engineering engagements.
- Produce comprehensive engagement reports detailing vulnerabilities, impact, technical detail, risk ratings, remediation complexity, and recommendations.
- Contribute to the continual improvement of testing methodologies, standard operating procedures, and internal tooling.
- Maintain current knowledge of security threats, tooling, standards, and frameworks.
Essential Qualifications & Skills:
- A minimum of two years conducting penetration tests in a consulting or professional services environment, or demonstrable equivalent capability.
- OSCP certification, or an equivalent hands-on offensive security certification.
- Demonstrated capability across at least three service streams, such as application testing, infrastructure testing, social engineering, cloud security, offensive security operations, and configuration reviews.
- Working proficiency with at least one scripting language.
- Sound technical knowledge of networking, Windows and Linux operating systems, and common enterprise security controls.
- Strong written communication, with the ability to produce client-ready reports that require minimal revision.
- Tertiary qualification in information security or a related information technology field, or demonstrable equivalent experience.
- Full Australian working rights.
- Willingness to undergo police checks and obtain a security clearance where required.
Desirable Qualifications & Skills:
- Advanced offensive security certifications.
- CREST Registered Tester (CRT), or the willingness and ability to achieve CRT within twelve months of commencement.
- Hands-on experience with red teaming, adversary simulation, purple team exercises, source code reviews, and social engineering.
- Experience with AI tools, AI and LLM security testing, Hardware, OT & IoT Penetration Testing
- Tool development, published research, CVEs, conference presentations, or bug bounty and CTF results.
Benefits
Team culture is central to Triskele Labs and is one of the reasons we exist. We are a forward-thinking company that continually looks for ways to strengthen our culture and ensure we remain a destination employer. We regularly seek feedback from our team on how we can improve the work environment and team member experience at Triskele Labs.
We provide our team with a range of additional benefits, including:
- Commitment to training and development.
- Access to a professional external Employee Assistance Program (EAP).
- Social functions organised by our People & Culture Team.
- Enjoy a brand-new office located in the heart of Melbourne CBD.
- Access to salary packaging options, novated leasing, and other benefits available through Triskele Labs’ employee benefits program.
Application Requirements:
- Include both a CV and a cover letter addressed to Sarath Nair, Head of Offensive Security, to be considered for this role.
Working Arrangements:
- Work full-time, Monday to Friday, with hybrid and flexible arrangements. Out-of-hours work may be required to accommodate client change windows, and interstate travel may be required for onsite engagements.