Senior Penetration Tester - Wellington based
Ready to join a team built on excellence?
At Bastion, our international team of cyber security experts deliver world class results, with industry leading tools, and a commitment to end to end protection of our clients, from our offices in Wellington and Auckland. This role is based in Wellington.
As a Senior Penetration Tester, you will take charge on testing of client applications and environments, solve complex problems, and discuss real world impacts with key stakeholders.
Our Offensive Security Services (OSS) team is integral to the successful running of our busy cybersecurity consultancy with offices in New Zealand and Australia.
The role
This is a fast-paced and varied role, working closely with an exciting range of clients across New Zealand and afar, from small kiwi-owned businesses to well-known public sector organisations.
The main responsibilities of the role are:
- Lead client engagements and projects through their full lifecycle.
- Web application penetration testing, network penetration testing, mobile application penetration testing, cloud security reviews, source code reviews, and general security consulting.
- Produce high-quality reports that highlight issues that you identify.
- Debrief clients on projects you manage.
- Nurture and grow our client base
Benefits of working for Bastion
You will work alongside an expert group of consultants and penetration testers who are dedicated to protecting others from cyber harm. The perks of being part of the Bastion team include:
- A collaborative, thoughtful team who do meaningful work and keep learning
- A supportive work environment, great team culture and regular social events
- Training budget, study time allowance, regular internal training sessions and internal mentor programme
- Competitive remuneration
- Half yearly bonus scheme
- Additional leave after 2 years
- Access to a gym within a short walk of the office.
About us
Bastion Security Group provides best-in-class cybersecurity services through a high-performance culture built on quality, excellence and collaboration. Our skilled and empowered team is dedicated to achieving meaningful security outcomes and delivering lasting value for our clients.
‘Assess & Improve’, ‘Detect & Respond’, ‘Protect & Secure’, ‘Advise & Empower’ and stay ahead of evolving threats.
We deliver security services across strategy, architecture, operations and compliance. Whether it’s advising on board-level risks, embedding into your teams, or responding to incidents, our experts provide actionable insight grounded in real threats and real solutions.
To learn more about our New Zealand operation, visit Bastion Security
Our Australian offices - Cythera; Seamless Intelligence; Phronesis Security; Astralas
Who we’re looking for
A results-focused, high performer across the security testing services domain, who can add exceptional value to the clients we work with. Ideally, you are already based in Wellington, with a permanent right to work or a valid work visa.
Someone supportive and collaborative, assisting others through their technical journey, whilst also keeping up to date and getting involved in research and tooling yourself.
These are the main skills and experience we’re looking for:
- 2-5 years’ experience in the security industry.
- Strong knowledge of information security.
- You’re at home with penetration testing tools and methodologies. You might hold security certifications such as OSCP, OSCE, CREST, GPEN, GWAPT, GXPN, or GMOB OWSE, though this is not essential.
- Skilled at analysing information, asking questions, and solving problems.
- You manage your time effectively, take ownership of projects or tasks to deliver work on time, and use your initiative to get stuff done!
- Confidently communicate your knowledge to a range of people, whether presenting, on the phone, or writing a report or email.
- Previous experience advising clients within public and enterprise sectors.
(Note this is not an opportunity for a new graduate)
Due to the nature of our work, this role requires a clean criminal record. Successful applicants will be required to complete a criminal record check during the onboarding process.
Great things to include in your cover letter include:
- Attended or presented at a security conference.
- Published any vulnerabilities (especially if CVEs assigned).
- A security blog that you post on.
- Participating in Capture-the-Flag events.
- Developing and maintaining penetration testing methodologies.
- GitHub account to showcase code.
- Your own security tools.
- Participation in bug bounties on the Hackerone or Bugcrowd platforms.
Apply today
If you have the desire to help us deliver excellence for our clients, we want to hear from you.
Apply now via Seek and yes, we do read your cover letter. We want to read about how joining our team will add value to your career path and why you decided to apply for our specific role.
We'll be reviewing applications on an ongoing basis as they come in, and depending on application volume, may close the advert early. If this is your ideal next role, we'd encourage you to get in touch today!
For a confidential conversation, email Tracy at [email protected].