Offensive Security Engineer

  • Hybrid
  • Sydney (AU)
  • 37.5 hours
  • Full time
Apply
  • Change Agility
  • Cloud Computing
  • Customer-Focused
  • Digital Literacy
  • Disciplined Execution
  • Distributed Systems
  • Information Technology Security
  • Information Technology Strategies
  • Problem Management
  • Solution Architecture
  • Technology Landscape

This match does not affect your application. It is purely an indication of whether this vacancy matches your skills.

About Us

Rabobank is the world’s leading specialist in food & agribusiness banking.  One of our key strengths lies in our people who have a deep understanding of agriculture & are committed to adding long-term value for clients.  Our commitment to our employees & clients is at the heart of everything we do.

About the role:

Rabobank’s Technology Engineering Security Team is on the front line of cyber defence - designing & implementing controls that protect our systems & data.  This collaborative team covers Security Architecture, Vulnerability Management, Security Testing, & Red Teaming.  The team is now looking for an Offensive Security Engineer in Sydney on a 12-month fixed term contract

As Offensive Security Engineer, you will be responsible for delivering high‑impact offensive security testing across applications, infrastructure, cloud environments, & emerging technologies within Rabobank Australia & New Zealand (RANZ).

Top Role Responsibilities & Accountabilities:

  • Partner with business leaders & technology stakeholders to identify systems & services that meet defined criteria for offensive security testing, establishing & managing a prioritised testing pipeline
  • Execute offensive security testing pipeline across applications, infrastructure, & cloud platforms (on‑prem & Azure)
  • Deliver hands‑on penetration testing & vulnerability assessments, validating exploitability & real business impact
  • Support squads by triaging findings from code scanning, helping teams understand what matters & why
  • Partner with DevSecOps engineering teams to support shift‑left security by informing, tuning, & validating automated security testing & CI/CD controls based on real‑world offensive findings
  • Champion effective remediation by collaborating with engineering, security architecture, secure design, & vulnerability management teams to prioritise findings, provide actionable guidance, validate fixes, & influence secure‑by‑design practices
  • Oversee & coordinate testing activity across the Rabobank ANZ region, including external penetration testing schedules
  • Produce clear, high‑impact security reports tailored to both technical & non‑technical stakeholders
  • Contribute to secure‑by‑design outcomes by feeding findings back into architecture, design, & vulnerability management processes
  • Influence the ongoing maturity of the offensive security capability through knowledge sharing, research, & continuous improvement

To Be Successful, you will have:

  • Strong hands-on experience conducting penetration testing & offensive security assessments in complex environments
  • Proven ability to identify & exploit vulnerabilities across diverse technologies while collaborating with defensive teams
  • Deep passion for ethical hacking & security research; proactively exploring & adopting new tools, techniques, exploits, and methodologies to elevate testing quality.
  • Broad technical expertise in assessing platforms including (but not limited to)web applications & APIs, mobile (iOS/Android), network/server infrastructure, major cloud providers (AWS, Azure, etc.), & hardware/IoT devices
  • Excellent ability to write clear, concise, & impactful reports that translate technical findings into understandable risks & remediation steps for technical & non-technical audiences
  • Solid understanding of offensive security frameworks & methodologies (e.g.,OWASP Testing Guide, OSSTMM, PTES,NIST, MITRE ATT&CK)
  • General knowledge of SAST (Static Application Security Testing) & DAST (Dynamic Application Security Testing)tooling, & how these complement manual offensive testing in identifying & prioritising vulnerabilities
  • Knowledge of secure development practices & DevSecOps principles within the SDLC, including integration of security controls in CI/CD pipelines to support shift-left security & faster remediation
  • Strong technical communication & collaboration skills, with the ability to work effectively across domains (including SOC, architecture, & vulnerability management) to drive meaningful improvements & remediation outcomes

Our Values

Rabobank Australia values inclusion, belonging, & positive experiences for all.  Our work environment, our benefits, & the way we live our values, “Client Driven”, “Responsible”, “Professional” & “Cooperative” make it a great place to work.   We welcome applicants from diverse backgrounds.

Please let our Talent Acquisition team know if you need any accommodations to make our opportunities more accessible to you.

The Application Process

This is our standard application process. It may vary by role.

Step 1You Apply

Thanks for applying! You will always receive a confirmation of your application by email. We review all the resumes and covering letters that we receive. We will let you know as soon as possible if we invite you for an interview.

Step 2Interview

We invite you for one or more (online) interviews. We want to know if you fit the role and the team. You probably have many questions for us too. For some positions, we may also ask you to complete an assignment or assessment.

Step 3Our Offer

Are you the new colleague we are looking for, and do you also feel happy with us? Congratulations! You will receive a good offer from us. Before you start, we conduct a legal screening to ensure that our employees do not pose a risk to us and our customers.

Step 4Welcome!

Welcome to Rabobank! We look forward to seeing you and can't wait to work together.

Apply for this job

Offensive Security Engineer

The required field 'first name' has not been filled in.
The required field 'last name' has not been filled in.
The required 'email' field has not been filled in.

The required 'phone number' field has not been filled in.
Upload
The required 'CV' field has not been filled in.
Upload
You have not yet accepted the privacy statement. Check the box to agree.
The required field 'working rights australia' has not been filled in.
The required field 'remuneration expectations' has not been filled in.
The required field 'connections to rabobank' has not been filled in.