Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Penetration Testing Manager

Full-time

ASX Limited

ASX: Powering Australia's financial markets

Why join the ASX?

When you join ASX, you’re joining a company with a strong purpose – to power a stronger economic future by enabling a fair and dynamic marketplace for all.

In your new role, you’ll be part of a leading global securities exchange with a strong brand. We are known for being a trusted market operator and an exciting data hub.

Want to know why we are a great place to work, click on the link to learn more.

We are more than a securities exchange!

The ASX team brings together talented people from a diverse range of disciplines.

We run critical market infrastructure, with 1 in 3 people employed within technology. Yet we have a unique complexity of roles across a range of disciplines such as operations, program delivery, financial products, investor engagement, risk and compliance.

We’re proud to foster a workplace where diversity is celebrated and inclusion is part of our everyday culture. Our employee-led networks champion LGBTIQ+ inclusion, promote gender equality, accessibility and wellbeing, inspire giving and volunteering, and celebrate cultural and religious events, creating a sense of belonging for all. As an AWEI Bronze employer and member of the Champions of Change Coalition for gender equality, we’re committed to a fair and inclusive workplace where everyone can thrive.

Your Team

The Cyber Architecture and Assurance team provides independent assurance over ASX’s cyber control environment, helping protect the integrity, availability and resilience of market-critical services.

The team works across Cyber Security, Technology and business stakeholders to establish assurance standards, govern testing activity, coordinate specialist external providers, drive accountability for remediation, and provide evidence over the effectiveness of controls across penetration testing, Red/Purple Team coordination, control validation and risk-based security assessment activities.

Coordinate ASX’s end-to-end penetration testing program, including annual planning, project-based testing, engagement governance, vendor delivery, reporting, closure and remediation follow-up.

  • Coordinate Red Team and Purple Team activities, ensuring exercises are appropriately scoped, governed, safely executed and translated into actionable control improvement opportunities.

  • Own the scope definition and rules of engagement for penetration testing, ensuring coverage is risk-based, complete, agreed by accountable system and project owners, and aligned to system criticality, project risk, technology change and threat exposure.

  • Manage relationships with external penetration testing providers, ensuring engagements are appropriately planned, governed, delivered and assessed against agreed quality expectations.

  • Support budget allocation, forecasting and tracking for penetration testing and related assurance activities, including provider spend, planned testing demand and delivery risks.

  • Drive internal readiness for regular and project-based penetration tests, holding project, system and platform owners accountable for providing testable environments, required access, approved connectivity, stakeholder support, test windows and safe execution constraints.

  • Establish and manage engagement governance, including readiness criteria, go/no-go decision points, escalation paths, daily status reporting, issue management, SOW coordination and closure criteria.

  • Act as the central escalation and decision point during live testing, removing blockers, coordinating rapid issue resolution, tracking coverage against agreed scope, and ensuring high or critical findings are communicated promptly.

  • Hold technology, application, cloud, infrastructure, business and vendor teams accountable for triaging findings, agreeing remediation actions, tracking closure and escalating material risks where obligations are not being met.

  • Evaluate, pilot and integrate AI-enabled or automated penetration testing capabilities into the broader cyber assurance and security testing strategy.

  • Communicate testing outcomes, themes, delivery risks and risk insights clearly to technical teams, senior stakeholders and non-technical audiences.

Your experience and qualifications Must have:
  • Background in information security, penetration testing principles, vulnerability assessment and risk-based security assurance.
  • Exposure to the delivery lifecycle for security testing or assurance engagements, including planning, scope governance, readiness management, execution oversight, reporting or remediation follow-up.
  • Experience working with external security vendors or penetration testing service providers, including delivery coordination, quality review or performance follow-up.
  • Ability to translate project, system and control risk into clear testing objectives, rules of engagement, readiness expectations and remediation priorities.
  • Exposure to penetration testing across complex technology environments, such as applications, APIs, infrastructure, cloud platforms and critical business systems.
  • Ability to influence stakeholders and drive accountability across technology, project, application, infrastructure, cloud, business and vendor teams.
  • Working knowledge of engagement governance, including roles and responsibilities, readiness criteria, escalation paths, reporting cadence and quality expectations.
  • Working knowledge of contemporary security testing methodologies, common vulnerability classes and relevant cyber security frameworks or regulatory expectations.
Nice to have:
  • Hands-on penetration testing experience, noting ASX primarily uses a panel of specialised providers for delivery.
  • Experience with Red Team or Purple Team exercises, including exercise planning, coordination, debriefs and translation of outcomes into control improvements.
  • Experience with AI-driven, automated or continuous security testing tools, including safe adoption, governance and integration into assurance workflows.
  • Relevant security certifications such as OSCP, GPEN, CISSP, CISM or equivalent practical experience in security testing or cyber assurance.
  • Experience working in financial services, critical infrastructure or another highly regulated technology environment. What you need to enjoy and be good at
  • Highly organised, detail-oriented and able to switch context across varied assurance, delivery, stakeholder and operational
  • tasks.
  • Negotiating mutually acceptable outcomes while clearly asserting non-negotiable security, process and control requirements.
  • Building strong relationships with internal and external stakeholders, including technology teams, business owners and specialist security providers.
  • Taking ownership of issues and driving them through to closure, balancing the bigger picture with the ability to dive into detail when required.
  • Communicating clearly in writing and verbally, with a continuous improvement mindset and strong risk focus in an environment where control effectiveness cannot be compromised.

We make hiring decisions based on your skills, capabilities and experience, and how you’ll help us to live our values. We encourage you to apply even if you don’t meet all the criteria of this role.

If you need any adjustments during the application or interview process to help you present your best self, please let us know at View email address on decentrajobs.com.

At ASX Group, our diverse workforce is essential to build and maintain a fair and dynamic marketplace. We support flexible working and offer hybrid working options. Even if our roles are advertised as full-time, we encourage you to apply if you are interested in part-time or other flexible working arrangements.

We will arrange for successful candidates to have background checks, including reference and police checks, completed as part of the on-boarding process.

To be considered for this position, candidates must be legally authorised to work in Australia on a permanent basis without any restrictions.

Vacancy posted 10 days ago
Similar jobs that could be interesting for youBased on the Penetration Testing Manager in Remote vacancy
  •  ...to establish assurance standards, govern testing activity, coordinate specialist external...  ...the effectiveness of controls across penetration testing, Red/Purple Team coordination, control...  ...change and threat exposure. Manage relationships with external penetration... 
    Suggested
    Permanent employment
    Full time
    Part time
    Flexible hours

    ASX Limited

    Remote
    11 days ago
  •  ...Senior Web Application Penetration Tester Remote SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that...  ...candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques, with the... 
    Suggested
    Full time
    Temporary work
    Remote work
    Flexible hours

    SIXGEN

    United States
    2 days ago
  •  ...Hiring Web and Mobile Application Penetration Testers Job Title – Application Penetration Tester (Senior – Principal) Shorebreak Security...  ..., self-disciplined, motivated application penetration test professionals to join our team. Live where you want and work... 
    Suggested
    Permanent employment
    Full time
    Contract work
    Remote work
    Flexible hours

    Shorebreak Security, Inc

    Cocoa Beach, FL
    more than 2 months ago
  • $130k - $160k

     ...to produce meaningful results. This is a contingent position based upon contract win. SkyePoint Decisions is seeking a Penetration Testing Team Lead to join our team supporting the Department of Education's (DoED) Federal Student Aid (FSA) Cybersecurity and Privacy... 
    Suggested
    Contract work
    Remote work

    SkyePoint Decisions

    Washington DC
    3 days ago
  • Ein führendes Cybersecurity-Unternehmen sucht einen technischen Berater im Bereich Cyber Security und Penetration Testing zur Unterstützung von Kunden in komplexen IT-Umgebungen. Der ideale Kandidat bringt 3-5 Jahre Erfahrung sowie Kenntnisse in TCP/IP, Netzwerken und Scripting... 
    Suggested
    Remote job

    Cyberguard Connect

    New York, NY
    5 days ago
  •  ...Job Description Job Description Overview Cybersecurity Test Manager - Mid-Level JOB STATUS: Full-time CLEARANCE: Secret...  ...testing methodologies and tools, such as vulnerability scanning, penetration testing, and risk assessments. Knowledge of DoD... 
    Full time
    Work at office
    Remote work
    Worldwide
    2 days per week
    3 days per week

    Astrion

    Eglin Air Force Base, FL
    3 days ago
  • Job SummaryOur corporate activities are growing rapidly, and we are currently seeking a full-time Software Testing Manager to join our Information Technology team. This position will manage a team of software testing engineers and software validation projects to implement... 
    Full time
    Contract work
    Work from home

    Medpace

    Cincinnati, OH
    5 days ago
  •  ...software experiences for our customers. The person in this software test position is passionate about the validation and verification of...  ...Architectures.Effectively uses:Software configuration management systems (source control, DevSecOps, CI/CD) and proposes enhancements... 
    Work experience placement
    Immediate start
    Flexible hours

    Ford

    Dearborn, MI
    2 days ago
  •  ...organization, apply now.We are currently seeking a Information Security Manager to join our team in Plano, Texas (US-TX), United States (US)....  ...to information security; remediation may be from incidents, penetration tests, vulnerability scans, internal/external audits and Critical... 
    Contract work
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Plano, TX
    1 day ago
  •  ...Extreme Engineering Solutions (X-ES) is seeking a Software Engineering Manager to lead our Automated Test Software (ATS) team. This team develops software used in manufacturing to program and electrically verify product assemblies, confirm product functionality, and ensure... 
    Casual work
    Work at office
    Local area
    Flexible hours
    Day shift

    Extreme Engineering Solutions, Inc.

    Verona, WI
    a month ago
  • $255k - $295k

     ...executive owner of information security, cybersecurity risk management, system integrity and IT operational controls ensuring technology...  ...2, and customer contractual obligations.* Oversee audits, penetration tests, and remediation programs; report risk posture clearly to... 
    Full time
    Temporary work
    Remote work

    EWS Group

    Kentucky
    1 day ago
  • A digital usability consulting firm in the United States is seeking a Junior Usability Tester to explore and provide feedback on mobile apps. This position allows for flexible remote work, requiring only a smartphone or tablet. No prior experience is necessary, making it...
    Remote work
    Flexible hours

    Review Pays

    New York, NY
    5 days ago
  •  ...Possibility for Extension: Yes. Work Location: Role is 100% remote. Required Skills 7+ years of experience in document accessibility testing and remediation 3+ years of experience in Microsoft Word WCAG 2.1 AA Remediation (styles, headings, alt text, reading order) 3+... 
    Contract work
    For contractors
    Remote work

    Lumen Solutions Group Inc.

    United States
    5 days ago
  •  ...Tester to join their team. As an Accessibility Tester, you will be part of the Quality Assurance department supporting diverse product testing initiatives. The ideal candidate will demonstrate attention to detail, strong communication skills, and a passion for creating... 
    Remote work

    Experis

    United States
    3 days ago
  •  ...Qantas, SHEIN and many more - with fully integrated solutions to manage everything from business accounts, payments, spend management...  ...understanding of the spend management landscape to identify and penetrate new enterprise verticals, driving significant revenue growth... 
    Contract work
    Temporary work
    Local area
    Remote work
    Worldwide

    Airwallex

    San Francisco, CA
    5 days ago
  • $1,000 per month

     ...Jersey, Pennsylvania, and West Virginia . This is a great opportunity to earn extra income on a flexible schedule while helping us test online casinos. No prior experience is required, and all training is provided. This is a short-term contract, with opportunities... 
    Extra income
    Temporary work
    Second job
    Currently hiring
    Immediate start
    Work from home
    Flexible hours

    Little Wheel

    Jersey City, NJ
    3 days ago
  •  ...Remote Duration: 06 Months Job Description: Developing test scenarios & cases Execute test cases for User Acceptance...  ...requirements into functional specifications for the IT organization and manage changes to such specifications. Preform Business Checkout... 
    Remote work

    Integrated Resources

    United States
    3 days ago
  •  ...SCCI is seeking a System Tester for manned aircraft projects for the Battle Management System (BMS) family of projects. In this position you will plan, conduct, and report results of test and evaluation of the systems and products of the project teams within the BMS... 
    16 hours
    Remote work

    SCCI

    King George, VA
    4 days ago
  •  ...Remote Duration: 06 Months Job Description: Developing test scenarios & cases Execute test cases for User Acceptance...  ...requirements into functional specifications for the IT organization and manage changes to such specifications. Perform Business Checkout for... 
    Remote work

    Careers Integrated Resources Inc

    United States
    3 days ago
  • $230k - $245k

     ...related risk decisions across the organization, and advancing and managing a comprehensive Governance, Risk, and Compliance (GRC)...  ...requirements. Conduct regular risk assessments and periodic penetration testing and vulnerability assessments to identify and mitigate... 
    Work at office
    Local area
    Remote work

    Business Wire

    San Francisco, CA
    2 days ago
  • $37.3 - $43.3 per hour

     ...the financial institution. Serving as a Project Manager for risk assessments, pen tests, new security tool implementations and recommendations...  ...external vendors to conduct periodic vulnerability scans and penetration tests. Work with IT staff to remediate any issues... 
    Hourly pay
    Work experience placement
    Work at office
    Local area
    Remote work
    Relocation package

    SAG-AFTRA

    Burbank, CA
    2 days ago
  •  ...surveillance systems. We have an exciting opportunity for a System Test Analyst to join the GA-ASI Systems Integration Lab (SIL) team...  ...and report findings to a variety of audiences, including management. Must have strong interpersonal skills to influence and guide other... 
    Full time
    Remote work

    General Atomics Aeronautical Systems

    Poway, CA
    21 hours ago
  • $107.9k - $195.05k

     ...Sector at Leidos is looking for an Information System Security Manager (ISSM) to support a fast-paced program with the Air Force...  ....Experience with security tools for vulnerability scanning, penetration testing, and security auditing.Advanced security certifications (e.g... 
    Full time
    Remote work
    Night shift

    Leidos

    Lorton, VA
    6 days ago
  •  ...automation and data transformation. We then bring those commercially tested solutions to  government entities to deliver predictable,...  ...generated summaries, call metadata, quality scores, and Verint quality management systems Validate CloudWatch alarms, anomaly detection... 
    Full time
    Local area

    rockITdata

    Remote
    8 days ago
  •  ...our government customer. The System Tester is responsible for testing and debugging a government information system that supports human...  ...Provide daily help desk support for all system users, managing requests through a ticketing system and meeting established service... 
    Full time
    Work at office
    Remote work

    Client First Technologies

    Fairfax, VA
    3 days ago
  • Job DescriptionThe RoleThe Manager, Offensive Product Cybersecurity & PSOC leads two key areas within GM’s Product Cybersecurity...  ...Product Security Operations Center (PSOC). This leader oversees penetration testing, red team operations, and security research to strengthen... 
    Full time
    Local area
    Work from home
    Relocation package

    General Motors

    Warren, MI
    3 days ago
  • $225k

     ...the public cloud, Capital One needed to build cloud and data management tools that didn’t exist in the marketplace to enable us to...  ...customers through vendor risk assessments, architecture reviews, penetration tests, and compliance validation (SOC2, ISO, PCI-DSS, HIPAA)... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Capital One

    United States
    5 days ago
  •  ...way. The potential is enormous, and we have a clear path to make it real. Come join us. Job SummaryWe are seeking an experienced Test Manager to join our Photonics Test Engineering team. This role focuses on developing and scaling advanced test capabilities to support... 
    Full time
    Remote work
    Shift work

    PsiQuantum

    Palo Alto, CA
    5 days ago
  •  ...language codes in HTML and PDF metadata, and identify mixed-language content missing proper declarations. In-Language Screen Reader Testing : Using native-language screen readers (JAWS, NVDA, VoiceOver, TalkBack, or Narrator), review translated accessible text —... 
    Temporary work

    Welo Global

    Remote
    24 days ago
  • $90.9k - $129.9k

     ...values your contributions and puts a premium on work flexibility, learning, and career development. Summary As a Experienced Test Manager - PBM (Pharmacy Benefit Manager) at Gainwell, you can contribute your skills as we harness the power of technology to help our... 
    Full time
    Remote work
    Flexible hours

    Gainwell Technologies LLC

    Remote
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Penetration Testing Manager. Be the first to apply!