Penetration Testing Manager
ASX Limited
ASX: Powering Australia's financial markets
Why join the ASX?
When you join ASX, you’re joining a company with a strong purpose – to power a stronger economic future by enabling a fair and dynamic marketplace for all.
In your new role, you’ll be part of a leading global securities exchange with a strong brand. We are known for being a trusted market operator and an exciting data hub.
Want to know why we are a great place to work, click on the link to learn more.
We are more than a securities exchange!
The ASX team brings together talented people from a diverse range of disciplines.
We run critical market infrastructure, with 1 in 3 people employed within technology. Yet we have a unique complexity of roles across a range of disciplines such as operations, program delivery, financial products, investor engagement, risk and compliance.
We’re proud to foster a workplace where diversity is celebrated and inclusion is part of our everyday culture. Our employee-led networks champion LGBTIQ+ inclusion, promote gender equality, accessibility and wellbeing, inspire giving and volunteering, and celebrate cultural and religious events, creating a sense of belonging for all. As an AWEI Bronze employer and member of the Champions of Change Coalition for gender equality, we’re committed to a fair and inclusive workplace where everyone can thrive.
Your TeamThe Cyber Architecture and Assurance team provides independent assurance over ASX’s cyber control environment, helping protect the integrity, availability and resilience of market-critical services.
The team works across Cyber Security, Technology and business stakeholders to establish assurance standards, govern testing activity, coordinate specialist external providers, drive accountability for remediation, and provide evidence over the effectiveness of controls across penetration testing, Red/Purple Team coordination, control validation and risk-based security assessment activities.
Coordinate ASX’s end-to-end penetration testing program, including annual planning, project-based testing, engagement governance, vendor delivery, reporting, closure and remediation follow-up.
- Coordinate Red Team and Purple Team activities, ensuring exercises are appropriately scoped, governed, safely executed and translated into actionable control improvement opportunities.
- Own the scope definition and rules of engagement for penetration testing, ensuring coverage is risk-based, complete, agreed by accountable system and project owners, and aligned to system criticality, project risk, technology change and threat exposure.
- Manage relationships with external penetration testing providers, ensuring engagements are appropriately planned, governed, delivered and assessed against agreed quality expectations.
- Support budget allocation, forecasting and tracking for penetration testing and related assurance activities, including provider spend, planned testing demand and delivery risks.
- Drive internal readiness for regular and project-based penetration tests, holding project, system and platform owners accountable for providing testable environments, required access, approved connectivity, stakeholder support, test windows and safe execution constraints.
- Establish and manage engagement governance, including readiness criteria, go/no-go decision points, escalation paths, daily status reporting, issue management, SOW coordination and closure criteria.
- Act as the central escalation and decision point during live testing, removing blockers, coordinating rapid issue resolution, tracking coverage against agreed scope, and ensuring high or critical findings are communicated promptly.
- Hold technology, application, cloud, infrastructure, business and vendor teams accountable for triaging findings, agreeing remediation actions, tracking closure and escalating material risks where obligations are not being met.
- Evaluate, pilot and integrate AI-enabled or automated penetration testing capabilities into the broader cyber assurance and security testing strategy.
- Communicate testing outcomes, themes, delivery risks and risk insights clearly to technical teams, senior stakeholders and non-technical audiences.
- Background in information security, penetration testing principles, vulnerability assessment and risk-based security assurance.
- Exposure to the delivery lifecycle for security testing or assurance engagements, including planning, scope governance, readiness management, execution oversight, reporting or remediation follow-up.
- Experience working with external security vendors or penetration testing service providers, including delivery coordination, quality review or performance follow-up.
- Ability to translate project, system and control risk into clear testing objectives, rules of engagement, readiness expectations and remediation priorities.
- Exposure to penetration testing across complex technology environments, such as applications, APIs, infrastructure, cloud platforms and critical business systems.
- Ability to influence stakeholders and drive accountability across technology, project, application, infrastructure, cloud, business and vendor teams.
- Working knowledge of engagement governance, including roles and responsibilities, readiness criteria, escalation paths, reporting cadence and quality expectations.
- Working knowledge of contemporary security testing methodologies, common vulnerability classes and relevant cyber security frameworks or regulatory expectations.
- Hands-on penetration testing experience, noting ASX primarily uses a panel of specialised providers for delivery.
- Experience with Red Team or Purple Team exercises, including exercise planning, coordination, debriefs and translation of outcomes into control improvements.
- Experience with AI-driven, automated or continuous security testing tools, including safe adoption, governance and integration into assurance workflows.
- Relevant security certifications such as OSCP, GPEN, CISSP, CISM or equivalent practical experience in security testing or cyber assurance.
- Experience working in financial services, critical infrastructure or another highly regulated technology environment. What you need to enjoy and be good at
- Highly organised, detail-oriented and able to switch context across varied assurance, delivery, stakeholder and operational
- tasks.
- Negotiating mutually acceptable outcomes while clearly asserting non-negotiable security, process and control requirements.
- Building strong relationships with internal and external stakeholders, including technology teams, business owners and specialist security providers.
- Taking ownership of issues and driving them through to closure, balancing the bigger picture with the ability to dive into detail when required.
- Communicating clearly in writing and verbally, with a continuous improvement mindset and strong risk focus in an environment where control effectiveness cannot be compromised.
We make hiring decisions based on your skills, capabilities and experience, and how you’ll help us to live our values. We encourage you to apply even if you don’t meet all the criteria of this role.
If you need any adjustments during the application or interview process to help you present your best self, please let us know at View email address on decentrajobs.com.
At ASX Group, our diverse workforce is essential to build and maintain a fair and dynamic marketplace. We support flexible working and offer hybrid working options. Even if our roles are advertised as full-time, we encourage you to apply if you are interested in part-time or other flexible working arrangements.
We will arrange for successful candidates to have background checks, including reference and police checks, completed as part of the on-boarding process.
To be considered for this position, candidates must be legally authorised to work in Australia on a permanent basis without any restrictions.
- ...to establish assurance standards, govern testing activity, coordinate specialist external... ...the effectiveness of controls across penetration testing, Red/Purple Team coordination, control... ...change and threat exposure. Manage relationships with external penetration...SuggestedPermanent employmentFull timePart timeFlexible hours
- ...Senior Web Application Penetration Tester Remote SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that... ...candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques, with the...SuggestedFull timeTemporary workRemote workFlexible hours
- ...Hiring Web and Mobile Application Penetration Testers Job Title – Application Penetration Tester (Senior – Principal) Shorebreak Security... ..., self-disciplined, motivated application penetration test professionals to join our team. Live where you want and work...SuggestedPermanent employmentFull timeContract workRemote workFlexible hours
$130k - $160k
...to produce meaningful results. This is a contingent position based upon contract win. SkyePoint Decisions is seeking a Penetration Testing Team Lead to join our team supporting the Department of Education's (DoED) Federal Student Aid (FSA) Cybersecurity and Privacy...SuggestedContract workRemote work- Ein führendes Cybersecurity-Unternehmen sucht einen technischen Berater im Bereich Cyber Security und Penetration Testing zur Unterstützung von Kunden in komplexen IT-Umgebungen. Der ideale Kandidat bringt 3-5 Jahre Erfahrung sowie Kenntnisse in TCP/IP, Netzwerken und Scripting...SuggestedRemote job
- ...Job Description Job Description Overview Cybersecurity Test Manager - Mid-Level JOB STATUS: Full-time CLEARANCE: Secret... ...testing methodologies and tools, such as vulnerability scanning, penetration testing, and risk assessments. Knowledge of DoD...Full timeWork at officeRemote workWorldwide2 days per week3 days per week
- Job SummaryOur corporate activities are growing rapidly, and we are currently seeking a full-time Software Testing Manager to join our Information Technology team. This position will manage a team of software testing engineers and software validation projects to implement...Full timeContract workWork from home
- ...software experiences for our customers. The person in this software test position is passionate about the validation and verification of... ...Architectures.Effectively uses:Software configuration management systems (source control, DevSecOps, CI/CD) and proposes enhancements...Work experience placementImmediate startFlexible hours
- ...organization, apply now.We are currently seeking a Information Security Manager to join our team in Plano, Texas (US-TX), United States (US).... ...to information security; remediation may be from incidents, penetration tests, vulnerability scans, internal/external audits and Critical...Contract workWork at officeRemote workFlexible hours
- ...Extreme Engineering Solutions (X-ES) is seeking a Software Engineering Manager to lead our Automated Test Software (ATS) team. This team develops software used in manufacturing to program and electrically verify product assemblies, confirm product functionality, and ensure...Casual workWork at officeLocal areaFlexible hoursDay shift
$255k - $295k
...executive owner of information security, cybersecurity risk management, system integrity and IT operational controls ensuring technology... ...2, and customer contractual obligations.* Oversee audits, penetration tests, and remediation programs; report risk posture clearly to...Full timeTemporary workRemote work- A digital usability consulting firm in the United States is seeking a Junior Usability Tester to explore and provide feedback on mobile apps. This position allows for flexible remote work, requiring only a smartphone or tablet. No prior experience is necessary, making it...Remote workFlexible hours
- ...Possibility for Extension: Yes. Work Location: Role is 100% remote. Required Skills 7+ years of experience in document accessibility testing and remediation 3+ years of experience in Microsoft Word WCAG 2.1 AA Remediation (styles, headings, alt text, reading order) 3+...Contract workFor contractorsRemote work
- ...Tester to join their team. As an Accessibility Tester, you will be part of the Quality Assurance department supporting diverse product testing initiatives. The ideal candidate will demonstrate attention to detail, strong communication skills, and a passion for creating...Remote work
- ...Qantas, SHEIN and many more - with fully integrated solutions to manage everything from business accounts, payments, spend management... ...understanding of the spend management landscape to identify and penetrate new enterprise verticals, driving significant revenue growth...Contract workTemporary workLocal areaRemote workWorldwide
$1,000 per month
...Jersey, Pennsylvania, and West Virginia . This is a great opportunity to earn extra income on a flexible schedule while helping us test online casinos. No prior experience is required, and all training is provided. This is a short-term contract, with opportunities...Extra incomeTemporary workSecond jobCurrently hiringImmediate startWork from homeFlexible hours- ...Remote Duration: 06 Months Job Description: Developing test scenarios & cases Execute test cases for User Acceptance... ...requirements into functional specifications for the IT organization and manage changes to such specifications. Preform Business Checkout...Remote work
- ...SCCI is seeking a System Tester for manned aircraft projects for the Battle Management System (BMS) family of projects. In this position you will plan, conduct, and report results of test and evaluation of the systems and products of the project teams within the BMS...16 hoursRemote work
- ...Remote Duration: 06 Months Job Description: Developing test scenarios & cases Execute test cases for User Acceptance... ...requirements into functional specifications for the IT organization and manage changes to such specifications. Perform Business Checkout for...Remote work
$230k - $245k
...related risk decisions across the organization, and advancing and managing a comprehensive Governance, Risk, and Compliance (GRC)... ...requirements. Conduct regular risk assessments and periodic penetration testing and vulnerability assessments to identify and mitigate...Work at officeLocal areaRemote work$37.3 - $43.3 per hour
...the financial institution. Serving as a Project Manager for risk assessments, pen tests, new security tool implementations and recommendations... ...external vendors to conduct periodic vulnerability scans and penetration tests. Work with IT staff to remediate any issues...Hourly payWork experience placementWork at officeLocal areaRemote workRelocation package- ...surveillance systems. We have an exciting opportunity for a System Test Analyst to join the GA-ASI Systems Integration Lab (SIL) team... ...and report findings to a variety of audiences, including management. Must have strong interpersonal skills to influence and guide other...Full timeRemote work
$107.9k - $195.05k
...Sector at Leidos is looking for an Information System Security Manager (ISSM) to support a fast-paced program with the Air Force... ....Experience with security tools for vulnerability scanning, penetration testing, and security auditing.Advanced security certifications (e.g...Full timeRemote workNight shift- ...automation and data transformation. We then bring those commercially tested solutions to government entities to deliver predictable,... ...generated summaries, call metadata, quality scores, and Verint quality management systems Validate CloudWatch alarms, anomaly detection...Full timeLocal area
- ...our government customer. The System Tester is responsible for testing and debugging a government information system that supports human... ...Provide daily help desk support for all system users, managing requests through a ticketing system and meeting established service...Full timeWork at officeRemote work
- Job DescriptionThe RoleThe Manager, Offensive Product Cybersecurity & PSOC leads two key areas within GM’s Product Cybersecurity... ...Product Security Operations Center (PSOC). This leader oversees penetration testing, red team operations, and security research to strengthen...Full timeLocal areaWork from homeRelocation package
$225k
...the public cloud, Capital One needed to build cloud and data management tools that didn’t exist in the marketplace to enable us to... ...customers through vendor risk assessments, architecture reviews, penetration tests, and compliance validation (SOC2, ISO, PCI-DSS, HIPAA)...Full timeContract workPart timeLocal areaRemote work- ...way. The potential is enormous, and we have a clear path to make it real. Come join us. Job SummaryWe are seeking an experienced Test Manager to join our Photonics Test Engineering team. This role focuses on developing and scaling advanced test capabilities to support...Full timeRemote workShift work
- ...language codes in HTML and PDF metadata, and identify mixed-language content missing proper declarations. In-Language Screen Reader Testing : Using native-language screen readers (JAWS, NVDA, VoiceOver, TalkBack, or Narrator), review translated accessible text —...Temporary work
$90.9k - $129.9k
...values your contributions and puts a premium on work flexibility, learning, and career development. Summary As a Experienced Test Manager - PBM (Pharmacy Benefit Manager) at Gainwell, you can contribute your skills as we harness the power of technology to help our...Full timeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Testing Manager. Be the first to apply!



