Location: Various locations across Australia (Remote and Onsite opportunities available)
Type: Contract, Permanent, or Subcontractor
Summary
SovereignSourced invites talented Penetration Tester to join our employment register. This register offers access to a diverse range of opportunities across industries such as finance, technology, government, and professional services. While registering your interest doesn’t guarantee immediate placement, it ensures you’re considered for roles aligned with your expertise as they arise.
About the Role
We are seeking an experienced Penetration Tester to conduct security assessments, identify vulnerabilities, and provide remediation strategies to strengthen organisational security posture. This role requires expertise in ethical hacking, penetration testing methodologies, and cyber security frameworks to ensure compliance and resilience against cyber threats.
Salary Range
Salaries for Penetration Tester roles range from $100k-180k inc super.
Key Responsibilities
Conduct penetration testing on networks, web applications, cloud environments, and mobile applications.
Perform red teaming, ethical hacking, and adversary simulation exercises to assess security controls.
Identify, document, and report security vulnerabilities with risk-based remediation recommendations.
Ensure compliance with ISM, PSPF, ASD Essential Eight, ISO 27001, and other security standards.
Develop and execute manual and automated security testing techniques.
Work with security teams to implement secure coding practices and vulnerability management strategies.
Provide technical consulting, threat modelling, and risk assessments to enhance security frameworks.
Support incident response and forensic investigations as needed.
Collaborate with development and IT teams to integrate security improvements.
Stay updated on emerging threats, attack techniques, and security best practices.
Skills and Experience
Active Positive Vetting (PV) security clearance – essential
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field.
Proven experience in penetration testing, vulnerability assessment, or ethical hacking roles.
Strong knowledge of OWASP Top 10, MITRE ATTACK, and common attack vectors.
Proficiency in penetration testing tools such as Burp Suite, Metasploit, Nmap, Kali Linux, and Cobalt Strike.
Experience with cloud security testing (AWS, Azure, Google Cloud) and DevSecOps methodologies.
Hands-on experience in web, mobile, network, and cloud security assessments.
Understanding of exploit development, scripting, and security automation.
Strong ability to create technical reports, risk assessments, and vulnerability remediation plans.
Relevant certifications such as OSCP, OSCE, GPEN, CEH, CISSP are highly regarded.
Benefits of Joining
Access to exclusive opportunities with leading organisations in Australia’s most dynamic industries.
Competitive compensation packages tailored to your expertise and engagement type.
Flexible work arrangements to suit your career and lifestyle preferences.
Opportunities to work on high-impact projects that enhance your professional portfolio.
Collaboration with industry leaders and opportunities for ongoing professional development.
Important Note
Joining our employment register means your application will be retained and considered for future opportunities that match your skills and experience. Registering does not guarantee immediate placement but ensures you’re among the first to be considered for relevant roles as they arise.


Bluerydge
Senior GRC Specialist (Defence)
18 days ago
Senior GRC Specialist (Defence)
Location: Sydney (onsite)
Type: Full-time
Summary
SovereignSourced connects employers with top talent to help them grow, deliver, and thrive across Australia’s most critical industries.
For this role, we are proud to partner with Bluerydge, an Australian-owned cyber security and technology firm trusted to deliver mission-critical capabilities for major organisations and national security initiatives. Bluerydge drives operational excellence through innovative, reliable, and secure solutions.
Bluerydge is seeking a highly capable GRC Specialist (Defence) to support complex Defence programs and lead the cyber governance, risk, and compliance (GRC) uplift practices. This role is pivotal in ensuring the accuracy, consistency, and audit-readiness of cyber terrain data within classified environments and enabling effective risk management and contributing directly to national security outcomes.
About the Role
As a GRC Specialist, you will be responsible for maintaining, managing, and refining cyber terrain artefacts in support of cybersecurity governance across Defence environments.
You’ll work with structured datasets, generate and update cyber terrain topologies, and lead initiatives to develop sustainable processes for cyberworthiness assessments and reporting.
You will also use relevant platforms and cloud-based repositories to ensure the integrity and traceability of information required for audit, assurance, and compliance activities.
NOTE: Minimum NV2 Security Clearance is required.
Salary Range
Salaries for GRC Specialist (Defence) roles range from $150,000 to $250,000, depending on experience.
Key Responsibilities
Assess system-risks for IT & OT systems and create system-risk assessment reports
Collaborate with IT & OT threat modelling activities
Generate and maintain cyber threat models from Defence data sources
Develop and document techniques and procedures to conduct cyber threat assessments
Provide expert guidance to internal Defence stakeholders on terrain management practices
Liaise with security, GRC, and data teams to align frameworks and documentation
Support audit and assurance efforts through proactive governance of cyber data
Skills and Experience
Minimum NV2 Security Clearance required
Experience managing cyber data and terrain artefacts in Defence or secure ICT environments
Knowledge of CTL, cyber terrain models, and relevant Defence frameworks
Proficiency in developing SRMPs, SSPs, E8 checklists and other security documentation
Strong analytical and documentation skills, especially around compliance and assurance
Tertiary qualifications in Cybersecurity, Information Security, ICT, or Data Management
Certifications such as ISO 27001, CRISC, or CISSP, CEH are highly regarded
Mindset
Proactive and solution-focused, with a strong drive to deliver accurate, high-integrity governance outcomes
Eager to grow a long-term career within a mission-driven, high-security environment
Takes initiative and owns tasks, from technical data governance to strategic audit preparation
Passionate about continuous improvement, accuracy, and learning from complexity and failure
Self-motivated and capable of working independently in sensitive environments
Thrives in fast-paced settings that require resilience, adaptability, and critical thinking
Values collaboration, and attention to detail in high-stakes delivery
Benefits of Joining
As an award-winning employer of choice and a high-performing cyber security and technology firm, Bluerydge offers a career experience that is both rewarding and meaningful.
Be part of a trusted delivery team driving cyber security uplift across mission-critical Defence and Government programs
Collaborate with experienced professionals in an inclusive environment
Be recognised with competitive remuneration and a rewards and recognition program that celebrates your achievements
Access ongoing career development through mentorship, training, and certifications
Enjoy flexible working arrangements tailored to support your lifestyle and productivity
Take advantage of health and wellbeing benefits, including initiatives that support mental wellness, physical fitness, and a healthy work environment
How to Apply
Please upload your resume to apply or send it to [email protected].
Candidates must be willing to undergo pre-employment screening checks, including verification of ID, work rights, and current security clearance status.
We will contact suitably qualified candidates with further instructions.
For further discussion, please contact:
· Nathalie – 02 6183 6573
· Andi – 02 6183 6568