Powered by pgvector · cosine kNN
Cliffside Cybersecurity
Offensive Security Consultant: Build What Penetration Testing BecomesThe Honest Version FirstWe are not hiring a penetration tester. We are hiring the person who will build what our penetration testing practice looks …
Your match
See how you fit
Scored against this job in seconds
Your account
Sign in to apply
Your profile and your match for this job appear right here.
sign in above to apply · via LinkedIn
About the role
Offensive Security Consultant: Build What Penetration Testing BecomesThe Honest Version FirstWe are not hiring a penetration tester. We are hiring the person who will build what our penetration testing practice looks like in five years.And here is the reasoning: Penetration testing as it is sold today, scoped applications, checklist methodologies, findings ranked by CVSS, is being commoditised from below and made insufficient from above. Scanners and automation are eating the bottom of the market. AI-driven systems, agent architectures, and interconnected business processes are creating attack surfaces the traditional methodology was never designed to test.The consultancies that keep selling the old model will spend the next five years competing on price. We intend to spend them defining what comes next. That is the job.
About CliffsideCliffside Cybersecurity delivers assessment-first security services for Australian organisations that are serious about understanding and reducing real risk. Our work spans web applications, infrastructure, cloud, identity platforms, and increasingly AI-driven systems including chatbots and agent-based architectures.We are known for cutting through noise and testing what actually matters: how systems behave under real-world abuse, not whether a scanner flags a vulnerability. From regulated industries to high-growth platforms adopting AI, we partner with CIOs and CISOs who want honest answers, not templated reports.
What You Are Actually Signing Up ForDay one, this is hands-on offensive work. You cannot build the future of a practice you cannot deliver today. You will:Conduct penetration testing across web applications, APIs, cloud, and identity platformsDesign and execute attack scenarios, not follow checklistsTest AI systems and chatbots for abuse risks: prompt injection, policy bypass, data leakage, and unintended behaviourAssess how AI systems handle context, state, and interaction flows under adversarial conditionsSimulate real-world attackers, chaining vulnerabilities across systems and servicesValidate defensive controls such as WAFs, rate limiting, and bot protections under active exploitationArticulate business risk clearly, not just technical findingsBut delivery is the floor, not the job description. The actual mandate is bigger:Define how offensive testing works against multi-agent systems, where AI agents interact with APIs, users, and each otherBuild the methodologies, tooling, and delivery standards that our practice will run onDesign complex attack simulations against AI-driven business processes, not single applications in isolationShape what we sell, how we scope it, and how we prove its value to clientsIn other words: the engagements you deliver in year one are the research and development for the practice you build by year three.
Who This SuitsThis is not a junior box-ticking role, and it is not a pure architect role either. You need both the hands and the head.Offensive capability you already have:Strong experience across web, API, infrastructure, and cloud penetration testingAbility to independently scope, execute, and deliver end-to-end engagementsExperience with adversary simulation or red teamingComfort in ambiguous environments where the path is not predefinedThe forward-looking part:Exposure to testing AI systems, chatbots, or LLM-based applicationsUnderstanding of how AI systems can be manipulated through input, context, or workflow abuseGenuine curiosity about how autonomous agents and integrated systems create new attack surfacesA view, even a half-formed one, on where this discipline is heading. We would rather hire someone with strong opinions we can argue with than someone waiting to be told the methodology.The thinking style:Attack chains, not isolated vulnerabilitiesComfort with APIs, authentication flows, and complex application logicWillingness to break things that are not obviously brokenAbility to translate technical issues into business impact for technical and non-technical stakeholders alikeBackground:Certifications such as OSCP, OSCE, CREST CRT or similar are valued, not worshippedExperience in consulting or client-facing delivery environmentsCybersecurity, computer science, or equivalent practical experienceWhy This Role Exists Here and Not at a Big FirmLarge firms will eventually build AI-era offensive practices. They will do it by committee, two years late, and the person who builds it will be three management layers below the decision. Here, you are the decision. You will have direct access to the founder, real clients already asking for this work, and the mandate to build the practice rather than inherit one.
We do not sell generic penetration testing, and we are not going to start. If you are still running tools and calling it a day, this is not for you. If you want your name on what penetration testing becomes, this is exactly where you should be.
sign in above to apply · via LinkedIn
HackLabs
About HackLabsHackLabs is a leading, CREST-accredited Australian information security consultancy dedicated to delivering superior offensive security services. We are a boutique firm known for our cutting-edge experti…
Open Positions at Packetlabs
Who we are looking for Core values: You have a customer-first mentality. Is a great communicator with clients, project managers, and teammates. Rapid responses and on time. You deliver work that you take pride in. You…
Kinetic IT
About The Role We’re looking for a technically skilled Penetration Tester to work within our Professional Services portfolio. You’ll execute offensive security assessments to identify vulnerabilities, demonstrate real…
Kinetic IT
About The Role We’re looking for a technically skilled Penetration Tester to work within our Professional Services portfolio. You’ll execute offensive security assessments to identify vulnerabilities, demonstrate real…
Kinetic IT
About The Role We’re looking for a technically skilled Penetration Tester to work within our Professional Services portfolio. You’ll execute offensive security assessments to identify vulnerabilities, demonstrate real…
BDO
We’re BDO, a global professional services firm connected to local markets. Our people work together to provide specialist expertise, helping businesses achieve their goals. We inspire others, to go further. We create …
Your job hunt, handled
Ask about any role and get a straight answer on your fit. Then stop searching: new matches land in your WhatsApp the moment they’re listed.
Free for jobseekers