Setting the Scene
Our client is an Australian-based boutique cybersecurity advisory firm specialising in offensive security, penetration testing, red teaming and security research. They work with enterprise organisations globally, helping clients understand real-world cyber threats, assess their security posture and develop practical strategies to strengthen their defences.
Their approach is deeply rooted in the offensive security mindset, with a focus on understanding how attackers operate and using that knowledge to identify vulnerabilities and improve organisational security. The team works across diverse technologies, industries and environments, providing exposure to complex security challenges and opportunities to work alongside highly experienced offensive security professionals.
Due to continued growth, they are seeking a Junior Penetration Tester / Junior Red Teamer to join their team and develop their career in offensive security.
The Role
This role is ideal for someone who has a strong technical foundation and a genuine passion for penetration testing, ethical hacking and offensive security, and wants to build a long-term career in red teaming. Working alongside experienced penetration testers and red teamers, you will support the delivery of security assessments and gradually develop your capability across vulnerability identification, exploitation, attack paths and adversary simulation.
As your experience develops, you'll have the opportunity to move beyond traditional penetration testing and build expertise in areas such as advanced red teaming, security research, offensive tooling and adversary simulation.
Key responsibilities:
- Support penetration testing and security assessment engagements across client environments
- Identify, investigate and document vulnerabilities and security weaknesses
- Assist with testing security controls and identifying opportunities for exploitation
- Develop an understanding of attack paths and how vulnerabilities can be chained together
- Support senior consultants during red team engagements and adversary simulation exercises
- Develop foundational skills across reconnaissance, exploitation, privilege escalation and lateral movement
- Assist with developing practical remediation recommendations based on technical findings
- Use scripting and automation to improve penetration testing processes and capabilities
- Research emerging vulnerabilities, offensive techniques and attacker methodologies
- Learn and apply new technologies, tools and techniques to solve unfamiliar security challenges
- Contribute to internal security research, tooling and knowledge-sharing activities
- Develop your consulting and communication skills through client interaction and engagement delivery
- Work closely with senior offensive security professionals and progressively take ownership of technical activities as your skills develop
What you'll bring - A strong interest in penetration testing, red teaming, ethical hacking or offensive security
- Foundational knowledge of networking, TCP/IP, DNS, HTTP and common network protocols
- Understanding of Windows and Linux operating systems
- Exposure to Active Directory and common enterprise environments
- Understanding of common vulnerabilities, exploitation concepts and security fundamentals
- Basic scripting or programming skills, particularly Python, PowerShell or Bash
- Strong curiosity and a genuine desire to understand how systems work and how they can be compromised
- A problem-solving mindset and willingness to investigate unfamiliar technologies and environments
- Ability to learn independently while also working collaboratively with experienced consultants
- Strong communication skills and the ability to explain technical concepts clearly
- A willingness to continuously develop your technical skills and offensive security knowledge
What will set you apart? Commercial experience isn't the only way to demonstrate your passion for offensive security. We're particularly interested in candidates who can demonstrate their technical curiosity through:
- Hack The Box
- TryHackMe
- Capture The Flag (CTF) competitions
- Home labs
- Security research
- GitHub projects
- Personal security tooling or automation
- University cybersecurity projects
- OSCP, PNPT, eCPPT or similar certifications
What’s in it for you? - Join a highly technical boutique cybersecurity consultancy focused on offensive security
- Work alongside experienced penetration testers and Senior/Principal Red Teamers
- Gain hands-on exposure to real-world penetration testing and red team engagements
- Genuine pathway into advanced red teaming and adversary simulation
- Exposure to diverse clients, industries, technologies and environments
- Opportunity to develop skills in security research, automation and offensive tooling
- Strong learning and development opportunities
- Build your career alongside some of Australia's most experienced offensive security professionals
- Sydney CBD location
- Hybrid working model - 3 days per week in the office and 2 days from home
- Performance-based annual bonus scheme
- Monthly coffee and meal allowance
- Quarterly team activities
- Birthday work-free day + gift
- Flexible public holiday arrangements
- Collaborative culture focused on technical excellence, learning and innovation
- Opportunity to specialise and develop into the areas of offensive security you're most passionate about
How to apply Applications are treated with absolute confidentiality. Click APPLY or contact Clodagh at clodagh@decipherbureau.com for an informal conversation about your next career move. Equal opportunity and diversity are a priority. We encourage applicants from all backgrounds to apply.