Security Consultant, Offensive Security - Mid OR Senior Level Penetration Tester
AI in this role
Deliver offensive security engagements, penetration testing, and adversary simulations for critical infrastructure and enterprise clients.
At Thales, we know technology has the ability to make our world more secure, sustainable, and inclusive – and that it’s all driven by human intelligence.
Because it takes human intelligence to build and power the systems and solutions that people depend on every day. So we stay curious and make space for diverse points of view. We share what we know and we challenge what’s possible.
From manufacturing and engineering to cybersecurity and space, we’re driving progress in some of the world’s most important industries – and working together to build a future we can all trust.
Our Benefits
In addition to interesting, engaging opportunities that impact at scale, and ongoing personal and professional development opportunities, Thales Cyber can offer you:
- Competitive remuneration structure
- Hybrid and flexible working options under the Thales Flex program
- Paid parental leave and family support through Parents at Work
- The day off on your birthday each year
- Novated Lease options
- Ongoing personal and professional development opportunities
- Sonder Wellbeing & Support Partner
Our Team
Thales delivers cybersecurity products and services that keep people and assets safe, giving organisations confidence in the security of their digital journeys. Our solutions are deployed in 148 countries, helping governments to maintain sovereignty and organisations to preserve their strategic autonomy.
Thales is a global leader in cybersecurity, no.1 in data security with more than 6,000 experts and developers worldwide. We bring trust and resilience to key industries including finance, health, retail and manufacturing, as well as critical sectors such as aerospace, defence, critical infrastructure and space.
Your Role
Join our Offensive Security team delivering complex, real-world engagements across critical infrastructure, defence, government and enterprise clients.
In this permanent full time position based in our Barangaroo office, this is an opportunity to go beyond traditional web application testing and gain exposure to internal network assessments, Active Directory environments, physical security testing, social engineering and adversary simulation activities.
For this role, we are open to a Mid or a Senior to to join our team.
Why Join Us
- Interesting and challenging work across critical infrastructure and defence sectors
- Exposure to physical security, social engineering and advanced offensive security engagements
- Strong engineering-led culture with experienced practitioners
- Boutique team environment backed by a global cybersecurity and technology organisation
- Access to international experts, global research teams and AI innovation labs
- Supported career development, mentoring and certification pathways
What You'll Do
- Conduct penetration testing across web, API, infrastructure and cloud environments
- Perform internal network and Active Directory assessments
- Support or lead physical security and social engineering engagements
- Execute assumed breach, privilege escalation and lateral movement scenarios
- Produce high-quality technical reports and present findings to clients
- Contribute to offensive security tooling, automation and methodology improvements
- Mentor junior team members (Senior level)
What We're Looking For
Mid-Level
- Developed experience with penetration testing or offensive security experience
- Experience with web, API or infrastructure testing
- Strong desire to develop skills in internal network, physical and social testing
Senior Level
- Demonstrated hands-on penetration testing experience
- Strong capability across internal network, Active Directory, web, API and cloud assessments
- Experience leading engagements and mentoring consultants
- OSCP or equivalent highly regarded, but not essential
- Advanced certifications such as OSCE3, OSEP, OSED or CRTO are highly valued
If you're looking for technically challenging work, the opportunity to broaden your offensive security skills, and a team that values technical excellence, we'd love to hear from you.
Australian Defence Roles & Security
A Defence security clearance is required for this role, applicants must be Australian citizens and eligible to obtain and maintain an appropriate clearance.
Additional information with regards to clearances is available from the Australian Government Security Vetting Agency website http://www.defence.gov.au/AGSVA/. In some cases, individuals who hold a current clearance from a foreign government may be eligible to have this clearance recognised by the Australian Government and be eligible for this role. The Australian Defence Trade Controls Act (DTCA) is applicable and as such, your nationality may be a factor in determining your suitability for this role.
We Encourage You to Apply
After you have applied, you will receive an email acknowledging your application. We’ll then provide a personalised experience for suitable applicants as we progress through the selection and assessment process. Prior to being offered employment, you will be required to complete pre-employment checks, including police and medical checks where applicable.
It’s easy to dismiss the perfect opportunity if you don’t see yourself as the perfect fit. If this role feels right – no matter your background or personal circumstances – please introduce yourself or join our community. We’re committed to supporting a diverse workplace, and that starts here.
We’re proud to be endorsed by WORK180 as an Employer for All Women, but we know there’s always more we can do. We’ll continue to foster industry partnerships, employee resource groups (ERGs) and development opportunities to make Thales a genuinely equitable employer, for everyone.
Read more about our WORK180 endorsement.
How we rate this
Security Consultant, Offensive Security - Mid OR Senior Level Penetration Tester at Thales rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where penetration testing was part of your work. What did you do?
- Tell me about a project where cybersecurity was part of your work. What did you do?
- Tell me about a project where vulnerability assessment was part of your work. What did you do?
- Tell me about a project where social engineering was part of your work. What did you do?
- Walk me through how you've used Active Directory in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Penetration Testing, Cybersecurity, Vulnerability Assessment, Social Engineering, and Active Directory. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new remote cybersecurity jobs by email
One email a week with the new remote cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step