Senior Application Security Engineer - 6 month contract
Contract Type
Location
Industry
Specialisation
Salary
Contact Name
Contact Email
Date published
Job Reference
Description
6-Month Contract | competitive day rate | Sydney CBD + Hybrid
I'm working with a well-known Australian technology business that's continuing to invest heavily in its engineering and platform capabilities. With a large cloud-native environment and a strong engineering culture, they're looking to bring in a Senior Application Security Engineer to help uplift their AppSec capability and embed security into the software development lifecycle.
This is a hands-on contract where you'll own the delivery of a number of key AppSec initiatives across the engineering function. You'll work closely with Platform, DevOps and Engineering teams to implement security controls that are practical, scalable and developer friendly.
Some of the key pieces of work include:
- Rolling out GitHub Advanced Security across the business.
- Building secure-by-default CI/CD patterns.
- Standing up and hardening a private package registry.
- Implementing gated deployment processes.
- Improving software supply chain security.
- Container image scanning and vulnerability management.
- Working with engineering teams to improve AppSec practices and developer experience.
- Producing documentation and handing the capability over to the Platform team.
We're keen to speak with people who have experience across:
- Application Security, Product Security or DevSecOps.
- GitHub Advanced Security including CodeQL, secret scanning and dependency review.
- GitHub Enterprise and GitHub Actions.
- CI/CD security and secure software delivery.
- Software supply chain security and package management.
- Private package registries such as Artifactory, JFrog, Nexus or GitHub Packages.
- Container security and image scanning tools.
- AWS or other cloud-native environments.
- Scripting and automation using Python, Bash, Go or similar.
- Working closely with engineering teams to embed security into development workflows.
Experience building or uplifting an AppSec function from scratch would be a huge plus.
- Initial 6-month contract.
- Competitive day rate
- Hybrid working with offices in Sydney CBD.
- Greenfield AppSec uplift project.
- Modern cloud-native engineering environment.
- High-performing Platform and Engineering teams.
- Immediate start available.
If you're an experienced Application Security Engineer or DevSecOps specialist looking for your next contract, I'd be keen to have a confidential chat.