Penetration Tester
Summary
Penetration Tester on a 12-month remote contract providing cybersecurity assurance, vulnerability assessment, and security testing across networks, web apps, APIs, cloud and identity environments for a Regional Council.
About the Company
Davidson Technology are working with a large Regional Council to supply a Penetration Tester to support the Cyber Security and ICT Governance Service through a large program of work on an initial 12-month contract with the option of 2 x 1-year extensions.
About the Role
As a Penetration Tester, you will provide specialist cybersecurity assurance and technical security testing to support a Regional Council in strengthening its cyber maturity, ICT governance and operational resilience. You will assess Council's ICT environment for vulnerabilities and security weaknesses through structured penetration testing and security assurance activities, identifying potential attack paths, validating the effectiveness of existing security controls and providing clear, risk-based recommendations for remediation. You will work closely with Council's internal ICT team, managed service providers and third-party vendors to support security monitoring, incident response readiness and the ongoing improvement of cybersecurity practices. You will translate technical findings into practical remediation actions and meaningful risk insights, contributing to governance uplift and executive-level reporting while ensuring security risks are clearly understood, prioritised and effectively managed within a complex local government operating environment.
About You
To be successful in this role, you will be an experienced Penetration Tester with strong hands-on expertise identifying, exploiting and documenting security vulnerabilities across complex ICT environments, including networks, infrastructure, web applications, APIs, cloud platforms and identity environments. You will bring a strong understanding of penetration testing methodologies, attack techniques and security frameworks, with the ability to assess control effectiveness, identify realistic attack paths and translate technical findings into clear, risk-based remediation recommendations for both technical teams and senior stakeholders. You will demonstrate strong capability across vulnerability assessment, security testing, threat analysis and reporting, supported by excellent communication and stakeholder engagement skills and the ability to work collaboratively with internal ICT teams, managed service providers and third-party vendors. Relevant industry certifications such as OSCP, CREST, GPEN or equivalent will be highly regarded. This is a fully remote 12-month contract opportunity with the potential for two additional 12-month extensions.
The Benefits
You will be offered a 12-month contract on a competitive daily rate with the options of 2 x 12-month extensions.
Please apply with current resume in Microsoft Word format only (.doc or .docx). If you would like to have a confidential discussion, please contact Nina Magill, quoting reference JN -082026-44108. Want to know more about Davidson? Visit us at www.davidsonwp.com