Information Security Specialist

🗓️ Posted 2026-08-14 Brisbane QLD Full-time Hybrid ICT

Company shared salary

Negotiable package offered to the right applicant. AUD

Market rate

A$5,800–A$7,500/mo (A$69,600–A$90,000/yr)

Based on similar roles (title + domain + location).

About the Company

At Best Practice Software, our vision is communities connected with care. We're achieving this through our mission to build a culture people love, where we value customers, we work together for success, we are accountable for our actions, we innovate for the future, and we celebrate diversity and inclusion. Bp Premier sits inside thousands of Australian general practices and touches the health records of millions of people.

Responsibilities

  • Partner with our product and development teams from the design stage - facilitating threat modelling and shaping architecture decisions before code is written
  • Validate what matters: demonstrate real exploitability of findings so developers trust what lands in their backlog
  • Build security into the way we work - backlog items, acceptance criteria, PR templates and definition of done, not a separate document nobody reads
  • Own and tune our SAST/DAST tooling in CI/CD so it produces signal, not noise
  • Own our penetration testing program - identifying when a pen test is needed, scoping and managing engagements, driving the output into actioned work, and maintaining a regular testing cadence across our products
  • Help drive our security maturity roadmap alongside the security directorate

Requirements

  • Practical offensive testing skills - you can penetration test web applications, APIs and services to a professional standard, working manually beyond automated tooling and demonstrating real exploitability rather than forwarding scanner output
  • Structured threat modelling - you can facilitate threat modelling sessions with architects and developers using recognised approaches, and turn the results into prioritised, actionable engineering work
  • Turning risk into clear security requirements - you can translate regulatory, contractual and risk-based drivers into specific, testable security requirements that fit how delivery teams actually work
  • A remediation mindset, not just a findings mindset - you recommend proportionate, practical controls, talk credibly about trade-offs, compensating controls and residual risk with engineers and risk owners alike, and stay involved until the issue is genuinely closed
  • Credibility with development teams - you explain risk in terms