Information Security Specialist

DIRECTORATE – Security & Infrastructure • Bundaberg, Queensland 4670, Australia • Full-time
AI Job Summary
  • Manual penetration test web apps, APIs and services; demonstrate real exploitability to a professional standard.
  • Facilitate threat modelling with architects and developers using STRIDE/attack trees; turn results into actionable work.
  • Translate regulatory, contractual and risk drivers into specific, testable requirements integrated into delivery (user\n

Role Type

Permanent • Full-time • Team Member

Description

At Best Practice Software, our vision is communities connected with care. We’re achieving this through our mission to build a culture people love, where:

  • we value customers,
  • we work together for success,
  • we are accountable for our actions,
  • we innovate for the future, and
  • we celebrate diversity and inclusion.

If you share our vision and values, please consider this exciting career opportunity to join our growing team in Bundaberg or Brisbane, Queensland.

You’re unique, and we value that.

Bp Premier sits inside thousands of Australian general practices and touches the health records of millions of people. The security decisions made in our products matter — and this role is where they get made well. At Best Practice Software, our vision is communities connected with care, and application security is at the core of how we deliver it.

This is a senior, embedded security partner role, not an advisory position. You’ll sit within our security directorate but spend much of your time embedded with our product teams and developers, from design onwards — the kind of person who would rather influence a design decision early than write a findings report about it later, and who demonstrates the ability to apply knowledge directly into our product planning and delivery processes.

You’ll have modern tooling behind you (SAST, DAST, CI/CD pipelines, Kubernetes) and a security maturity roadmap (OWASP SAMM) to help drive.

As an Information Security Specialist, we’ll call on your unique talents, skills, expertise, and experience to:

  • Partner with our product and development teams from the design stage — facilitating threat modelling and shaping architecture decisions before code is written;
  • Validate what matters: demonstrate real exploitability of findings so developers trust what lands in their backlog;
  • Build security into the way we work — backlog items, acceptance criteria, PR templates and definition of done, not a separate document nobody reads;
  • Own and tune our SAST/DAST tooling in CI/CD so it produces signal, not noise;
  • Own our penetration testing program — identifying when a pen test is needed, scoping and managing engagements, driving the output into actioned work, and maintaining a regular testing cadence across our products;
  • Help drive our security maturity roadmap (OWASP SAMM) alongside the security directorate.

We believe our ideal applicant will demonstrate the following attributes:

1. Practical offensive testing skills — you can penetration test web applications, APIs and services to a professional standard, working manually beyond automated tooling and demonstrating real exploitability rather than forwarding scanner output

2. Structured threat modelling — you can facilitate threat modelling sessions with architects and developers using recognised approaches (STRIDE, attack trees or similar), and turn the results into prioritised, actionable engineering work

3. Turning risk into clear security requirements — you can translate regulatory, contractual and risk-based drivers into specific, testable security requirements that fit how delivery teams actually work: user stories, acceptance criteria and definition of done, not a separate document nobody reads

4. A remediation mindset, not just a findings mindset — you recommend proportionate, practical controls, talk credibly about trade-offs, compensating controls and residual risk with engineers and risk owners alike, and stay involved until the issue is genuinely closed

5. Credibility with development teams — you explain risk in terms engineers care about, challenge constructively without becoming a blocker, and build enough trust that teams come to you for advice before they build rather than after

Nice to have:

  • Experience with regulated health data — Privacy Act / APP 11, notifiable data breaches, ADHA conformance or My Health Record integration — or a working knowledge of the Australian healthcare community and its unique challenges
  • Industry certifications such as CSSLP, OSCP, PNPT or CREST — or the drive to earn one
  • Experience lifting an organisation’s maturity against a framework such as OWASP SAMM
  • Development or security experience across .NET, Microsoft SQL Server and Azure-native cloud, including client-server as well as web architectures
  • Experience working in application security alongside large development teams
  • A tertiary qualification or accreditation in a related discipline — or a demonstrated commitment to progressing your learning and development

What’s in it for you?

  • Market-leading benefits that make us a proven local employer of choice.
  • Flexible work arrangements that help you strike the right career balance.
  • Exciting start to, or positive development of, your Health IT career, with brilliant internal growth opportunities.
  • Belong as part of a dynamic and highly supportive team with a strong dedication to the mission.
  • Enrich your experience by supporting our frontline healthcare heroes across Australasia.

Our team members enjoy exclusive access to our brilliant B-Perks Program, offering great rewards like birthday leave, an annual health and wellbeing bonus, and sponsored rewards to recognise outstanding contributions. You’ll also access our leadership development program and learning opportunities across our group of businesses and enjoy the freedom and flexibility to work as you work best. We offer purpose and impact, an inclusive culture, a connected workforce, transparent leadership, and growth and belonging.

How can we get this ball rolling?

To start a conversation on your fit within our team, we recommend you provide us with:

  • a capability statement/cover letter highlighting your experience and how you meet our requirements; and
  • an updated copy of your resume.

Your new career starts here.

For more information on this role, please contact Jemma Sewell on 1300 40 1111 (in Australia) or 0800 40 1111 (in New Zealand). If you’re ready to soar to new heights, then click the button to ‘Apply’ for this job. Only applicants who are required to be interviewed will be contacted upon submission of this application.

Company Overview

More than just a job – a career with Best Practice Software opens the door for professional growth and development, giving you an opportunity to reach your upmost potential with an organisation that is shaping Australasian healthcare. We proudly foster a supportive, collaborative environment where each employee’s contribution is recognised, a healthy work/life balance is promoted, and our team embodies our BEST values each day.