Application Security Engineer - CTEM, 12 Month Fixed Term Contract
- Hiring from
- Australia
- Work type
- Hybrid
- Posted
- Sep 30, 2026
We’ve been around since 1988, and today we’re one of Australia’s largest profit‑to‑member super funds.
That means everything we do is focused on delivering better outcomes for our members – not shareholders.
Closing date: 14 October 2026
Please note Rest does not accept speculative resumes from recruitment agencies
Rest will review applications prior to the closing date and may close the role earlier
Join a purpose-led organisation where your expertise contributes to protecting member data, platforms and digital experiences.
Twelve-month opportunity to make a visible impact while helping advance Rest's application security maturity.
Sydney CBD Office Location, Hybrid Working
At Rest, we help more than 2 million Australians to build a better financial future. With around $112 billion in funds under management, we focus on delivering strong long-term outcomes for our members — from their first job through to retirement*. Your best at Rest means focusing on what matters, being trusted to get on with it, and knowing your work genuinely makes a difference. That’s how we operate every day, guided by our values: Be Daring, Keep It Simple, Take Action and Have Grit.
Join us as an Application Security Engineer - CTEM on a 12 Month Fixed Term Contract. This is your opportunity to make a real contribution to the financial wellbeing of millions of Australians.
About the Role
Embed within API and Platform Engineering to strengthen its mature application security and engineering practices, then scale those practices across Data Engineering, Investment Engineering and Digital Engineering. Provide risk-based cross-functional support that ensures application security findings are prioritised, remediated and tracked through to validated closure.
Accountabilities/Responsibilities
- Analyse and triage findings from SAST, DAST, SCA, secrets, API, container, infrastructure-as-code and other application security tooling, validating impact and identifying false positives, duplicates and systemic issues.
- Prioritise application security findings using severity, exploitability, asset criticality, exposure and business context, aligned to the vulnerability management process.
- Provide clear, practical remediation guidance and maintain end-to-end traceability between source findings, remediation tickets, accountable owners, due dates, exceptions and closure evidence.
- Own and coordinate secure SDLC controls across design, development, testing, release and ongoing maintenance, including control requirements, implementation guidance, evidence expectations and effectiveness reviews.
- Govern GitHub source-control security and application security integrations, including repository baselines, access reviews, branch protection, pull-request controls, code ownership, secrets protection, scanning, status checks, ticketing and exception handling.
- Monitor and report remediation backlog health, risk and trends; escalate overdue or blocked work; validate completed remediation; update security records; and coordinate risk exemptions through approval, review and expiry.
Experience, skills and qualifications
- Strong analytical capability and demonstrated experience triaging and prioritising application security findings.
- Working knowledge of SAST, DAST, SCA, secrets, API, container and infrastructure-as-code scanning, together with OWASP Top 10, API Security Top 10, common CWEs and software supply-chain risks.
- Experience defining, implementing and assessing secure SDLC controls across design, development, testing, release and ongoing maintenance.
- Ability to translate technical findings into clear, actionable remediation guidance for engineering teams.
- Experience with vulnerability management workflows, ticketing systems, backlog management, reporting and evidence-based closure.
- Strong GitHub source-control security knowledge, including repository governance, access models, branch protection, pull-request controls, code ownership, GitHub security features and application security integrations.
.What you'll find at Rest
- Hybrid working
- 5 Rest Days (wellbeing days) each year in addition to annual leave
- Eligible employees are entitled to 22 weeks paid parental leave (gender neutral)
- Continued super contributions during parental leave
- Learning and development opportunities, including AI & Data Academy, leadership programs, LinkedIn Learning, study assistance and professional memberships
- Income Protection Insurance
- Option to purchase additional leave
- Recognition through our Rest Excellence Awards
If you share our values and this sounds like the kind of place you’d do your best work, we’d like to hear from you. Apply now.
Rest is committed to creating a flexible work environment and culture that embraces diversity, equity, and inclusion - where people feel welcome, safe to be themselves and inspired to do their best.
We value the different backgrounds, lived experiences and abilities our diverse team brings. We welcome and encourage applications from candidates of all ages, cultural backgrounds, faiths, gender identities, sexual orientations and thinking styles. This includes people with disability, neurodiverse individuals, Aboriginal & Torres Strait Islander peoples and those with disrupted work history due to career or other breaks.
We welcome applications from all candidates. To be considered, you will need the right to work in Australia.
*Funds under management as at 30 June 2026. Rest is recognised as a superannuation leader across a range of areas including performance, responsible investment and member value. Find out more at https://rest.com.au/why-rest/awards.