Posted 01 August, 2026
Senior / Lead Pentester - based in Auckland
Bastion Security Group
Auckland, AUK, NZ
Full Time
Reference: 7d748c2f1ccab34d
Job Description
Senior / Lead Pentester – based in Auckland Bastion Security Group – Auckland, North Island Ready to join a team built on excellence? At Bastion, our international team of cyber security experts deliver world class results, with industry leading tools, and a commitment to end to end protection of our clients, from our offices in Wellington and Auckland. This role is based in Auckland. We empower our people to assess, detect, respond, and recover before threats become crises. If you're someone who thrives in a dynamic environment and enjoys being responsible for finding solutions for your clients. Whether your expertise is hands on and technical or rooted in strategy, operations, or client support, you’ll be part of a collaborative group committed to safeguarding businesses, government agencies, and communities. Join us as we build a safer, more resilient digital and physical world. As a Senior / Lead pentester, you take charge on penetration testing of client’s applications and environments, have the tenacity to solve complex problems, and discuss real world impacts with key stakeholders. Our Offensive Security Services (OSS) teams are integral to the successful running of our busy cybersecurity consultancy with offices in New Zealand and Australia. The role This is a fast-paced and varied role, working closely with an exciting range of clients across New Zealand and afar, from small kiwi-owned businesses to well-known public sector organisations, that have a variety of risks and future maturity goals. Your responsibility will cover the full engagement lifecycle including, scoping, setup, testing, reporting, internal QA, summary meetings, and engaging with clients to utilise your specialist skills to have issues resolved. You’ll be working closely with an exciting range of clients across New Zealand and afar, from small kiwi-owned businesses with 5 people through to public sector organisations and Fortune 500 companies. The main responsibilities of the role are: Lead client engagements and projects, ensuring timely and high-quality delivery of your own and other consultants’ work. Web application penetration testing, network penetration testing, mobile application penetration testing, cloud security reviews, source code reviews, and general security consulting. Produce high-quality reports on issues that you identify Brief and de-brief other consultants on projects you manage. Act as an escalation point for client problems, communicating in person and online. Nurture and grow our client base. Who we’re looking for A results orientated, high performer across pentesting, adding exceptional value to the clients you work with. You are already based in Auckland, with a permanent right to work or a valid work visa with no restrictions. Someone supportive and collaborative, assisting others through their technical journey, whilst also keeping up to date and getting involved in research and tooling yourself. These are the main skills and experience we’re looking for: 2-5 years’ experience in the security industry. Strong knowledge of information security. You’re at home with penetration testing tools and methodologies. You might hold security certifications such as OSCP, OSCE, CREST, GPEN, GWAPT, GXPN, or GMOB OWSE, though this is not essential. Skilled at analysing information, asking questions, and solving problems. You manage your time effectively, take ownership of projects or tasks to deliver work on time, and use your initiative to get stuff done! Confidently communicate your knowledge to a range of people, whether presenting, on the phone, or writing a report or email. Previous experience advising clients within public and enterprise sectors. (Note this is not an opportunity for a new graduate) Due to the nature of our work, this role requires a clean criminal record. Successful applicants will be required to complete a criminal record check during the onboarding process. Great things to include in your cover letter include: Attended or presented at a security conference. Published any vulnerabilities (especially if CVEs assigned). A security blog that you post on. Participating in Capture-the-Flag events. Developing and maintaining penetration testing methodologies. GitHub account to showcase code. Your own security tools. Participation in bug bounties on theHackerone or Bugcrowd platforms. Benefits of working for Bastion You will work alongside an expert group of consultants and penetration testers who are dedicated to protecting others from cyber harm. The perks of being part of the Bastion team include: A collaborative, thoughtful team who do meaningful work and keep learning Supportive work environment, great team culture and regular social events Training budget, study time allowance, regular internal training sessions and internal mentor programme Competitive remuneration Half yearly bonus scheme Additional leave after 2 years Access to a gymwithin a short walk of the office. About us Bastion Security Group provides best-in-class cybersecurity services through a high-performance culture built on quality, excellence and collaboration. Our skilled and empowered team is dedicated to achieving meaningful security outcomes and delivering lasting value for our clients. ‘Assess & Improve’, ‘Detect & Respond’, ‘Protect & Secure’, ‘Advise & Empower’ and stay ahead of evolving threats. We deliver security services across strategy, architecture, operations and compliance. Whether it’s advising on board-level risks, embedding into your teams, or responding to incidents, our experts provide actionable insight grounded in real threats and real solutions. To learn more about our New Zealand operation, visit https://bastionsecurity.co.nz/. Our Australian offices - https://www.cythera.com.au/; https://www.seamlessintelligence.com.au/; https://www.phronesissecurity.com/; https://www.astralas.com/ #J-18808-Ljbffr