Senior Security Consultant
- Flexibility That Works for You: Sydney based, modern hybrid setup 3 days in office, across Surry Hills and Norwest precincts.
- Blend Tech with Strategy: Stay hands on with your technical security skills while driving strategic client conversations.
We are Woolworths Group
200,000+ bright minds, passionate hearts and unique perspectives connected by a shared Purpose – ‘to create better experiences together for a better tomorrow.’ It’s that Purpose that fuels our ambition to explore new ideas, make brave commitments and innovate better ways to meet the food and everyday needs of more than 24 million customers every week.
If you’re excited to transform today’s blue sky thinking into a better tomorrow for future generations, you’ll find yourself supported and enriched in a dynamic, inclusive and empowering workplace that reflects the diverse communities we serve. With a culture of genuine care, a flexible approach to work and opportunities across the group to grow your career and make a meaningful impact, the possibilities for what we can achieve together are endless.
What you’ll do
As a Senior Security Consultant, you will serve as a trusted cyber security technical advisor, working closely with business leaders, IT teams, external partners, and colleagues across the Cyber Security function. Aligned within one or more key technology domains, you will provide security direction to ensure solutions are secure by design.
In this position, you will facilitate and manage the engagement of security services throughout the entire project lifecycle, from ideation and planning through design and execution. You will offer on-demand guidance aligned with security policies, industry standards, and best practices, empowering teams to innovate safely while maintaining a strong security posture across the enterprise.
- Domain Advisory: Build strong stakeholder relationships to deliver tailored security guidance across the entire technology solution lifecycle.
- Risk Assessment: Collaborate with business and risk partners to define security requirements using risk and business impact assessments.
- Service Integration: Facilitate key security engagements including pen testing, code scans, and architectural reviews tailored to domain needs.
- Remediation & Escalation: Serve as the primary contact for assigned domains, providing hands-on support to track and resolve security issues.
- Governance & Standards: Champion security policies, patterns, and best practices while driving continuous improvement of governance artifacts.
- Executive Reporting: Provide clear communication and reporting to Cyber Leadership and Senior Management regarding residual risks and vulnerabilities.
- Lifecycle Security: Embed security controls and industry-leading practices into application development, IT acquisitions, and critical projects.
- Leadership: Coach and mentor junior team members while continuously improving security consulting workflows and service delivery.
What you’ll bring
- 5+ years of IT/Security experience with deep knowledge of risk assessment methodologies (business impact, vulnerability) and embedding security architecture across strategic and project levels.
- Strong understanding of core enterprise domain tech (e.g., supply chain, finance, infrastructure, digital) alongside hands-on experience with technical security solutions and tools.
- In-depth knowledge of cloud security (specifically GCP), the OWASP top 10, AI security frameworks, and practical experience with DevSecOps practices.
- Proven ability to translate complex security risks into clear, business-relevant impacts and effectively influence stakeholders across all organizational levels.
- Solid grasp of project management fundamentals to seamlessly embed security requirements throughout the software and systems delivery lifecycle.
- Exceptional analytical skills to assess complex technology environments, pinpoint root causes, and engineer practical mitigation strategies.
- Certifications & Attributes: Familiarity with major security management frameworks (CISSP, CISM, or CRISC highly desirable), combined with a collaborative, self-driven mindset and a commitment to continuous learning.
What you'll experience
- A commitment to flexibility through a hybrid working model which combines time spent at a support office or hub and time working from home, supporting both in-person connection and balancing the flexibility that remote working provides for our teams.
- High-impact role supporting our teams who enrich our communities.
- A global business with endless career possibilities around every corner and across every discipline - with valuable exposure to a vast and exciting business network.
- A range of programs to help you prioritise and manage your wellbeing, including 24/7 access to the Sonder app.
- A progressive and competitive leave policy that gives you more space for what matters to you.
- Team discounts across our range of Woolworths Group brands you know and love and a robust rewards program that celebrates and incentivises purpose-driven work.
Everyone belongs at Woolworths Group
Diversity, equity, inclusion, and belonging are key to realising our purpose of better together for a better tomorrow. We recognise the value our team’s diversity brings to our business, customers, and communities and that teams with diverse experiences and backgrounds enrich our group and are better able to innovate and solve problems. As one of the largest employers in Australia and New Zealand, we aim to create a truly inclusive workplace where everyone feels that they belong, can be their best selves, and reach their full potential.