MedHealth Logo

MedHealth

Application Security Technical Lead

Posted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Melbourne, Victoria, AUS
Senior level
In-Office or Remote
Hiring Remotely in Melbourne, Victoria, AUS
Senior level
Own and continuously improve application security across the SDLC, including secure code reviews, threat modeling, risk assessment, AppSec tooling, vulnerability reporting, secure design standards, and Security Champion programs. Partner with development teams across varying maturity levels to embed effective security practices in Azure and CI/CD environments while maintaining delivery velocity. Mentor developers and strengthen secure coding capabilities.
The summary above was generated by AI
Company Description

MedHealth are a purpose-built collection of industry leading health, medical and employment brands. Our unique and diverse capabilities come together to get the best possible health and employment outcomes for you and the people you support. We support whole populations to better outcomes, yet never lose sight of the individual we are working with to build a better life through work and health.

Job Description

We’re looking for an experienced Application Security Technical Lead to own and run application security across MedHealth.

This is a hands-on role responsible for operating and continuously improving an established AppSec capability — ensuring security practices, tooling and processes are effectively embedded into development workflows.

You will work across multiple applications and development teams, each with varying levels of application security maturity, tailoring your approach to uplift capability while maintaining delivery alignment.

Key responsibilities

  • Own and operate application security across the SDLC
  • Identify and assess application security risks, partnering with Engineering teams on remediation
  • Perform secure code reviews (primarily .NET) and support secure development practices
  • Lead threat modelling and security assessments across applications and automation workflows
  • Adapt security practices to suit different team maturity levels, balancing uplift, standardisation and delivery needs
  • Own and optimise AppSec tooling (SAST, DAST, SCA) across CI/CD pipelines
  • Ensure effective security testing without impacting delivery velocity
  • Own vulnerability visibility, prioritisation and reporting
  • Define and apply secure design and development standards
  • Establish Security Champions across development teams
  • Mentor developers and uplift secure coding capability across teams

Qualifications

What You’ll Bring

  • 5+ years’ experience in software engineering including 2+ in an application security role.
  • Strong experience with DevSecOps and CI/CD environments
  • Hands-on experience with AppSec tools (SAST, DAST, SCA)
  • Strong experience working in Azure environments and Azure DevOps pipelines
  • Comfortable reviewing code (C#, .NET, web applications)
  • Strong understanding of OWASP Top 10 and secure design principles
  • Experience working across multiple teams or platforms with varying maturity levels
  • Able to adapt approach based on risk, complexity and delivery context
  • Self-driven, accountable and strong at stakeholder engagement

Additional Information

Why you’ll love it here:

  • Ability to own and run a mature Application Security capability
  • Work across a diverse application landscape and multiple engineering teams
  • Work somewhere serious about cybersecurity done right.
  • A culture that values continuous improvement, learning, and knowledge sharing.
  • Great balance of working from home and office collaboration.

You are welcome here.

Our fast-growing team of more than 4,000 people around Australia represent a huge array of life experiences, skills and ways of thinking. We value all these differences. 

We are an Equal Opportunity Employer, proudly welcoming people with disability including mental health conditions, people from diverse cultural and linguistic backgrounds, people from the LGBTQIA+ community, veterans, carers and Indigenous Australians to our team.

We are happy to adjust our recruitment process to support accessibility needs.
 

HQ

MedHealth Melbourne, Victoria, AUS Office

Melbourne, Australia

Similar Jobs

Yesterday
Remote or Hybrid
Melbourne, Victoria, AUS
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Leads reactive and proactive incident response engagements across the Asia Pacific and Japan region. Performs advanced host and network forensics across Windows, macOS, and Linux; advises customers during security incidents; develops remediation plans; produces reports and presentations; communicates with technical and executive audiences; mentors junior consultants; and contributes cybersecurity thought leadership through public content and speaking.
Top Skills: Ai TechnologiesComputer Forensics ToolsLinuxmacOSNetwork Analysis ToolsNetwork LogsNetwork ProtocolsWindows
2 Days Ago
Remote
Australia
Senior level
Senior level
Productivity • Software • App development • Automation
Manage and close enterprise B2B software license opportunities across Australia and New Zealand. Responsibilities include qualifying leads, managing the full sales cycle, identifying customer needs through consultative selling, collaborating with solution engineers, presenting competitive value, researching markets and prospects, and achieving sales quotas. The role requires engaging business and technical executives, including CTOs and product or engineering leaders, while maintaining pipeline activity in a CRM.
Top Skills: CRMDocument Processing SdksmacOSWindows
4 Days Ago
Remote or Hybrid
Melbourne, Victoria, AUS
Mid level
Mid level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Investigate and triage security events across customer environments, conduct incident response and forensic investigations, analyze malware, identify root causes, and recommend remediation. Produce MITRE ATT&CK-aligned incident reports, communicate findings to customers, collaborate with threat intelligence and detection engineering teams, and contribute to detection improvements and team mentoring within a 24/7 MDR SOC.
Top Skills: BloodhoundCloud EnvironmentsEndpoint Detection And ResponseLinuxmacOSMetasploitMimikatzMitre Att&CkRapid7SIEMUser Behavior AnalyticsWindows

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account