NextGen

Graduate Application Security Analyst

NextGen Sydney, New South Wales, Australia

IT Services and IT Consulting · 201-500 employees

11 h ago
security Junior (0-2 yrs) Full-time Australia
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The analyst will manage automated security scans, validate vulnerabilities, and coordinate remediation efforts with development teams. They will also ensure audit compliance for standards like SOC 2 and PCI-DSS while supporting secure development practices.

What they look for

Application Security Vulnerability Assessment Burp Suite Rapid7 SQLi XSS CSRF Security Testing Compliance SOC 2 PCI-DSS CDR Automation Code Assessment Technical Communication

Requirements

Candidates should have up to two years of experience and a solid understanding of web application vulnerabilities. Strong communication skills and a demonstrated passion for security through self-directed learning or community involvement are essential.

Benefits

Flexible working arrangements Collaborative environment Inclusive culture Professional development

Full description

Who is NextGen?

NextGen is a leader in Australian financial technology, providing innovative SaaS solutions to streamline mortgage processing and Open Banking for the nation's lenders, brokers and customers. Find out more about us here.

What does a Graduate Application Security Analyst do at NextGen?

As a Graduate Application Security Analyst you will help protect NextGen’s software and services by supporting secure development practices across the product lifecycle. Working with security, engineering and product teams, you will help identify and assess vulnerabilities, contribute to security testing and promote practical ways to build safer applications. This is an opportunity to develop your application security skills in a collaborative fintech environment, with guidance from experienced colleagues.

Key Responsibilities

  • Manage Automated Scans: Schedule, configure, authenticate, and tune recurring Rapid7 AppSec scans across 150+ sites, using AI and automation to streamline scanning, logging, and tracking.
  • Validate & Triage Findings: Manually validate High and Critical vulnerabilities in Burp Suite Pro, eliminate false positives, and document reproduction steps and business impact.
  • Coordinate Remediation: Partner with development teams to agree on fixes and timelines, track progress, and retest live code to confirm resolution before closing findings.
  • Ensure Audit Compliance: Maintain audit-ready test certification data and evidence to satisfy CDR, SOC 2, and PCI-DSS compliance requirements.
  • Support Application Security Programs: Assist with pre-deployment code assessments and validate or rule out externally reported vulnerability disclosures.

Essential Skills & Experience

  • Experience & Background: Up to two years of post-study experience, backed by a degree, non-traditional education (bootcamp/TAFE), or an internal transition from IT/dev roles.
  • Core Vulnerability Knowledge: Practical understanding of common web application vulnerabilities (e.g., SQLi, XSS, CSRF), including exploitation and remediation methods.
  • Demonstrated Passion & Curiosity: Hands-on self-directed learning or community involvement, such as PortSwigger Academy, CTFs, TryHackMe/HackTheBox, or home labs.
  • Technical Skills & Work Habits: Basic exposure to interception proxies like Burp Suite, alongside methodical habits and the capability to handle high-volume repetitive tasks.
  • Communication & Autonomy: Strong written and verbal skills to communicate with technical and non-technical stakeholders, combined with comfort working independently under manager direction.

What we offer

Growth: Structured onboarding, guidance from experienced security and engineering colleagues, and opportunities to build practical application security skills.

Flexible Working: Support for flexible working arrangements to help maintain work-life balance in a collaborative and inclusive environment.

Supportive Culture: Join a team that values learning, psychological safety and the opportunity to make a measurable impact on products used by customers and partners.

How to apply

If you are keen to start your career in application security and contribute to secure fintech products, please apply with your CV and a short cover letter outlining your relevant skills, experience and interest in the role.

Similar roles