Description & Requirements
At Bupa, purpose meets possible. Join us and help shape a future where healthcare is more connected, more personal and more human. We are a global healthcare leader trusted by millions and committed to helping people live longer, healthier, happier lives and making a better world.
The purpose of this role
As a Security Test Lead at Bupa Technology, you will lead the quality assurance of security across enterprise applications, APIs, cloud platforms and CI/CD pipelines. This technical leadership role is responsible for defining and driving security testing strategies, vulnerability management, DevSecOps integration and security automation practices across multiple delivery teams. You will ensure Bupa releases meet the highest security standards while enabling teams to deliver securely, efficiently and at scale.
This is an exciting opportunity for an experienced application security professional to embed security throughout the software development lifecycle, influence engineering practices and champion an automation-first approach. You will partner with engineering, security and business stakeholders to proactively identify, assess and mitigate security risks while improving security maturity across the organisation.
What you’ll need to make it possible
- 8+ years of experience in Security Testing, Application Security, Penetration Testing or Security Engineering.
- Degree in Information Security, Cyber Security or related discipline, or equivalent experience.
- Professional security certification such as CISSP, CISM, CCSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, CEH or eWPT.
- Hands-on expertise in penetration testing of web, desktop, API and cloud-based applications.
- Strong knowledge of SAST, DAST, SCA, IaC scanning, container security and secure SDLC practices.
- Experience integrating security testing into Azure DevOps, CI/CD pipelines and DevSecOps environments.
- Proven leadership experience mentoring teams and driving security testing strategies across complex programs.
- Experience with Checkmarx, NexusIQ, SonarQube and security automation frameworks.
- Strong stakeholder management, communication and influencing skills.
- Experience working in regulated industries such as healthcare or financial services will be highly regarded.
Key responsibilities
- Lead end-to-end security testing activities across programs and delivery teams.
- Define security test strategies and ensure consistent execution across ST, SIT, UAT and PVT phases.
- Perform security assessments, penetration testing and secure code reviews.
- Drive adoption of security automation and DevSecOps practices.
- Lead proof-of-concepts and evaluation of security testing tools and platforms.
- Facilitate threat modelling, vulnerability management and risk mitigation activities.
- Mentor quality engineering teams and promote security-first practices.
- Collaborate with development, DevOps and security teams to improve security outcomes.
- Ensure accurate reporting, audit readiness and regulatory compliance.
Why you’ll love it
We support our people to be the healthiest and happiest versions of themselves. Through the Viva Healthier and Happier program, we provide a range of health and wellbeing benefits, career development opportunities and a workplace where your contributions are valued.
If this sounds exciting, we’d love to hear from you. Let’s shape the future of healthcare, together.
At Bupa, your wellbeing, identity and personal story are respected and valued. We are committed to building diverse teams that reflect the communities we serve and fostering an inclusive workplace free from discrimination, bullying and harassment. We encourage applications from people of all backgrounds and experiences, including Aboriginal and Torres Strait Islander peoples, veterans, people with disabilities and LGBTQIA+ communities.