Job detail for Director, Offensive Security

G
Director, Offensive Security
Grant Thornton
Todayvia fourdayweek

Use AI to assess how you fit

  • Build and lead a differentiated offensive security capability within our Cyber Resilience practice

  • Shape an AI-enabled delivery model designed to scale locally and globally

  • Work with global teams, strategic technology partners and clients to help organisations stay ahead of fast-evolving cyber threats

Grant Thornton Australia is one of Australia’s leading professional services firms, providing audit, tax, and advisory services to a diverse range of clients.

Our culture is underpinned by a commitment to our clients, people and communities, and our promise to ‘Reach for Remarkable’ by providing proven expertise, principled execution, and personalised experience.

In Australia we're proud to support the careers of more than 1,500 remarkable people. Backed by six Australian offices and a global network spanning more than 150 markets, we offer the scale, connections and opportunities to help you shape your future, wherever it takes you.

About this role

Have you built and led client-facing penetration testing teams in professional services, but would do things differently if you had a blank sheet of paper today? We are seeking a commercially minded and forward-thinking Director, Offensive Security to help build, lead and scale our offensive security capability within Grant Thornton’s Cyber Resilience practice.

This is a unique opportunity for someone who understands how rapidly AI, automation, tooling and partner ecosystems are disrupting both cyber-attacks and offensive security delivery models and can translate that disruption into better client outcomes and a compelling growth opportunity for the firm.

Working closely with local Partners, global teams and trusted technology partners, you will develop a scalable offensive security, vulnerability management and Continuous Threat Exposure Management (CTEM) capability that combines deep technical credibility with practical commercial models.

You will help clients understand, validate and reduce their cyber risk profile through both point-in-time engagements and fully managed services, including penetration testing, red team and purple team exercises, adversary simulation, cloud and application security testing, vulnerability management, exposure prioritisation, continuous security validation, attack path analysis, and executive-level cyber resilience advice.

What You’ll Do:

  • Build and lead the offensive security practice: Establish the strategy, service offerings, operating model, methods, quality standards and growth plan for a market-relevant offensive security team that delivers both point-in-time assurance and managed offensive security services.

  • Scale through technology and partners: Develop an AI-enabled and partner-led delivery model that improves speed, quality, consistency and reach, while maintaining strong governance, assurance and client trust.

  • Lead go-to-market activity: Shape propositions, campaigns, client conversations and commercial models that respond to local market needs while leveraging global Grant Thornton capability.

  • Deliver trusted client outcomes: Lead senior client relationships, translate technical findings into executive-level risk insight, and ensure offensive security work drives practical remediation and measurable resilience improvement.

  • Modernise offensive security delivery: Identify how AI, automation, attack simulation, testing orchestration and continuous validation can evolve point-in-time testing into scalable, intelligence-led assurance.

  • Grow vulnerability and exposure management services: Extend offensive security services into vulnerability management and Continuous Threat Exposure Management, helping clients identify attack surfaces, prioritise exploitable exposures, validate business impact and mobilise remediation through both targeted point-in-time assessments and ongoing managed exposure management services.

  • Lead people and capability: Recruit, develop, coach and retain a high-performing team, creating a culture that values curiosity, technical excellence, collaboration, commercial discipline and responsible innovation.

  • Collaborate across the firm: Work with cyber resilience, technology risk, incident response, managed security, global delivery teams and alliance partners to create integrated solutions for clients.

What You’ll Bring:

  • Senior offensive security experience: Significant experience in offensive security, penetration testing, red teaming, adversary simulation, security assurance or cyber consulting, including experience leading complex client engagements.

  • Customer-facing consulting and sales capability: Proven ability to build trusted client relationships, originate and shape opportunities, develop proposals, lead pursuits, manage commercial outcomes and deliver high-quality client work.

  • Strategic and commercial mindset: Ability to see where the market is heading, understand client demand, assess delivery economics, and build offerings that are differentiated, scalable and commercially sustainable.

  • Technical credibility: Strong understanding of offensive security methods across application, infrastructure, cloud, identity, network, endpoint and emerging technology environments, with the judgement to know when to bring specialist expertise into the conversation.

  • AI and automation fluency: Practical understanding of how AI, automation, agentic workflows and modern tooling are changing cyber-attack techniques and offensive security delivery, including the risks, controls and opportunities this creates for clients.

  • Vulnerability and exposure management expertise: Strong understanding of vulnerability management, attack surface management, exposure prioritisation, exploitability validation and remediation mobilisation, including how CTEM programs bring together people, process, platforms and evidence-based risk reduction.

  • Relevant technology awareness: Familiarity with platforms such as Qualys, Tenable, Horizon3.ai, Rapid7, Microsoft Defender Vulnerability Management, CrowdStrike Falcon Exposure Management, Wiz, Orca Security, XM Cyber, Cymulate, Pentera and Nucleus Security would be advantageous; the emphasis is on using technology to improve prioritisation, validation and measurable risk reduction rather than on any single toolset.

  • Market and regulatory awareness: Strong awareness of the Australian cyber market, buyer expectations, procurement drivers and relevant standards, including APRA CPS 234, the Australian Government Information Security Manual, Essential Eight, ISO 27001, PCI DSS and privacy obligations where relevant.

  • Leadership and people skills: Demonstrated ability to lead technical and consulting teams, develop talent, set clear expectations, manage quality, and create an inclusive, high-performing team culture.

  • Global collaboration: Experience working with global teams, delivery centres, alliance partners or specialist providers to deliver consistent client outcomes across markets.

Why Join Us

  • A unique market moment: Offensive security is being disrupted at lightning speed by AI, automation and changing attacker behaviour. This role gives you the opportunity to shape how clients respond, and how Grant Thornton builds a differentiated capability in the market.

  • Client impact: Help organisations understand where they are exposed, validate whether their controls work, and prioritise action against an increasingly complex cyber threat landscape.

  • Commercial ownership: Build propositions, partnerships and delivery models that create real business growth for the Cyber Resilience practice.

  • Local and global reach: Work with Australian clients while drawing on global capability, alliance relationships and specialist teams to deliver at scale.

  • Career growth: Take a visible leadership role in a growing practice, with the opportunity to shape capability, mentor others and grow toward broader leadership pathways.

Relevant Qualifications and Credentials

  • CREST credentials: CREST Practitioner Security Analyst, CREST Registered Penetration Tester and/or CREST Certified Tester credentials are highly relevant for the Australian market; CREST Certified Red Team Specialist or Manager credentials would be advantageous for senior red team leadership.

  • Offensive security qualifications: OSCP, OSCE3, OSEP, OSWE, CRTO, GIAC GPEN or equivalent practical offensive security certifications are desirable and demonstrate applied technical depth.

  • Security leadership qualifications: CISSP, CISM, CCSP, SABSA, TOGAF or similar credentials are useful for senior client engagement, security leadership and architecture-oriented conversations.

  • Cloud and platform certifications: Relevant cloud security qualifications across Microsoft Azure, AWS or Google Cloud are advantageous, particularly where offensive security services include cloud, identity, application and infrastructure testing.

  • Australian market requirements: Experience working to recognised testing methodologies, rules of engagement, ethical standards, secure handling of client data, and Australian regulatory expectations is essential; exposure to government or critical infrastructure assurance requirements would be advantageous.

If you’re interested in this role but don’t feel that you match every single one of our requirements, we would still love to hear from you and explore the unique skillset and attributes that you can bring to the team.

Reach your remarkable

At Grant Thornton we do things differently because we understand that when you strive for better and care about what you do remarkable things are possible. We’re a dynamic and authentic mix of backgrounds, perspectives and ways of thinking. We’re driven by our shared purpose – we ignite the potential within our people and clients to create enduring success and positively shape the communities around us.

With us, you’ll be exposed to challenging and rewarding opportunities – building your confidence and capabilities at every step. You’ll be supported, motivated and inspired by a team of passionate and caring collaborators and leaders. You’ll be empowered to build a career path that’s tailored to you and encouraged to make a meaningful difference. And we’ll make sure the excellence you deliver and the impact you make is always seen, felt and celebrated.

Remarkable perks that put you first:

  • 9-day fortnight with no salary reduction

  • Flexible working options available

  • Fully funded gym membership

  • Mental health support, financial and wellbeing coaching

  • And many more!

Need some help applying or participating in the recruitment process?

We are committed to ensuring our recruitment process is inclusive and accessible for anyone who wishes to apply, and we warmly encourage applications from individuals from diverse backgrounds including Aboriginal and/or Torres Strait Islanders, those in the LGBTQI+ community and individuals who identify as having disability or are neurodivergent.  Click here for recruitment support information and to learn more about Diversity, Equity and Inclusion at Grant Thornton.

Should you have questions or require any adaptations or additional support for your individual circumstances so you may perform at your best during the application or recruitment process please contact our Talent Acquisition team at gttalentscouts@au.gt.com

As we provide fair consideration and evaluation to a high volume of applications, we endeavour to provide feedback on your application at the earliest opportunity.

#LI-Hybrid