Security Software Engineer
Job description
NOJA Power designs, manufactures and supplies medium voltage switchgear products to over 117 countries globally. The Group operates from our manufacturing campus and global headquarters in Murarrie, Brisbane with Factory and Offices in Brazil, Canada, UK, USA, China and Vietnam.
We are committed to an inclusive environment where people feel comfortable to be themselves. We want our people to feel that their voices are heard, all cultures respected and that a variety of perspectives are not only welcome, but they are also essential to our success.
About the Role
We are seeking a talented Security Software Engineer with strong experience in Cyber Security Testing and Development to join our growing R&D team. This is an exciting opportunity to contribute to Australian technology that is deployed globally across mission-critical industrial and utility environments.
Reporting to the R&D General Manager, you will be responsible for designing, developing, and maintaining software for embedded Linux platforms, working across the full software development lifecycle from concept through deployment and support.
Key Responsibilities
· Identify, assess, and analyse security vulnerabilities in software, web applications, mobile applications, APIs, embedded systems, and networked devices.
· Perform security testing using manual and automated techniques, including vulnerability assessments and penetration testing.
· Research, reproduce, validate, and document security vulnerabilities and potential attack vectors.
· Conduct secure code reviews to identify security weaknesses and recommend remediation measures.
· Design and develop scripts and tools to automate security testing, vulnerability discovery, and reporting activities.
· Assist in threat modelling and security risk assessments for new and existing products.
· Collaborate with Software Developers, Quality Analysts, and Product Teams to ensure security requirements are incorporated throughout the development lifecycle.
· Verify the effectiveness of security fixes and mitigations.
· Investigate emerging threats, vulnerabilities, security advisories, CVEs, and industry best practices.
· Produce clear technical reports detailing findings, risk levels, exploitation scenarios, and remediation recommendations.
· Communicate security risks and recommendations effectively to both technical and non-technical stakeholders.
· Contribute to security documentation, standards, testing procedures, and continuous improvement initiatives.
What You’ll bring:
· University degree in cyber security, Software Engineering, Computer Science, Information Technology, Electrical Engineering, or a related discipline.
· Understanding of cybersecurity fundamentals including confidentiality, integrity, availability, authentication, authorization, and secure design principles.
· Knowledge of common vulnerability classes such as OWASP Top 10, CWE, CVE, and CAPEC.
· Familiarity with web application, API, network, and mobile application security concepts.
· Understanding of operating systems including Windows and Linux.
· Experience developing software or scripting in Python, C/C++, JavaScript, PowerShell, Bash, or similar languages.
· Familiarity with security testing tools such as Burp Suite, OWASP ZAP, Nmap, Wireshark, Nessus, OpenVAS, or equivalent.
· Understanding of secure coding principles and software development practices.
· Knowledge of networking concepts including TCP/IP, SSL/TLS, DNS, HTTP/HTTPS, and common network protocols.
· Strong analytical, troubleshooting, investigative, and problem-solving skills.
· Excellent written and verbal communication skills.
· Ability to document findings clearly and provide actionable recommendations.
· Demonstrated passion for cybersecurity, security research, and continuous learning.
Desirable
Skills
· Experience with vulnerability assessment or penetration testing through university projects, internships, labs, or personal research.
· Familiarity with embedded Linux, IoT, OT, or industrial control systems security.
· Knowledge of industrial protocols such as IEC 61850, DNP3, Modbus, IEC 60870-5-104, or SCADA systems.
· Experience with secure code review tools and static/dynamic application security testing (SAST/DAST).
· Familiarity with threat modelling methodologies.
· Experience with CI/CD pipelines and integrating security testing into DevSecOps workflows.
· Knowledge of cloud security concepts across AWS, Azure, or Google Cloud.
· Exposure to vulnerability management platforms and CVSS scoring.
· Experience with Linux security hardening and system administration.
· Experience working within Agile/Scrum development environments.
What we offer
· A work environment where safety is always number one priority.
· A permanent position working for NOJA Power.
· A competitive salary reflective of your skills and experience.
· Career development and opportunities to grow your knowledge.
· Job security, knowing you’re working for an award-winning successful manufacturer which is Australian owned, operated and based in Brisbane.
This role will provide you the challenges and rewards you have been searching for.
Applications close on 30-October-2026
Applications should be sent to:
NOJA Power Switchgear Pty Ltd
16 Archimedes Place, Murarrie Qld 4172
Ph: 07 3907 8777
Email: [email protected]
Skills mentioned
- Agile
- API
- Authentication
- AWS
- Azure
- Bash
- Burp Suite
- C
- CI Cd
- Cloud Security
- Code Review
- Control Systems
- C++
- Cybersecurity
- Dast
- Devsecops
- DNS
- Electrical Maintenance
- Embedded Linux
- GCP
- JavaScript
- Linux
- Modbus
- Networking
- Nmap
- Owasp
- Penetration Testing
- Powershell
- Process Improvement
- Python
- Reporting & Documentation
- Sast
- Scada
- Scrum
- Secure Coding
- SSL
- TCP IP
- TLS
- Troubleshooting
- Wireshark
Apply for this job
Use the application link supplied with this listing to apply to NOJA Power. Check the destination before entering personal information.

