Graduate Application Security Analyst
A home for your career
We usually respond within three days
Who is NextGen?
NextGen is a leader in Australian financial technology, providing innovative SaaS solutions to streamline mortgage processing and Open Banking for the nation's lenders, brokers and customers. Find out more about us here.
What does a Graduate Application Security Analyst do at NextGen?
As a Graduate Application Security Analyst you will help protect NextGen’s software and services by supporting secure development practices across the product lifecycle. Working with security, engineering and product teams, you will help identify and assess vulnerabilities, contribute to security testing and promote practical ways to build safer applications. This is an opportunity to develop your application security skills in a collaborative fintech environment, with guidance from experienced colleagues.
Key Responsibilities
Manage Automated Scans: Schedule, configure, authenticate, and tune recurring Rapid7 AppSec scans across 150+ sites, using AI and automation to streamline scanning, logging, and tracking.
Validate & Triage Findings: Manually validate High and Critical vulnerabilities in Burp Suite Pro, eliminate false positives, and document reproduction steps and business impact.
Coordinate Remediation: Partner with development teams to agree on fixes and timelines, track progress, and retest live code to confirm resolution before closing findings.
Ensure Audit Compliance: Maintain audit-ready test certification data and evidence to satisfy CDR, SOC 2, and PCI-DSS compliance requirements.
Support Application Security Programs: Assist with pre-deployment code assessments and validate or rule out externally reported vulnerability disclosures.
Essential Skills & Experience
Experience & Background: Up to two years of post-study experience, backed by a degree, non-traditional education (bootcamp/TAFE), or an internal transition from IT/dev roles.
Core Vulnerability Knowledge: Practical understanding of common web application vulnerabilities (e.g., SQLi, XSS, CSRF), including exploitation and remediation methods.
Demonstrated Passion & Curiosity: Hands-on self-directed learning or community involvement, such as PortSwigger Academy, CTFs, TryHackMe/HackTheBox, or home labs.
Technical Skills & Work Habits: Basic exposure to interception proxies like Burp Suite, alongside methodical habits and the capability to handle high-volume repetitive tasks.
Communication & Autonomy: Strong written and verbal skills to communicate with technical and non-technical stakeholders, combined with comfort working independently under manager direction.
What we offer
Growth: Structured onboarding, guidance from experienced security and engineering colleagues, and opportunities to build practical application security skills.
Flexible Working: Support for flexible working arrangements to help maintain work-life balance in a collaborative and inclusive environment.
Supportive Culture: Join a team that values learning, psychological safety and the opportunity to make a measurable impact on products used by customers and partners.
How to apply
If you are keen to start your career in application security and contribute to secure fintech products, please apply with your CV and a short cover letter outlining your relevant skills, experience and interest in the role.
- Division
- Technical Services
- Department
- Cyber Risk & Security
- Role
- Cyber Security Analyst
- Location
- North Sydney
- Remote status
- Hybrid
About NextGen
NextGen is Australia's leading technology partner to the lending industry
We create state-of-the-art solutions, from loan application through to processing and settlement. Our mission is to provide lenders, aggregators and brokers an easier and more efficient way to deliver for their customers.