Skip to main content Skip to main navigation
Australian Public Service Academy Australian Public Service Academy Australian Public Service Academy Australian Public Service Academy logo

APSLearn logo

APSLearn Login

APS Professions logo
Professions MCP Portal

Main navigation

  • APS Craft

    APS Craft

    • Integrity
    • Working in Government
    • Engagement & Partnership
    • Implementation & Services
    • Strategy, Policy & Evaluation
    • Leadership & Management
  • APS Professions

    APS Professions

    • Complex Project Management Profession
    • Data Profession
    • Digital Profession
    • Evaluation Profession
    • HR Profession
    • Procurement and Contract Management Profession
  • APS People

    APS People

    • Diversity and Inclusion
    • Health and Wellbeing
    • Work Health and Safety
    • Your APS Career
  • APS Induction
  • Learning Experiences

    Learning Experiences

    • Courses
    • Course session dates
    • Microcredentials
    • Events
    • Resources
    • Cross Agency Training Hub
    • Nationwide course sessions
    • SES Executive Coaching
  • Our Services

    Our Services

    • APSLearn
    • APS Academy course offerings
    • APS Academy Training Venues
    • Onboard learning experiences
    • Share and reuse learning experiences
  • L&D Guide

    L&D Guide

    • Learning Design and Administration
    • Learning Culture
    • The Learner and Career Development
    • Learning Technologies
    • Procurement in L&D
    • Evaluating Learning
    • L&D Search
  • News

    News

    • Academy News
    • MyAcademy
  • About us

    About us

    • About the APS Professions
    • Faculty
    • Learning approach
    • Contact
    • Supplier FAQ's

Day in the life of a penetration tester (APS 4/5)

Image representing recruitment and job opportunities. A magnifying glass highlighting the word “JOB” is positioned above a row of wooden blocks displaying icons for candidate search, a résumé, skills or problem-solving, partnership, and successful hiring.

You are here

  1. Home
  2. Learning Experiences
  3. Resources
  4. Day in the life of a penetration tester (APS 4/5)
  • Linkedin
  • Twitter
  • Facebook
  • Email
Print
Contents

Find out what it’s like to work as a penetration tester (APS 4/5) in the Australian Public Service (APS).

We spoke to a number of penetration testers working in the APS to help us understand what their day involves.

What does a penetration tester do?

Penetration testers in government play a vital role in safeguarding information systems against cyber attacks. Their primary responsibility is to simulate cyber attacks on government systems. Penetration testers identify vulnerabilities. They also work out how to prevent malicious actors from using those vulnerabilities. This approach helps protect critical government infrastructure and data, while helping to maintain public trust in government services.

The day begins with a review of messages. We check the calendar to plan out the day’s activities, prioritising tasks based on urgency, and upcoming deadlines. We attend a daily briefing with the wider penetration testing team to discuss upcoming penetration tests, current blockers and upcoming access requirements. This meeting helps the team stay aligned and ensures that everyone is aware of their responsibilities for the day. During the meeting, I take notes on any new tasks or priorities assigned during the briefing.

“My fascination with cyber security began in university, though I initially underestimated the field’s immense scope - my degree only offered a single foundational course on the subject. After graduating, I was fortunate enough to secure a spot in a government department’s graduate program. During this program, I landed a placement with the penetration testing team. The work immediately captivated me. The mix of technical challenges and the vital task of securing Australian government systems was so intriguing that I’ve been with the team ever since.”

Penetration tester, APS

Testing public sector systems

My first task of the day is to retest several vulnerabilities that were identified on a previous engagement. An internal project team has recently applied patches and configuration changes to address these vulnerabilities. I am asked to confirm whether the issues have been fully resolved. I review the original findings and begin a targeted retesting process. I use both automated scanning tools and manual techniques to verify the effectiveness of the mitigations. Retesting is a critical part of our workflow. It ensures that our recommendations lead to measurable improvements in public-sector systems.

After lunch, I rejoin the ongoing penetration test. I focus on identifying cross-site scripting (XSS) vulnerabilities. This is a very common and dangerous vulnerability class in web applications. I methodically assess various input fields, parameters and headers to detect anomalies that could indicate an underlying security vulnerability. These checks are crucial to ensure our systems remain secure and cannot be abused to steal data.

Throughout the process, I maintain detailed documentation. I record the components tested, any vulnerabilities discovered and potential areas for further investigation.

Variety of work

In the afternoon, I’m assigned a technical task by one of the senior penetration testers. I'm required to assist with an upcoming penetration test, by checking SSL/TLS ciphers across a range of target hosts. These ciphers are special keys used to encrypt information to keep it safe and secure. My testing helps assess the strength of these and identify any weak or deprecated ciphers that could pose a security risk.

I begin by prototyping a script to perform these cipher checks, focusing on script performance and stability while ensuring it is modular enough for reuse in future engagements. Once the initial version is complete, I validate its output against test infrastructure. I share it with the senior penetration testers for feedback and potential integration into our internal toolkit.

Staying informed

Before logging off for the day, I spend the last hour reviewing the latest exploits. I catch up on recent webinars or use our training subscriptions to stay updated with the latest offensive security trends and best practices. Staying up to date not only supports my professional growth but also allows me to apply new skills and knowledge directly to better protect Australian government systems.

Categories
Digital Profession
Was this page helpful?
Last updated
18 September 2026

Links & Downloads

Interested in becoming a penetration tester?

Acknowledgement of Country

The APS Academy acknowledges the Traditional Custodians of Country throughout Australia and recognises the continuing connection to lands, waters and communities.
We pay our respect to Aboriginal and Torres Strait Islander cultures and to Elders both past and present.

Museum of Australian Democracy
Old Parliament House 
Parkes 2600

APSLearn terms & conditions

About us

apsacademy@apsc.gov.auContact us
ABN: 99 470 863 260 
  • LinkedIn - external site - external site - external site

Help us improve

We are always looking for ways to improve the user experience of our website

 Share your thoughts

  • © 2021 APS Academy. All rights reserved.
  • FOI
  • Privacy Policy 
  • Terms of use
  • Accessibility
Back to top