Black Shard

Build and secure production software.

Black Shard is an Australian software engineering and cybersecurity firm, headquartered in Brisbane. We build and run software on Azure in Australia.

What the work is.

Production systems.
The software this firm builds runs in production every day. The work is live systems with users on them.
Security from the inside.
The firm runs an engineering practice and a security practice. Whichever one you sit in, you work within reach of the other.
Written work.
Decisions, findings and reproduction steps go to clients as written. Findings are manually verified before they are reported.

Open roles.

Senior Software Engineer

Own systems end to end, from architecture through build to running in production. The work spans everything the firm builds and runs on Azure in Australia, including the Assay attack-surface scanner.

What you will do

  • Design, build and operate production systems on Azure, and stay accountable for them after they ship.
  • Work across several production codebases and stacks.
  • Set the engineering bar on the work you touch: architecture, code review, and the way findings become fixes.
  • Threat-model and harden what you build alongside the security practice, and re-test once fixes land.

What you need

  • Deep experience designing, shipping and operating production software.
  • Strong cloud engineering, ideally on Azure.
  • The habit of treating security as part of the design.
  • Plain, direct written communication. Your decisions and findings go to clients as written.
  • The right to work in Australia.

How to apply: email info@blackshard.com.au with the subject "Application: Senior Software Engineer".

Software Engineer

Build and fix systems in production. You will ship features that reach users, with senior engineers reviewing and shipping beside you.

What you will do

  • Ship features across web applications, APIs and infrastructure that run in production today.
  • Contribute across several production codebases, including the Assay scanner.
  • Fix what testing finds, then re-test to confirm the fix landed.
  • Write code that stands up to review by the security practice.

What you need

  • Solid engineering fundamentals and experience with a modern web stack.
  • Working knowledge of cloud infrastructure. We build and run on Azure.
  • An interest in security and the discipline to build with it in mind.
  • Clear written communication.
  • The right to work in Australia.

How to apply: email info@blackshard.com.au with the subject "Application: Software Engineer".

Cyber Security Consultant

Assessment, hardening and advisory work for Australian businesses. You will run offensive testing, write findings a client can act on, and re-test once the fix lands.

What you will do

  • Run penetration tests and security assessments against the OWASP and ASD playbooks.
  • Assess and harden cloud environments, including Azure and Entra ID.
  • Take clients through compliance readiness against the Essential Eight, SMB1001 and ISO 27001.
  • Write findings with reproduction steps and a recommended fix for each one.
  • Re-test remediation and contribute to standing advisory engagements, including vCISO work.

What you need

  • Hands-on penetration testing or security assessment experience.
  • Working knowledge of the frameworks Australian businesses are asked for: the Essential Eight, SMB1001, ISO 27001, and the Privacy Act.
  • Enough engineering background to read code and talk credibly to the people who wrote it.
  • Reporting discipline. Findings are manually verified and reproducible before they are reported.
  • The right to work in Australia.

How to apply: email info@blackshard.com.au with the subject "Application: Cyber Security Consultant".

Introduce yourself.

Send a CV and a short note on the work you have done. If none of these roles fit but the work sounds like yours, write anyway.