Security Engineer (SaaS)
Core
Hands-on Security Engineer establishing a dedicated function to operate, tune, and integrate security tooling across enterprise/internal security and product security domains.
Role type
Generalist Security Engineer (Enterprise & Product Security)
Builds
Secures SaaS platforms, CI/CD pipelines, cloud infrastructure, and application layers for an Australian credit reporting bureau.
Domain
Financial Services / Cybersecurity
Deliverable
production ML models | product features | infrastructure
Required skills
Application security (SAST/SCA, threat modeling, vulnerability management), Cloud security (AWS IAM, networking, Security Hub), Identity and Access Management (SSO, OAuth, OIDC, SAML), CI/CD security integration, Enterprise security tools (EDR, SSE, DLP, Email Security), Security automation (Python, Bash, APIs), Compliance frameworks (ISO 27001, SOC 2)
Preferred skills
Secure code review, Supply chain hardening, Security incident response, Mentoring security champions
Technologies
AWS, Python, Bash, SAST/SCA tools, EDR, SSE, DLP, OAuth, OIDC, SAML
Responsibilities
Implement and operate enterprise security solutions (IAM, EDR, DLP, SSE); Conduct security reviews, threat models, and risk assessments for the SDLC; Embed security controls in CI/CD pipelines; Act as a trusted advisor to engineering on secure development practices; Support compliance and assurance activities (ISO 27001, SOC 2).
Seniority
Mid-Senior, hands-on IC