04 Aug
|
Amazon Web Services (AWS)
|
Melbourne
04 Aug
Amazon Web Services (AWS)
Melbourne
Description
G'day! You've found an opportunity that could define your next chapter. Applicants must be Australian citizens and hold or be eligible to obtain an Australian Government Security Clearance, with the ability to successfully complete an Organisational Suitability Assessment. More information regarding security clearances can be found at
The Mission - Why This Programme, Why Now?
You're joining at the defining moment of one of the most significant technology programmes Australia has ever undertaken. This programme will build and operate the dedicated cloud that gives Australia’s national security community and its allies the capability to see more, share more, innovate and act faster than ever before. The architectural decisions being made now — how we structure networking, implement security controls, and automate at scale — will shape how Australia’s national security community operates for the next decade. You won’t be inheriting someone else’s design choices; you’ll be making them.
Role
As the Security Engineering Lead, you will define how security is woven into the fabric of an entire portfolio of services — not as an afterthought, but as a foundational principle. You will drive a new era of distributed security ownership, building a model where security isn’t siloed but embedded in the DNA of every builder team. You’ll own threat modelling across critical services, lead the resolution of complex security challenges, and architect application security outcomes from secure design through code review. You will also act as the Developer Advocate for Security, establishing and leading the Security Guardians programme that trains, mentors, and empowers security champions across systems engineering teams. This role influences security strategy across partner organisations, communicates risk to senior leadership, and helps builder teams navigate the intersection of speed and security with pragmatic, mission‑focused guidance. You will be at the forefront of accelerating Generative AI proficiency across engineering teams — shaping how the next generation of builders thinks about security in an AI‑augmented world.
Key Job Responsibilities
• Architect security outcomes across a portfolio of services that directly underpin Australia’s national security capability.
• Own threat modelling using structured methodologies like STRIDE and CAPEC; translate complex threat landscapes into pragmatic mitigation strategies that empower teams to build securely and ship confidently.
• Establish and lead the Security Guardians programme — identifying, training, and mentoring security ambassadors embedded within builder teams, creating a multiplier effect that scales security knowledge far beyond what any single engineer could achieve alone.
• Drive outcomes end‑to‑end when complex security challenges arise — from design reviews and security assessments through penetration testing coordination and remediation tracking.
• Review code, scripts, detection mechanisms, and innovate on resolutions that others can learn from and replicate.
• Construct security and system runbooks for new problem domains, transforming expertise into repeatable, scalable frameworks.
• Influence security strategy across related teams and partner organisations, ensuring consistency and raising the collective bar.
• Mentor system engineers and builders, growing their ability to deliver security outcomes independently.
• Guide teams through priority decisions and pragmatic risk management when under pressure.
• Communicate security risk and design decisions with clarity and conviction to senior leadership and customers.
• Accelerate builder proficiency in Generative AI through targeted education and hands‑on guidance.
• Participate in on‑call rotations to bring security expertise to incidents that arise out‑of‑hours.
A Day in the Life
Your morning begins with a threat model review for a service nearing its next major release. You map attack surfaces using STRIDE, identify gaps, and craft mitigation recommendations that balance security rigour with delivery velocity. In mid‑morning you run a Security Guardians session, coaching a cohort of embedded security champions through a real‑world scenario. After lunch you dive into a complex security finding, review code, and collaborate with the service team to design a resolution that becomes a pattern documented in a runbook. Later you participate in a design review with senior leadership, translating technical risk into business language. You finish the day pairing with a junior engineer on a secure code review, sharing the “why” behind each recommendation.
About The Team
The AWS Region Services team combines AWS global cloud leadership with Australian security expertise to deliver highly secure, scalable environments for sensitive workloads. We create innovative ways to use cloud computing, artificial intelligence, and machine learning while maintaining the highest standards of security and operational excellence. The Engineering organisation within Region Services is structured across core capability pillars: Compute & Machine Learning, Security Identity & Compliance, Storage & Databases, and a growing capability domain. Collectively these pillars encompass a team of varying technical skillsets, including Engineers; Technical Program Managers and Subject Matter Experts, organized into focused sub‑teams.
Benefits
- Learning & development – AWS training and certification support, access to internal learning platforms.
- Health, income protection and life cover – Amazon subsidises private health insurance premiums; group salary continuance and life insurance are included at no cost.
- Military differential pay launching in Australia – employees taking defence reserve leave may receive up to 52 weeks of military differential pay.
- Employee Assistance Program – free, confidential support 24/7 for you and your family covering mental health, financial coaching,
legal questions and everyday life events.
- Family‑building benefit – access to Maven for fertility treatment, adoption support, surrogacy and parenting coaching.
- Amazon Extras & employee discount – cashback and discounts across hundreds of retail, fitness, travel and lifestyle partners.
Basic Qualifications
- Experience leading and applying threat modelling activities using structured methodologies (e.g., STRIDE, CAPEC), translating findings into pragmatic risk mitigation approaches in code that enable service teams to launch securely.
- Experience owning security risk identification and mitigation outcomes beyond a single team, influencing security strategy across related teams and partner organisations.
- Experience driving application security outcomes end‑to‑end for service teams — from design reviews and security assessments through to measurable, sustained security risk reduction across a portfolio of services.
- Experience facilitating penetration testing engagements across service teams — guiding scoping, coordinating execution, and partnering with teams to interpret findings, prioritise remediation, and deliver security outcomes.
- Experience building mechanisms to identify, track, measure and report on security program effectiveness — creating predictable process paths and reducing reliance on manual overhead.
Preferred Qualifications
- Experience establishing or leading a Security Guardians (Developer’s advocate) program (or equivalent distributed security ownership model) — training security ambassadors within builder teams to scale security reviews, reduce findings, and embed security earlier in the development lifecycle.
- 5+ years of coding or scripting experience (e.g., Java, Python, TypeScript, Rust) with the ability to review code for security deficiencies and guide builder teams on remediation.
- Experience identifying and resolving systemic security deficiencies that bottleneck innovation, driving security debt reduction across a diverse service portfolio through root‑cause analysis rather than tactical workarounds.
- Experience designing and implementing security automation — building paved paths and reusable mechanisms that deliver security outcomes with minimal builder friction and cost.
- Ability to interpret government security frameworks such as the Australian Government Information Security Manual (ISM) or Protective Security Policy Framework (PSPF).
Equal Prospect
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. We empower our people to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, please visit for more information.
Acknowledgement Of Country
In the spirit of reconciliation Amazon acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.
#J-18808-Ljbffr
📌 Sr Security Engineer, Region Services (Melbourne)
🏢 Amazon Web Services (AWS)
📍 Melbourne