06 Aug
|
Payroll Metrics
|
Melbourne
06 Aug
Payroll Metrics
Melbourne
Founded in 2013, Payroll Metrics delivers cloud-based payroll and workforce management software. Our platform integrates seamlessly with HR, finance, learning management, banking, and gateway systems to streamline payroll for businesses across Australia and New Zealand. We are ISO 27001, ISO 27701 and ISO 9001 certified, reflecting our strong commitment to information security, privacy and service excellence. Our workplace culture values respect, collaboration and continuous improvement, with a solutions-focused, no-blame approach that encourages innovation, accountability and practical outcomes.
Position Purpose
This is a hands-on role responsible for operating and improving our security controls day to day, and for delivering internal IT support at Levels 1 and 2 across the business. It protects customer and employee data, keeps the internal technology environment secure and reliable, and produces the evidence that underpins our certifications and IRAP readiness.
Security strategy, policy and risk acceptance sit with the CIO. This role executes, monitors, documents and improves. Roughly two thirds of the effort is security and compliance work and one third internal IT support, reviewed quarterly; security incident response always takes priority over routine tickets.
Key Responsibilities
Security operations and incident response
Operate and tune security monitoring and centralised logging; triage, investigate and action alerts.
Maintain endpoint protection and detection coverage across all managed devices and servers.
Run the vulnerability and patch management cycle to defined timeframes, including penetration test remediation.
Respond to security incidents through containment, recovery and post-incident review, and take part in incident, continuity and disaster recovery exercises.
Identity, endpoint and cloud security
Administer identity and access: user lifecycle, conditional access, MFA, privileged access and periodic access reviews.
Manage device enrolment, configuration, compliance and application deployment across corporate endpoints and mobiles.
Maintain secure configuration baselines and the approved software catalogue, applying secure-by-design and least privilege.
Monitor cloud security posture and remediate misconfigurations; support secrets management, credential lifecycle and managed identities.
Work with the development team on secure development practices, dependency scanning and pipeline security.
Compliance and assurance
Implement, operate and evidence controls for ISO/IEC 27001, ISO/IEC 27701 and ISO 9001, and the ISM uplift programme.
Maintain audit‑ready evidence and support internal audits, surveillance audits and IRAP assessment activity.
Contribute to the risk register, corrective actions, customer security questionnaires and supplier security assessments.
Deliver security awareness activity, including phishing simulation and onboarding briefings.
Internal IT security support (Level 1 and Level 2)
Own the Internal IT ticket queue: triage, prioritise, resolve and close L1 and L2 requests.
Support endpoints, Microsoft 365 and collaboration tools, mobile devices and remote access.
Deliver IT onboarding and offboarding, including device build, account and licence provisioning, equipment recovery and complete revocation of access on exit.
Manage IT asset lifecycle, licensing assignment, and secure disposal or sanitisation of retired devices and media.
Maintain knowledge base content, reduce repeat tickets through automation, and support the customer-facing L1 team to improve triage quality before escalation.
Selection Criteria
Hands‑on cyber security operations experience: endpoint protection, identity and access management, vulnerability remediation, secure configuration and incident response.
Practical administration experience across Microsoft 365, Entra ID, Intune and Azure.
Proven Level 1 and Level 2 end‑user support experience in a ticket-based environment, with a strong service orientation.
Ability to produce clear technical documentation and audit‑ready evidence.
Strong communication skills, including explaining technical matters to non-technical colleagues.
Ability to prioritise across competing security and support demands with limited supervision.
Qualification in IT or cyber security,
or certifications such as CompTIA A+ / Security+, Microsoft SC-200, SC-300, AZ-500 or MD-102.
Experience working within a certified ISO/IEC 27001 management system and supporting audits.
Familiarity with the ISM/IRAP or NIST CSF.
SIEM deployment or detection engineering experience, and scripting ability (PowerShell, Python).
Experience in SaaS, fintech, payroll or another regulated data environment.
Key Attributes
Security‑first mindset – identifies and closes risk without being asked.
Service orientation – treats colleagues as customers; responsive and clear under pressure.
Technical versatility – moves between endpoint troubleshooting, cloud administration and security engineering in the same day.
Evidence discipline – in a certified environment, work that is not documented has not been done.
Integrity and discretion – handles privileged access and sensitive data with the judgement that trust requires.
Conditions and what we offer
Occasional after‑hours work for change windows, patching and incident response; on-call or escalations may apply.
The role holds privileged access to systems containing sensitive customer and employee data, and is subject to confidentiality obligations and periodic access review as per Security Calendar.
Broad exposure reporting directly to the CIO, across a live ISM/IRAP uplift programme, a SIEM deployment and a maturing AI governance framework as part of ISO/IEC 42001.
Funded training, certification and conference support, with real development pathways.
Why Join Payroll Metrics?
At Payroll Metrics, employees are part of a purpose‑driven SaaS organisation delivering essential payroll and workforce solutions across Australia and New Zealand. As the company continues to scale, it is investing in secure, innovative systems and this role offers a unique opportunity to help lead that transformation.
The successful candidate will work within a skilled and collaborative team in a position that bridges cybersecurity, internal IT, and tangible impact across the technology stack. Payroll Metrics values initiative and lifelong learning and offers strong support for qualified growth and development.
We appreciate the work recruiters do, however we manage all recruitment internally and are not seeking agency support.
#J-18808-Ljbffr
📌 Cyber Security Engineer (Melbourne)
🏢 Payroll Metrics
📍 Melbourne