Cyber Security Engineer (Melbourne)

Cyber Security Engineer (Melbourne)

06 Aug
|
CH.Solutions
|
Melbourne

06 Aug

CH.Solutions

Melbourne

This is a rare opportunity to join a high-growth, purpose-driven fintech business that is scaling with real momentum. The technology and security function is evolving to match, and this hire is central to that journey.

About the Role

This is a hands-on, mid-level Security Engineer role sitting within a small, blended Security and IT Operations team reporting directly to the Head of Security and IT. The team is lean by design and that means every person in it has real ownership, real variety, and real impact.

You will be the go-to security SME for the business, the person who can answer 90% of security questions, make pragmatic judgements about risk, and help the broader technology team embed security into how they operate every day. This is not a compliance reporting role. It is an engineering and operations role for someone who wants to get in, get their hands dirty, and build something that lasts.

The work you do here will form the foundation of this organisation's security posture for years to come. The next generation of security hires will build on top of what you put in place, not reverse-engineer it.

What You'll Be Working On:

Acting as the in-house security SME, providing practical guidance across security operations, compliance obligations, technology change and control design

Leading the triage, coordination and improvement of security incidents, working with internal teams and the external SOC and MDR partners

Improving and assuring core security controls across identity, endpoint, Microsoft 365, SaaS platforms, integrations, cloud-based systems, vulnerability management and user security

Supporting identity and access management controls including privileged access, access reviews, joiner/mover/leaver processes and MFA

Providing pragmatic security input into technology change,



projects and vendor implementations so risks are identified early and controls are workable

Maintaining practical standards, playbooks and runbooks so repeatable security activities can be shared across the broader operations team

Supporting vulnerability management, internal assessments, audits, third-party risk reviews, evidence collection and remediation tracking

Contributing to security awareness activities including training and phishing simulations

Maintaining clear security reporting across incidents, control health, vulnerabilities and compliance activity

What We're Looking For

The things that matter most:

1. 3–5 years of hands-on experience across cyber security operations and engineering, someone who has spent their time doing, not just advising. A diverse background across environments is valued over narrow specialism.

2. Strong M365 and up-to-date cloud security capability, you're genuinely across Microsoft 365 security tooling, understand how to leverage Microsoft-native capabilities for security event management and compliance, and think in terms of cloud-first security architecture.

3. Zero trust understanding in practice - not just as a concept you can define, but as an architecture you can speak to, apply, and help evolve. You'll be asked what zero trust means to you, and the answer matters.

Beyond the non-negotiables, we're also looking for:

Experience working with MDR,



SOC or incident response partners - managing escalations, challenging findings, and turning partner outputs into practical actions

Familiarity with security frameworks including ACSC Essential Eight, ISO 27001 and/or NIST CSF

Exposure to financial services or regulated environments where PII controls, audit evidence and operational discipline matter

An ISMS working knowledge - this organisation operates one and you'll need to work within it

Interest in or exposure to infrastructure-as-code and automation tooling, including Terraform — the security function is heading in this direction and ambition to grow into it is valued

Strong documentation habits and a bias toward practical improvement over theoretical security

Security certifications are beneficial but not essential - judgement, ownership and delivery matter most

The Person

As importantly as anything technical, we are looking for someone who is inquisitive, pragmatic and human. Someone who does their homework before saying no. Someone who understands that security exists to enable the business, not obstruct it — and who can measure risk appropriately for the problem at hand rather than applying an enterprise-grade framework to every small issue.

If you are someone who gets energy from building things that didn't exist before, who wants to leave a function in better shape than you found it, and who sees a small team as an opportunity rather than a constraint — this role was written for you.

Be careful - Don’t provide your bank or credit card details when applying for jobs. Don't transfer any money or complete suspicious online surveys. If you see something suspicious, report this job ad .

#J-18808-Ljbffr

📌 Cyber Security Engineer (Melbourne)
🏢 CH.Solutions
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber security engineer (melbourne) / melbourne