09 Aug
|
iterate
|
East Melbourne
09 Aug
iterate
East Melbourne
Security work is easy to get away with doing badly when the consequences are abstract. This role doesn't have that luxury. The infrastructure you're securing connects cloud services to physical hardware operating in the field so a gap here isn't a theoretical risk, it's a real one.
You'll own and mature the AWS security stack for a platform where cloud meets edge, and you'll be the one embedding security into how engineering teams actually work, not just how they're told to.
The Technical Challeng
- eOwn and mature the AWS security stack; Identity Center, Security Hub, GuardDuty, WAF, Cognito, IAM, SCP
- sDesign and enforce security guardrails, policies, and compliance controls across multi-account AWS setting
- sRun threat modelling, vulnerability analysis, and security assessments across both cloud and application layer
- sSecure the cloud-to-edge boundary — device connectivity and data flows linking cloud infrastructure to hardware in the fiel
- dReview and shape network security architecture (VPC, Transit Gateway, VPN, Route53
- )Codify security controls as Infrastructure as Code (CloudFormation and/or SAM
- )Build security into CI/CD as a gate, not an afterthought, SAST/DAST, dependency and container scannin
- gLead or support incident response and security investigations when something does go wron
- gOwn identity and access strategy, including authentication and authorisation for application
s The Culture Challen
- ge
This is a role built on influence as much as tooling,
you'll partner directly with engineering teams to embed security into the SDLC, not police it from the outs
- ideTurn security knowledge into practices other engineers actually adopt, not rules they quietly work aro
- undRaise the security baseline for the whole team through documentation and standards, not just your own out
- putBuild security awareness as a shared habit across engineering — the goal is a team that thinks about security by default, not one that waits to be t
**old
What You'll B**
- ring 5+ years in cloud security engineering, application security, or a related
- roleStrong hands-on experience with the AWS security stack: Identity Center, Security Hub, GuardDuty, WAF, Cognito, IAM, SCPs, Insp
- ectorSolid application security background; OWASP Top 10, secure code review, SAST/DAST to
- olingExperience managing security within multi-account AWS environ
- mentsWorking understanding of network security architecture (VPC, Transit Gateway, VPN, Route53) from a security
- lensIaC proficiency (CloudFormation and/or SAM) with the ability to codify security con
- trolsExperience integrating security into CI/CD pipelines (GitHub Actions and/or GitLa
- b CI)A programming language for security tooling and automation Python, Go, or
- RustAWS Security Specialty and/or CISSP/OSCP highly reg
- ardedExperience with security auditing, compliance frameworks, or formal threat modelling methodol
ogies
📌 Senior Security Engineer (East Melbourne)
🏢 iterate
📍 East Melbourne