About HUB24
At HUB24, we’re rethinking the way wealth management works, combining platform, technology and data to create better outcomes for financial professionals and their clients.
Our purpose is simple: Empower better financial futures, together.
What sets us apart is how we work. We back bold thinking, move with pace, and turn ideas into action. You’ll have the opportunity to make a real impact across your team, the business, and for the clients we support every day.
HUB24 Limited is an ASX-listed company (ASX: HUB) and part of the ASX100. We have over 1,100 employees across Australia, with offices in Sydney, Melbourne, Brisbane, Perth and the Gold Coast.
Why you’ll enjoy working here
We create an environment where you can do your best work and see the impact of it.
- Work with smart, collaborative people who get things done.
- Your ideas won’t sit in a backlog, they’ll be heard, tested and actioned.
- Grow your career your way, with support to learn, stretch and explore new opportunities.
We also offer benefits to support you inside and outside of work:
- Genuinely flexible and hybrid ways of working.
- Employee Share Scheme.
- Additional leave and wellbeing support.
- Enhanced parental leave and support through different life stages.
- Everyday benefits, including discounts and financial wellbeing support.
Why this is an exciting opportunity
At HUB24, we’re committed to building secure, scalable, and high-performing technology that enables better financial futures. As a DevSecOps Engineer, you will play a key role in embedding security into every stage of the DevOps lifecycle.
You’ll work closely with platform, cyber,
and engineering teams to automate security controls, improve resilience, and ensure compliance—while enabling fast, reliable software delivery. This role is ideal for someone who sees security as an enabler, enjoys solving complex challenges, and thrives in a collaborative, fast-paced environment.
What you’ll be doing
- Embed security practices across the SDLC, promoting a shift-left and secure-by-design approach
- Automate security controls within CI/CD pipelines to support productive and secure releases
- Implement and manage application security testing (SAST, DAST, SCA, container scanning)
- Strengthen cloud security and infrastructure across AWS, Azure, or GCP, including IaC hardening
- Perform threat modelling, vulnerability management, and risk mitigation activities
- Ensure compliance with security frameworks and standards (CIS, NIST, ISO27001, PCI-DSS)
- Establish and enhance monitoring, logging, and alerting for security events
- Support incident response and remediation processes
- Manage identity and access controls, secrets management, and Zero Trust practices
- Collaborate with Dev, Sec, and Ops teams to promote shared ownership of security
- Provide guidance on secure coding practices and continuous improvement initiatives
What you bring
You don’t need to tick every box,
but experience in the below will set you up for success.
Experience & Skills
- Proven experience integrating security into CI/CD pipelines (e.g. Jenkins, GitHub Actions, GitLab CI, Azure DevOps)
- Hands-on experience with security testing tools (SAST, DAST, SCA, container security tools)
- Strong scripting and automation skills (Python, Bash, or similar)
- Experience with cloud platforms and security controls (AWS, Azure, or GCP)
- Knowledge of monitoring, logging, and alerting solutions for security events
- Experience with vulnerability management and remediation practices
- Solid understanding of security frameworks and compliance standards
- Familiarity with IAM, secrets management, WAF, and Zero Trust principles
- Strong problem-solving and risk analysis skills
- Excellent collaboration and communication skills, with the ability to work across multiple teams
Our process
We aim to keep the process simple and respectful of your time:
- You’ll receive an acknowledgement after applying.
- Our Talent team will review your application and keep you updated.
- If shortlisted, we’ll connect to learn more about you.
- Interviews may be virtual or in person.
- You’ll receive an outcome and feedback.
If you need any adjustments, please let us know - we’re here to support you.
Our commitment
We’re committed to building an inclusive environment where everyone feels valued and supported to do their best work. We welcome applications from people of all backgrounds, identities and experiences.
Agencies, we work with a panel of preferred suppliers and are not accepting any unsolicited CVs.
📌 DevSecOps Engineer (Sydney)
🏢 HUB24
📍 Sydney