23 Aug
|
iterate
|
Melbourne
We're partnering with a well-known Australian technology business to bring in a Senior Security Engineer on an initial 12-month engagement, supporting a significant security programme alongside proactive review work across their existing platforms. You'll be embedded with engineering teams at the design phase leading threat modelling sessions, running security architecture reviews, and turning the output into reusable threat libraries and secure design patterns that teams can apply without you in the room.
What you'll be doing:
- Leading threat modelling sessions and security architecture reviews across a complex, high-traffic product workplace.
- Providing security guidance to engineering teams during system design and development, rather than handing over findings after the build.
- Developing and maintaining reusable threat libraries, security patterns and developer guidance.
- Working with engineering teams to prioritise and remediate security issues across products and services.
- Contributing to security automation that improves detection, prevention and remediation of application vulnerabilities.
- Supporting incident and vulnerability response hands-on when it's needed.
- Communicating complex security findings and design risk credibly to both technical and non-technical audiences.
- Mentoring a junior security engineer and contributing to team knowledge sharing.
The role reports into the security leadership team and works closely with security, product and engineering.
What you'll bring:
- Demonstrable experience leading threat modelling sessions and security architecture reviews for distributed systems.
- Strength across security domains at the application layer; application security, cloud security (AWS), container security, security architecture.
- Working knowledge of OWASP, MITRE ATT&CK;, NIST and ISO 27001.
- Experience in agile engineering environments with CI/CD pipelines, microservices, APIs and cloud-native architectures.
- Deep understanding of secure software design principles and common application vulnerabilities.
- The ability to decompose a complex problem and then land the risk clearly with engineers and the business alike
- Initiative and ownership; comfortable working independently across cross-functional teams.
Nice to have: Experience implementing DevSecOps tooling, exposure to AI security, certifications such as OSCP, CSSLP or CISSP, and active involvement in the security community — meetups, conferences, open source, CTFs or bug bounty. The client genuinely values that last one; it's written into the brief.
The details
12 months initially, with a possible extension. ASAP start. Sydney or Melbourne preferred, Brisbane considered. 2–3 days per week onsite.
📌 Senior Product Security Engineer (Melbourne)
🏢 iterate
📍 Melbourne