30 Aug
|
Compass Education
|
Williamstown
30 Aug
Compass Education
Williamstown
Come shape the future of education with us. At Compass, we're on a mission to transform the school day for everyone - from staff and students to families and administrators. We build smart, seamless technology that empowers schools to focus on what really matters: learning, growing and thriving. That mission has fuelled our growth into a global scale-up, now supporting 5,000+ schools across three countries, backed by a team of 300+ people. Our all-in-one school management platform is redefining how education communities connect, communicate and operate.
We're now looking for a Senior Cyber Security Engineer to work closely with our Head of Technology to help build and shape the security roadmap at Compass.
About the Role
You’ll play a key role in how the organisation approaches risk, and be a trusted voice on platform, infrastructure and application. This is a great opportunity for someone who wants to work closely with senior leadership, help build a security function from the ground up, and make a real difference to the safety of a platform used by schools every day.
What you’ll do
Security Strategy & Risk
- Work alongside the Head of Technology to build the security roadmap, set standards and be a trusted voice on security risk and posture.
- Build and maintain a formal risk register covering vulnerabilities, remediation progress and residual risk.
- Advise the Head of Technology and senior leadership on security risks, incidents and investment priorities.
Penetration Testing & Vulnerability Management
- Lead and conduct penetration testing across web applications, APIs, infrastructure and cloud, including managing third-party pen test engagements.
- Identify and remediate security gaps including access control, database security (MongoDB, Redis, SQL), secrets management and cloud IAM.
Cloud & Infrastructure Security
- Assess and improve GCP security configuration including VPC architecture, IAM policies, audit logging and Cloud Security Command Centre.
- Work with DevOps and platform engineers to harden infrastructure and review Terraform and CI/CD pipelines.
- Oversee application security including OWASP Top 10, code review involvement and secure SDLC guidance for the development team.
Investigations & Data Governance
- Oversee and quality-assure security investigations, including school-facing audit and access cases handled by junior team members.
- Ensure investigation processes are documented, consistent and legally defensible under Australian privacy law and, where relevant, UK/EU data protection requirements.
- Own data access governance - who can access what, under what conditions and with what audit trail.
Incident Response & Resilience
- Lead incident detection and response across the platform.
- Design, maintain and continually test Business Continuity Plans (BCPs) to ensure rapid restoration of critical services and mitigate operational impact during disruptions.
- Define, oversee and validate backup rotation strategies, ensuring strict data integrity, retention compliance and reliable restoration procedures.
Team Leadership
- Manage and mentor junior team members, including setting workload, providing direction and supporting their development.
About You
- 5+ years of hands‑on cyber security experience with depth in both application and infrastructure security.
- Strong penetration testing skills across web applications, APIs, network and cloud, including managing third‑party engagements.
- Solid cloud security knowledge, particularly GCP or AWS (IAM, network security, audit logging, secrets management and posture tooling).
- Proven ability to identify and remediate vulnerabilities in production environments.
- Practical experience with security risk management - building a risk register, prioritising remediation and communicating risk to non‑technical stakeholders.
- Familiarity with database security across relational and NoSQL systems - access control, encryption and audit logging.
- Understanding of Australian SaaS compliance obligations and privacy frameworks.
- Explicit communication skills - able to translate technical risk for leadership and turn security requirements into practical guidance for engineers.
- Experience managing or mentoring junior security staff.
- Highly regarded: Relevant certifications such as OSCP, CISSP, CISM or equivalent.
- Familiarity with UK/EU data protection requirements including GDPR.
- Prior experience in EdTech, SaaS or a high‑growth scale‑up environment.
Why Join Compass
You’ll join a purpose‑driven company at a genuinely exciting stage of growth, with the opportunity to make a real impact on education at scale.
What we offer:
- A hybrid working environment, based out of our Melbourne office hub.
- Learning and development opportunities, including a dedicated PD budget.
- 24/7 access to our Employee Assistance Program (EAP), including face‑to‑face, phone and live chat support.
- A parental leave program for both primary and secondary carers.
- Regular team events, social budgets and in‑office perks he
#J-18808-Ljbffr
📌 Senior Cyber Security Engineer (Williamstown)
🏢 Compass Education
📍 Williamstown