29 Aug
|
Compass Education
|
Victoria
29 Aug
Compass Education
Victoria
Job Description
Come shape the future of education with us.
n
At Compass, we're on a mission to transform the school day for everyone - from staff and students to families and administrators. We build smart, seamless technology that empowers schools to focus on what really matters: learning, growing and thriving.
n
That mission has fuelled our growth into a global scale-up, now supporting 5,000+ schools across three countries, backed by a team of 300+ people. Our all-in-one school management platform is redefining how education communities connect, communicate and operate.
n
We're now looking for a Senior Cyber Security Engineer to work closely with our Head of Technology to help build and shape the security roadmap at Compass.
n
About the Role
n
You'll play a key role in how the organisation approaches risk, and be a trusted voice on platform, infrastructure and application.
n
This is a great opportunity for someone who wants to work closely with senior leadership, help build a security function from the ground up, and make a real difference to the safety of a platform used by schools every day.
n
What you'll do
n
Security Strategy & Risk
n
n
Work alongside the Head of Technology to build the security roadmap, set standards and be a trusted voice on security risk and posture.
n
Build and maintain a formal risk register covering vulnerabilities, remediation progress and residual risk.
n
Advise the Head of Technology and senior leadership on security risks, incidents and investment priorities.
n
n
Penetration Testing & Vulnerability Management
n
n
Lead and conduct penetration testing across web applications, APIs, infrastructure and cloud, including managing third‐party pen test engagements.
n
Identify and remediate security gaps including access control, database security (MongoDB, Redis, SQL), secrets management and cloud IAM.
n
n
Cloud & Infrastructure Security
n
n
Assess and improve GCP security configuration including VPC architecture, IAM policies, audit logging and Cloud Security Command Centre.
n
Work with DevOps and platform engineers to harden infrastructure and review Terraform and CI/CD pipelines.
n
Oversee application security including OWASP Top 10, code review involvement and secure SDLC guidance for the development team.
n
n
Investigations & Data Governance
n
n
Oversee and quality‐assure security investigations, including school‐facing audit and access cases handled by junior team members.
n
Ensure investigation processes are documented, consistent and legally defensible under Australian privacy law and, where relevant, UK/EU data protection requirements.
n
Own data access governance - who can access what, under what conditions and with what audit trail.
n
n
Incident Response & Resilience
n
n
Lead incident detection and response across the platform.
n
Design, maintain and continually test Business Continuity Plans (BCPs) to ensure rapid restoration of critical services and mitigate operational impact during disruptions.
n
Define, oversee and validate backup rotation strategies, ensuring strict data integrity, retention compliance and reliable restoration procedures.
n
n
Team Leadership
n
n
Manage and mentor junior team members, including setting workload, providing direction and supporting their development.
n
n
About You
n
You will bring:
n
n
5+ years of hands‐on cyber security experience with depth in both application and infrastructure security.
n
Strong penetration testing skills across web applications, APIs, network and cloud, including managing third‐party engagements.
n
Solid cloud security knowledge, particularly GCP or AWS (IAM, network security, audit logging, secrets management and posture tooling).
n
Proven ability to identify and remediate vulnerabilities in production environments.
n
Practical experience with security risk management - building a risk register, prioritising remediation and communicating risk to non‐technical stakeholders.
n
Familiarity with database security across relational and NoSQL systems - access control, encryption and audit logging.
n
Understanding of Australian SaaS compliance obligations and privacy frameworks.
n
Clear communication skills - able to translate technical risk for leadership and turn security requirements into practical guidance for engineers.
n
Experience managing or mentoring junior security staff.
n
n
Highly regarded:
n
n
Relevant certifications such as OSCP, CISSP, CISM or equivalent.
n
Familiarity with UK/EU data protection requirements including GDPR.
n
Prior experience in EdTech, SaaS or a high‐growth scale‐up environment.
n
n
Why Join Compass
n
You'll join a purpose‐driven company at a genuinely exciting stage of growth, with the opportunity to make a real impact on education at scale.
n
What we offer:
n
n
A hybrid working environment, based out of our Melbourne office hub.
n
Learning and development opportunities, including a dedicated PD budget.
n
24/7 access to our Employee Assistance Program (EAP), including face‐to‐face, phone and live chat support.
n
A parental leave program for both primary and secondary carers.
n
Regular team events, social budgets and in‐office perks help you stay connected, from team lunches to end‐of‐week socials.
n
Employee Referral Program
n
A supportive, inclusive culture where your voice is valued and heard.
n
n
Compass is proud to be an equal chance employer. We embrace and celebrate diversity and are committed to creating an inclusive environment for all employees.
n
Prior to commencing employment, you'll need:
n
n
A valid Employee Working With Children Check
n
A satisfactory National Police Check
n
Verification of unrestricted work rights in Australia (e.g. citizenship, passport or birth certificate)
n
📌 Senior Cyber Security Engineer (Victoria)
🏢 Compass Education
📍 Victoria