03 Sep
|
Compass
|
Victoria
Job Description
Come shape the future of education with us.
n
At Compass, we're on a mission to transform the school day for everyone - from staff and students to families and administrators. We build smart, seamless technology that empowers schools to focus on what really matters: learning, growing and thriving.
n
That mission has fuelled our growth into a global scale-up, now supporting 5,000+ schools across three countries, backed by a team of 300+ people. Our all-in-one school management platform is redefining how education communities connect, communicate and operate.
n
We're now looking for a Senior Cyber Security Engineer to work closely with our Head of Technology to help build and shape the security roadmap at Compass.
n
About the Role
n
You'll play a key role in how the organisation approaches risk, and be a trusted voice on platform, infrastructure and application.
n
This is a great opportunity for someone who wants to work closely with senior leadership, help build a security function from the ground up, and make a real difference to the safety of a platform used by schools every day.
n
What you'll do
n
Security Strategy & Risk
n
n
- Work alongside the Head of Technology to build the security roadmap, set standards and be a trusted voice on security risk and posture.
n
- Build and maintain a formal risk register covering vulnerabilities, remediation progress and residual risk.
n
- Advise the Head of Technology and senior leadership on security risks, incidents and investment priorities.
n
n
Penetration Testing & Vulnerability Management
n
n
- Lead and conduct penetration testing across web applications, APIs, infrastructure and cloud, including managing third‐party pen test engagements.
n
- Identify and remediate security gaps including access control, database security (MongoDB, Redis, SQL), secrets management and cloud IAM.
n
n
Cloud & Infrastructure Security
n
n
- Assess and improve GCP security configuration including VPC architecture, IAM policies, audit logging and Cloud Security Command Centre.
n
- Work with DevOps and platform engineers to harden infrastructure and review Terraform and CI/CD pipelines.
n
- Oversee application security including OWASP Top 10, code review involvement and secure SDLC guidance for the development team.
n
n
Investigations & Data Governance
n
n
- Oversee and quality‐assure security investigations, including school‐facing audit and access cases handled by junior team members.
n
- Ensure investigation processes are documented, consistent and legally defensible under Australian privacy law and, where relevant, UK/EU data protection requirements.
n
- Own data access governance - who can access what, under what conditions and with what audit trail.
n
n
Incident Response & Resilience
n
n
- Lead incident detection and response across the platform.
n
- Design, maintain and continually test Business Continuity Plans (BCPs) to ensure rapid restoration of critical services and mitigate operational impact during disruptions.
n
- Define, oversee and validate backup rotation strategies, ensuring strict data integrity, retention compliance and reliable restoration procedures.
n
n
Team Leadership
n
n
- Manage and mentor junior team members, including setting workload, providing direction and supporting their development.
n
n
About You
n
You will bring:
n
n
- 5+ years of hands‐on cyber security experience with depth in both application and infrastructure security.
n
- Strong penetration testing skills across web applications, APIs, network and cloud, including managing third‐party engagements.
n
- Solid cloud security knowledge, particularly GCP or AWS (IAM, network security, audit logging, secrets management and posture tooling).
n
- Proven ability to identify and remediate vulnerabilities in production environments.
n
- Practical experience with security risk management - building a risk register, prioritising remediation and communicating risk to non‐technical stakeholders.
n
- Familiarity with database security across relational and NoSQL systems - access control, encryption and audit logging.
n
- Understanding of Australian SaaS compliance obligations and privacy frameworks.
n
- Clear communication skills - able to translate technical risk for leadership and turn security requirements into practical guidance for engineers.
n
- Experience managing or mentoring junior security staff.
n
n
Highly regarded:
n
n
- Relevant certifications such as OSCP, CISSP, CISM or equivalent.
n
- Familiarity with UK/EU data protection requirements including GDPR.
n
- Prior experience in EdTech, SaaS or a high‐growth scale‐up environment.
n
n
Why Join Compass
n
You'll join a purpose‐driven company at a genuinely exciting stage of growth, with the prospect to make a real impact on education at scale.
n
What we offer:
n
n
- A hybrid working environment, based out of our Melbourne office hub.
n
- Learning and development opportunities, including a dedicated PD budget.
n
- 24/7 access to our Employee Assistance Program (EAP), including face‐to‐face, phone and live chat support.
n
- A parental leave program for both primary and secondary carers.
n
- Regular team events, social budgets and in‐office perks help you stay connected, from team lunches to end‐of‐week socials.
n
- Employee Referral Program
n
- A supportive, inclusive culture where your voice is valued and heard.
n
n
Compass is proud to be an equal opportunity employer. We embrace and celebrate diversity and are committed to creating an inclusive environment for all employees.
n
Prior to commencing employment, you'll need:
n
n
- A valid Employee Working With Children Check
n
- A satisfactory National Police Check
n
- Verification of unrestricted work rights in Australia (e.g. citizenship, passport or birth certificate)
n
📌 Senior Cyber Security Engineer (Victoria)
🏢 Compass
📍 Victoria