10 Sep
|
Wrkr
|
Melbourne
Senior Cyber Security Specialist – Identity & Access
Melbourne preferred - open to Sydney (3-4 days a week in the office)
Most Security Analyst roles look like this: review alerts, close tickets, escalate, repeat.
This one isn't that.
Wrkr is the RegTech platform sitting behind workforce compliance for more than 3 million Australians: onboarding, identity verification, payroll, superannuation and ATO obligations, built in partnership with some of Australia's largest super funds, including AustralianSuper and Rest Super. Over the next few years Wrkr is scaling that footprint to 7 million Australians, and security is central to that growth, not a compliance afterthought.
They already have; ISO27001, SOC2 Type 2, a mature SIEM, CrowdStrike, Transmit Security. What they don't have yet is someone who can turn all of those signals into intelligence: someone who can look at a login from a new location, a change of bank details, a session that doesn't quite look right, and work out whether it's a legitimate customer, a compromised account, or the start of organised fraud.
That's this role.
WHY THIS IS DIFFERENT TO A TRADITIONAL SOC ROLE
Most SOC teams protect employees and corporate infrastructure. At Wrkr, you're protecting the millions of people who use the platform itself — which means you'll spend far more of your time in authentication behaviour, identity telemetry, session activity and account-takeover indicators than in laptop-compromise territory. There's no "call the user" shortcut here — you progress investigations from telemetry alone, the way you would for any customer-facing product.
You'll sit across three worlds: Security Operations (investigation, threat hunting, detection engineering), Identity & Fraud (how people authenticate, how attackers exploit trust, how fraud patterns emerge), and Product Security (working directly with Product and Engineering to close the gaps you find).
WHAT YOU'LL ACTUALLY SPEND YOUR TIME ON
- 60–70%: detection engineering: building and tuning detections, improving signal quality, reducing false positives, developing playbooks and hunting hypotheses
- 30–40%: investigating high-confidence signals and closing the loop, what happened, and what should we detect next time
Most people join a security team where the playbooks, processes and strategy already exist. At Wrkr, you'll help build them — this is a genuine opportunity to shape detection strategy and security operations maturity from a relatively early stage, not just operate inside someone else's system. WHAT YOU NEED TO BRING
- Experience in a SOC for a customer-facing SaaS platform — not solely an internal/enterprise IT SOC or an MSSP protecting other companies' environments
- Solid SIEM and detection engineering skills: designing, building and tuning detections, log onboarding, alert lifecycle, and genuine fluency finding what you need in a SIEM under pressure
- Comfort reading authentication and identity telemetry - you don't need to have implemented OAuth/OIDC yourself, but you should be genuinely comfortable talking through how tokens, sessions and bearer/refresh flows work, common ways they're abused, and how you'd investigate a suspected token or session compromise
- Hands-on incident response: triage, investigation, evidence gathering, root cause analysis and clear write-ups
- Robust security engineering fundamentals - you think in systems, build repeatable processes,
and improve tooling/automation (SOAR, playbooks, scripting)
- The judgment to operate independently and make a defensible call on an ambiguous situation without a playbook to fall back on
- A genuine investigation mindset; you enjoy ambiguity and finding root causes more than closing tickets
NICE TO HAVE (WE CAN HELP YOU BUILD THE REST)
- Cloud security exposure
- Familiarity with identity platforms / IDP-SSO providers
- Identity verification (IDV) exposure - Wrkr's IDV workflows are niche and still evolving in Australia, and this is something we'll teach on the job
- Network-level attack familiarity or malware analysis experience (a bonus, not a requirement)
- Background in SaaS, financial services or superannuation
WHAT DEFINES "SENIOR" HERE Not years of experience, not certifications, not titles. It comes down to one question: can we trust you to investigate something ambiguous and come back with a recommendation? That means operating independently, understanding trade-offs, staying level-headed under pressure, and helping solve problems rather than just flagging them.
WHAT'S ON OFFER
- Melbourne-based (preferred but open to Sydney), hybrid (3–4 days/week in the office)
- A rare seat at the table shaping security operations maturity for a platform scaling from 3 million to 7 million Australians, with direct input into authentication, identity and fraud-control decisions that shape the product itself
This isn't a role for someone who wants to work fully remote, and it's not the right fit if you've never worked in a SOC - but if you've been looking for a security operations role with real technical depth, real autonomy, and a genuine seat at the table on product decisions, we'd like to hear from you. Apply via LinkedIn or reach out directly to Georgia Hart, Principal Consultant at nDeva, for a confidential conversation.
📌 Senior Cyber Security Specialist (Melbourne)
🏢 Wrkr
📍 Melbourne