02 Oct
|
iterate
|
East Melbourne
02 Oct
iterate
East Melbourne
Security work is easy to get away with doing badly when the consequences are abstract. This role doesn't have that luxury. The infrastructure you're securing connects cloud services to physical hardware operating in the field, so a gap here isn't a theoretical risk, it's a real one.
You'll own and mature the AWS security stack for a platform where cloud meets edge, and you'll be the one embedding security into how engineering teams actually work, not just how they're told to.
The Technical Challenge:
- Own and mature the AWS security stack: Identity Center, Security Hub, GuardDuty, WAF, Cognito, IAM, SCPs
- Design and enforce security guardrails, policies, and compliance controls across a multi-account AWS environment
- Run threat modelling, vulnerability analysis, and security assessments across both the cloud and application layers
- Secure the cloud-to-edge boundary: device connectivity and data flows linking cloud infrastructure to hardware in the field
- Review and shape network security architecture (VPC, Transit Gateway, VPN, Route53)
- Codify security controls as Infrastructure as Code (CloudFormation and/or SAM)
- Build security into CI/CD as a gate, not an afterthought: SAST/DAST, dependency and container scanning
- Lead or support incident response and security investigations when something does go wrong
- Own identity and access strategy, including authentication and authorisation for applications
The Culture Challenge:
- This is a role built on influence as much as tooling.
You'll partner directly with engineering teams to embed security into the SDLC, not police it from the outside
- Turn security knowledge into practices other engineers actually adopt, not rules they quietly work around
- Raise the security baseline for the whole team through documentation and standards, not just your own output
- Build security awareness as a shared habit across engineering. The goal is a team that thinks about security by default, not one that waits to be told
What You'll Bring:
- 5+ years in cloud security engineering, application security, or a related role
- Robust hands-on experience with the AWS security stack: Identity Center, Security Hub, GuardDuty, WAF, Cognito, IAM, SCPs, Inspector
- A general understanding of application security: OWASP Top 10, secure code review, SAST/DAST tooling
- Experience managing security within multi-account AWS environments
- Working understanding of network security architecture (VPC, Transit Gateway, VPN, Route53) from a security lens
- IaC proficiency (CloudFormation and/or SAM) with the ability to codify security controls
- Experience integrating security into CI/CD pipelines (GitHub Actions and/or GitLab CI)
- A programming language for security tooling and automation: Python, Go, or Rust
- AWS Security Specialty and/or CISSP/OSCP highly regarded
- Experience with security auditing, compliance frameworks, or formal threat modelling methodologies
📌 Cloud Security Engineer (East Melbourne)
🏢 iterate
📍 East Melbourne