01 Oct
|
Compass Education
|
Melbourne
01 Oct
Compass Education
Melbourne
Job Description
n
Come shape the future of education with us.
n
At Compass, we're on a mission to transform the school day for everyone - from staff and students to families and administrators. We build smart, seamless technology that empowers schools to focus on what really matters: learning, growing and thriving.
n
That mission has fuelled our growth into a global scale-up, now supporting 5,000+ schools across three countries, backed by a team of 300+ people. Our all-in-one school management platform is redefining how education communities connect, communicate and operate.
n
We're now looking for a Senior Cyber Security Engineer to work closely with our Head of Technology to help build and shape the security roadmap at Compass.
About The Role n
You'll play a key role in how the organisation approaches risk, and be a trusted voice on platform, infrastructure and application.
n
This is a great opportunity for someone who wants to work closely with senior leadership, help build a security function from the ground up, and make a real difference to the safety of a platform used by schools every day.
What You'll Do Security Strategy & Risk n
n
Work alongside the Head of Technology to build the security roadmap, set standards and be a trusted voice on security risk and posture
n
Build and maintain a formal risk register covering vulnerabilities, remediation progress and residual risk
n
Advise the Head of Technology and senior leadership on security risks, incidents and investment priorities
n
Penetration Testing & Vulnerability Management n
n
Lead and conduct penetration testing across web applications, APIs, infrastructure and cloud, including managing third-party pen test engagements
n
Identify and remediate security gaps including access control, database security (MongoDB, Redis, SQL), secrets management and cloud IAM
n
Cloud & Infrastructure Security n
n
Assess and improve GCP security configuration including VPC architecture, IAM policies, audit logging and Cloud Security Command Centre
n
Work with DevOps and platform engineers to harden infrastructure and review Terraform and CI/CD pipelines
n
Oversee application security including OWASP Top 10, code review involvement and secure SDLC guidance for the development team
n
Investigations & Data Governance n
n
Oversee and quality-assure security investigations, including school-facing audit and access cases handled by junior team members.
n
Ensure investigation processes are documented, consistent and legally defensible under Australian privacy law and, where relevant, UK/EU data protection requirements
n
Own data access governance - who can access what, under what conditions and with what audit trail
n
Incident Response & Resilience n
n
Lead incident detection and response across the platform
n
Design, maintain and continually test Business Continuity Plans (BCPs) to ensure rapid restoration of critical services and mitigate operational impact during disruptions.
n
Define, oversee and validate backup rotation strategies, ensuring strict data integrity, retention compliance and reliable restoration procedures.
n
Team Leadership n
n
Manage and mentor junior team members, including setting workload, providing direction and supporting their development
n
Requirements About You n
You will bring:
n
n
5+ years of hands-on cyber security experience with depth in both application and infrastructure security
n
Strong penetration testing skills across web applications, APIs, network and cloud, including managing third-party engagements
n
Solid cloud security knowledge, particularly GCP or AWS (IAM, network security, audit logging, secrets management and posture tooling)
n
Proven ability to identify and remediate vulnerabilities in production environments
n
Practical experience with security risk management - building a risk register, prioritising remediation and communicating risk to non-technical stakeholders
n
Familiarity with database security across relational and NoSQL systems - access control, encryption and audit logging
n
Understanding of Australian SaaS compliance obligations and privacy frameworks
n
Clear communication skills - able to translate technical risk for leadership and turn security requirements into practical guidance for engineers
n
Experience managing or mentoring junior security staff
n
n
Highly regarded:
n
n
Relevant certifications such as OSCP, CISSP, CISM or equivalent
n
Familiarity with UK/EU data protection requirements including GDPR
n
Prior experience in EdTech, SaaS or a high-growth scale-up environment
n
Benefits Why Join Compass n
You'll join a purpose-driven company at a genuinely exciting stage of growth, with the chance to make a real impact on education at scale.
n
What we offer:
n
n
A hybrid working workplace, based out of our Melbourne office hub
n
Learning and development opportunities, including a dedicated PD budget
n
24/7 access to our Employee Assistance Program (EAP), including face-to-face, phone and live chat support
n
A parental leave program for both primary and secondary carers
n
Regular team events, social budgets and in-office perks help you stay connected, from team lunches to end-of-week socials
n
Employee Referral Program
n
A supportive, inclusive culture where your voice is valued and heard
n
n
Compass is proud to be an equal opportunity employer. We embrace and celebrate diversity and are committed to creating an inclusive environment for all employees.
n
Prior to commencing employment, you'll need:
n
n
A valid Employee Working With Children Check
n
A satisfactory National Police Check
n
Verification of unrestricted work rights in Australia (e.g. citizenship, passport or birth certificate)
n
n
Find out more about Compass on our website -
n
#J-*****-Ljbffr
📌 Senior Cyber Security Engineer (Melbourne)
🏢 Compass Education
📍 Melbourne