Security Engineer

4 weeks ago


Sydney, New South Wales, Australia Canva Full time
Security Engineer - Red Team (Open to remote across ANZ)

Join to apply for the Security Engineer - Red Team (Open to remote across ANZ) role at Canva

Security Engineer - Red Team (Open to remote across ANZ)

Join to apply for the Security Engineer - Red Team (Open to remote across ANZ) role at Canva

Company Description

Company Description

Join the team redefining how the world experiences design.

Hey, g'day, mabuhay, kia ora, 你好, hallo, vítejte

Thanks for stopping by. We know job hunting can be a little time-consuming, and you're probably keen to find out what's on offer, so we'll get straight to the point.

Where And How You Can Work

Our flagship campus is in Sydney. We also have a campus in Melbourne and co-working spaces in Brisbane, Perth and Adelaide. But you have a choice in where and how you work. That means if you want to do your thing in the office (if you're near one), at home or a bit of both, it's up to you.

What You'd Be Doing In This Role

As Canva scales change continues to be part of our DNA. But we like to think that's all part of the fun. So this will give you the flavour of the type of things you'll be working on when you start, but this will likely evolve.

Job Description

About the Security Group / Team

Canva's goal is to create the world's most trusted platform, which makes security a top priority. As our product, platforms, infrastructure, and corporate environments grow and evolve, so too does our need to respond to an ever-increasing threat landscape.

The Security Group is responsible for protecting Canva systems and data from information security threats. Our teams work together and with other groups to deliver preventive and detective controls and processes that reduce security risk. The group runs programs across Identity and Access Management, Application Security, Risk Management, and Threat Detection and Response domains.

The Red Team focuses on emulating adversaries and testing Canva's ability to detect and respond to them. We're constantly identifying new and innovative attack techniques, reviewing the latest industry trends, and mapping out credible attack scenarios to run against Canva.

As a Red Team Security Engineer, your mission is to work together with Threat Intelligence, Detection & Response and Application Security teams to ensure that Canva is prepared and able to effectively respond to these real-world threats.

At The Moment, This Role Is Focused On

  • Planning, designing, and executing sophisticated threat scenarios that emulate realistic adversary techniques to identify vulnerabilities and response gaps in Canva's product, platform and infrastructure.
  • Researching viable attack paths and demonstrating how the risks may apply to Canva through stealth operations and collaborative purple team engagements.
  • Collaborating closely with security incident responders to continuously uplift Canva's threat detection and response capabilities.
  • Engaging with cross-functional teams across Canva to communicate risks, provide recommendations and develop effective risk mitigation strategies for enhancing security posture.
  • Providing technical guidance, mentoring, and support to engineers conducting security assessments and vulnerability analysis.
  • Communicate and present operational outcomes at various levels of the business, including internal teams and the wider engineering organisation, as well as product owners and leadership.

You're probably a match if you have
  • Demonstrated experience as an offensive security engineer and performing team engagements from reconnaissance through to actioning on objectives.
  • Ability to effectively communicate operational findings, risk ratings and recommendations to technical and non-technical stakeholders; build rapport with engineering and security teams to drive post-engagement outcomes.
  • Practical experience with offensive security tools and techniques, and how they can be applied within a complex business environment; experience operating offensive tooling and infrastructure (e.g. C2 frameworks, short haul vs. long haul infrastructure).
  • Continuous development of knowledge around current and emerging security threats, and how those threats could impact Canva.
  • Experience exploiting macOS and Linux endpoints, as well as corporate SaaS environments.
  • Solid foundational understanding of cloud infrastructure platforms (e.g. AWS, GCP).
  • Software development experience, with proficiency in either Golang or Python

What's in it for you?

Achieving our crazy big goals motivates us to work hard - and we do - but you'll experience lots of moments of magic, connectivity and fun woven throughout life at Canva, too. We also offer a stack of benefits to set you up for every success in and outside of work.

Here's a Taste Of What's On Offer
  • Equity packages - we want our success to be yours too
  • An inclusive parental leave policy that supports all parents & carers
  • An annual Vibe & Thrive allowance to support your wellbeing, social connection, office setup & more
  • Flexible leave options that empower you to be a force for good, take time to recharge and support you personally

Check out lifeatcanva.com for more info.

Other Stuff To Know

We make hiring decisions based on your experience, skills and passion, as well as how you can enhance Canva and our culture. When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.

Please note that interviews are conducted virtually.Seniority level
  • Seniority levelMid-Senior level
Employment type
  • Employment typeFull-time
Job function
  • Job functionInformation Technology
  • IndustriesSoftware Development

Referrals increase your chances of interviewing at Canva by 2x

Get notified about new Security Engineer jobs in Sydney, New South Wales, Australia.

Sydney, New South Wales, Australia 6 days ago

Artarmon, New South Wales, Australia 1 month ago

Sydney, New South Wales, Australia 1 day ago

Security Engineer, Incident Response, SIRT

Mascot, New South Wales, Australia A$65,000.00-A$80,000.00 1 day ago

Security Engineer, Incident Response, SIRT

Sydney, New South Wales, Australia 4 days ago

Millers Point, New South Wales, Australia 1 week ago

Artarmon, New South Wales, Australia 2 weeks ago

Sydney, New South Wales, Australia 2 weeks ago

Security Consultant, Red Team, Google Cloud

Millers Point, New South Wales, Australia 1 week ago

Staff Security Engineer, Endpoint Security

North Sydney, New South Wales, Australia 2 weeks ago

Sydney, New South Wales, Australia 4 days ago

Sydney, New South Wales, Australia A$120,000.00-A$130,000.00 3 weeks ago

Security Engineer (Zscaler / AWS) - $160k-$170k base - Global Financial

Artarmon, New South Wales, Australia 1 month ago

Sydney, New South Wales, Australia 6 hours ago

Sydney, New South Wales, Australia 5 days ago

Lane Cove West, New South Wales, Australia 1 week ago

Sydney, New South Wales, Australia 5 days ago

Sydney, New South Wales, Australia A$130,000.00-A$150,000.00 3 weeks ago

Sydney, New South Wales, Australia 4 days ago

Sydney, New South Wales, Australia A$140.00-A$150.00 2 weeks ago

Senior Security Engineer - Sydney/Melbourne

Sydney, New South Wales, Australia 2 weeks ago

Sydney, New South Wales, Australia 1 day ago

Sydney, New South Wales, Australia 3 weeks ago

Sydney, New South Wales, Australia 2 weeks ago

Network Security Engineer/Palo Alto firewall

Sydney, New South Wales, Australia 1 day ago

Sydney, New South Wales, Australia 2 weeks ago

Security Support Engineer, Vulnerability Management and Remediation

Sydney, New South Wales, Australia 5 days ago

We're unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr
  • Security Engineer

    4 weeks ago


    Sydney, New South Wales, Australia Newfold Digital Full time

    2 days ago Be among the first 25 applicantsGet AI-powered advice on this job and more exclusive features.Newfold Digital is a leading web technology company serving nearly seven million customers globally. Established in 2021 through the combination of leading web services providers Endurance Web Presence and Web.com Group, our portfolio of brands includes:...

  • Security Engineer

    4 weeks ago


    Sydney, New South Wales, Australia Newfold Digital Full time

    2 days ago Be among the first 25 applicantsGet AI-powered advice on this job and more exclusive features.Newfold Digital is a leading web technology company serving nearly seven million customers globally. Established in 2021 through the combination of leading web services providers Endurance Web Presence and Web.com Group, our portfolio of brands includes:...

  • Security Engineer

    2 weeks ago


    Sydney, New South Wales, Australia Kaizenglobaltechnologies Full time

    2 days ago Be among the first 25 applicants Direct message the job poster from Kaizen Global Technologies Australia Talent Hunt |Senior Talent Acquisition Specialist- Cyber Security |NSE 1, NSE 2, NSE 3 Certified Location: Sydney, Australia Contract: 1 year Experience: 4–6 Years About the Role: We are seeking a Security Engineer with a strong foundation in...

  • Security Engineer

    4 weeks ago


    Sydney, New South Wales, Australia Canva Full time

    Security Engineer - Red Team (Open to remote across ANZ)Join to apply for the Security Engineer - Red Team (Open to remote across ANZ) role at CanvaSecurity Engineer - Red Team (Open to remote across ANZ)Join to apply for the Security Engineer - Red Team (Open to remote across ANZ) role at CanvaCompany DescriptionCompany DescriptionJoin the team redefining...

  • Security Engineer

    2 weeks ago


    Sydney, New South Wales, Australia Macquarie Group Full time

    Join to apply for the Security Engineer - Automation role at Macquarie Group2 days ago Be among the first 25 applicants Join to apply for the Security Engineer - Automation role at Macquarie Group The mission of our Cyber Threat and Incident Response team is to enable Macquarie to operate safely within a challenging digital environment by detecting,...

  • Security Engineer

    4 weeks ago


    Sydney, New South Wales, Australia Standards Australia Full time

    Join to apply for the Security Engineer role at Standards Australia1 day ago Be among the first 25 applicantsJoin to apply for the Security Engineer role at Standards AustraliaGet AI-powered advice on this job and more exclusive features.Who are we?Standards Australia (SA) is the peak standards development organisation in Australia, with a rich history that...

  • Security Engineer

    4 weeks ago


    Sydney, New South Wales, Australia Standards Australia Full time

    Join to apply for the Security Engineer role at Standards Australia1 day ago Be among the first 25 applicantsJoin to apply for the Security Engineer role at Standards AustraliaGet AI-powered advice on this job and more exclusive features.Who are we?Standards Australia (SA) is the peak standards development organisation in Australia, with a rich history that...

  • Security Engineer

    2 days ago


    Sydney, New South Wales, Australia Buscojobs Full time

    About UsWe're The Missing Link - one of Australia's most awarded IT providers, now backed by global powerhouse Infosys. For over 28 years, we've helped businesses succeed with cutting-edge Cyber Security, IT & Cloud, and Automation solutions. With 200+ team members and a culture built on inclusion, innovation, and impact, we offer a workplace where you're...

  • Security Engineer

    3 weeks ago


    Sydney, New South Wales, Australia Kaizen Global Technologies Full time

    1 day ago Be among the first 25 applicantsGet AI-powered advice on this job and more exclusive features.Direct message the job poster from Kaizen Global TechnologiesWe are seeking a Security Engineer with a strong foundation in identity and access management, cloud security, and security operations. This role is ideal for someone with hands-on experience in...

  • Security Engineer

    3 weeks ago


    Sydney, New South Wales, Australia Kaizenglobaltechnologies Full time

    2 days ago Be among the first 25 applicantsDirect message the job poster from Kaizen Global TechnologiesAustralia Talent Hunt |Senior Talent Acquisition Specialist- Cyber Security |NSE 1, NSE 2, NSE 3 CertifiedLocation: Sydney, AustraliaContract: 1 yearExperience: 4–6 YearsAbout the Role:We are seeking a Security Engineer with a strong foundation in...