Enterprise Security Manager
Sydney, New South Wales, Australia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 5 jam yang lalu
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About The Role and Team
Become part of the group dedicated to safeguarding Canva's systems and data against information risks. The Security Group encompasses Application Security, Risk Management, Enterprise Security, and Threat Detection and Response. Collaboratively, we deliver controls and processes that minimize security threats effectively.
The Internal Systems Security (ISS) team focuses on securing our internal endpoints, networks, systems, and data utilized by all employees. We develop and maintain services supporting device posture, credential security, and scalable SaaS application security. We also partner closely with teams like IT, Sales, and Customer Support to embed security early into their roadmaps.
This role demands a fine balance between security measures and user experience, making thoughtful decisions especially as AI tooling accelerates workflows.
Key Responsibilities
- Lead a security engineering team involved in threat modeling, deployment of security tools, creating internal security services, and shaping security strategies in collaboration with other teams.
- Define and steer the strategy for internal security ensuring a balance among security, compliance, and developer experience, enabling staff to move swiftly within secure parameters.
- Provide coaching and regular practical feedback to engineers to foster their professional growth.
- Manage team workflows including sprint planning, daily stand-ups, and retrospectives to maintain a high-performing unit.
- Collaborate with IT, Sales, Customer Support, and other departments to implement scalable security enhancements beyond the immediate team.
- Advocate for internal adoption of developed systems, highlighting their advantages throughout the organization.
Required Experience
- Skill in crafting access strategies that maintain equilibrium between usability, security, and compliance, adapting flexibly to evolving user behaviors.
- Demonstrated leadership in managing and developing high-performance teams.
- Proven expertise in complex system threat modeling, risk identification, mitigation strategy design in cooperation with engineering teams, and successful implementation.
- Experience collaborating with external teams like IT and Procurement to deliver secure SaaS solutions.
- Strong familiarity with internal IT environments and current security technologies like zero trust frameworks, identity providers (IDPs), SaaS Security Posture Management (SSPM), mobile device management (MDM), and password managers.
- Capability to manage extensive, multifaceted projects across various groups, define completion criteria, monitor success metrics, and deliver communications at a company-wide scale.
Beneficial Experience (Not Mandatory)
- Proficiency in programming or scripting languages such as Python, Golang, or Java, including mentoring others on coding best practices.
- Knowledge of infrastructure as code tools like Terraform.
- Experience with identity management technologies including MFA, SAML, WebAuthn, and Okta.
- Understanding of compliance frameworks such as SOC2, ISO27001, and GDPR.
Additional Information
We are driven to accomplish ambitious objectives, accompanied by an engaging work environment full of meaningful moments and fun. Our benefits include:
- Equity packages allowing you to share in our success.
- An inclusive parental leave policy supporting all parents and carers.
- A yearly Vibe & Thrive allowance dedicated to wellbeing, social interactions, office setup, and more.
- Flexible leave policies to support personal recharge and impactful contributions.
Please inform us of your pronouns and any reasonable accommodations you may require during the interview process. We value diverse skills and backgrounds, so if you feel your experience doesn’t perfectly align, we still encourage you to apply. Interviews will be conducted virtually.