Enterprise Security Team Lead
Sydney, New South Wales, Australia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Company and Team
Join a pioneering team that is transforming the global design experience. At the core, our Security Group safeguards Canva’s systems and data against information security threats. This group oversees initiatives across Application Security, Risk Management, Enterprise Security, and Threat Detection and Response. The teams collaborate closely to establish preventive and detective controls that reduce security risks.
Within this, the Internal Systems Security (ISS) team protects internal endpoints, networks, systems, and data used by all employees, managing services that maintain device posture, secure credentials, and administer SaaS application security at scale. They also work alongside teams like IT, Sales, and Customer Support to embed security early in their project roadmaps.
The team consistently balances security alongside user experience, making practical compromises daily, especially with the rise of AI tools. Candidate evaluation includes AI coding proficiency, security assessments, and system design abilities.
Role Responsibilities
- Lead and manage a security engineering team focused on threat modeling, security tool implementation, building internal security services, and strategic partnerships to advance organizational security strategy.
- Develop and own the internal security strategy, aligning security, compliance, and developer experience to enable rapid, secure workflows for employees.
- Provide coaching and professional development through practical feedback to foster individual growth within the team.
- Oversee team processes such as sprint planning, daily stand-ups, and retrospectives to maintain high team performance.
- Collaborate with partner departments including IT, Sales, and Customer Support to scale security improvements beyond the immediate team.
- Champion internal systems adoption by promoting the benefits and importance of security solutions built by the team.
Required Experience
- Developing an access strategy that effectively balances usability, security, and compliance, adaptable to evolving user behavior.
- Proven leadership in building and expanding high-performing teams.
- Expertise in threat modeling complex systems, risk identification, creating mitigation strategies in partnership with engineering teams, and ensuring successful implementation.
- Experience collaborating with external stakeholder teams such as IT and Procurement to deliver secure SaaS solutions.
- Strong understanding of internal IT environments and security technologies including Zero Trust, Identity Providers (IDPs), SSPM, MDMs, Password Managers, and related areas.
- Capability to manage complex, cross-group projects, define completion criteria, monitor progress via metrics, and communicate outcomes at company scale.
Beneficial Experience
- Proficiency in one or more programming or scripting languages such as Python, Golang, or Java, with mentoring experience.
- Familiarity with infrastructure-as-code tools like Terraform.
- Experience with identity management technologies including MFA, SAML, WebAuthn, and Okta.
- Knowledge of compliance frameworks such as SOC2, ISO27001, and GDPR.
Additional Information
Working here comes with exciting challenges and rewarding moments woven through your journey. The company offers benefits aimed at supporting professional and personal success, including:
- Equity options to share in company success.
- Inclusive parental leave supporting diverse family situations.
- An annual allowance to promote wellbeing, social engagement, and optimal office setups.
- Flexible leave policies empowering employees to recharge and engage in meaningful personal activities.
Other Important Details
Hiring decisions are based on experience, skills, passion, and cultural fit. Applicants are encouraged to share their pronouns and any reasonable accommodations needed during the interview process. The organization values diverse skills and backgrounds and welcomes candidates who may not perfectly meet all listed qualifications. Interviews are conducted virtually.