- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About The Role
Join the team committed to safeguarding Canva's systems and data as a Staff Enterprise Security Engineer within the Internal Systems Security group. You will focus on securing the environment that Canvanauts interact with daily, including laptops, networks, identities, SaaS applications, and emerging AI agents.
Key Responsibilities
- Collaborate with various business teams to identify actual security risks and co-develop actionable roadmaps tailored to those risks.
- Enable teams to safely implement AI-driven workflows, ensuring secure adoption rather than imposing barriers.
- Evaluate and approve new tools and AI agents before deployment, providing recommendations or required settings for secure use.
- Develop threat models for emerging domains such as Multi-Channel Platforms (MCP), agentic workflows, and SaaS integrations, translating findings into widely adopted security controls.
- Define and maintain security standards, while automating processes to efficiently scale security efforts without increasing team size.
Candidate Profile
- A proactive problem solver who identifies issues, mobilizes others to address them, and drives solutions to completion.
- An influencer able to convince IT or engineering leads to adopt security initiatives without formal mandates.
- Hands-on experience with enterprise, corporate, or internal security engineering, including operating security services in production: endpoints, networks, identity management, and SaaS environments.
- A concept-driven security professional prioritizing the reasoning behind controls over specific tools.
- Competent in writing and reviewing high-quality code and emphasizes automation as a core practice.
Desirable Skills
- Experience securing diverse enterprise areas, especially in less conventional domains like marketing or sales.
- Expertise in macOS fleet management including device trust, posture assessments, zero trust models, and certificate-based device attestation.
- Proficiency in SaaS security posture management, including configuration baselines, SSPM, OAuth, third-party integration risks, and especially non-human identities.
- Knowledge in securing AI-driven agents, MCP servers, and agentic workflows involving granular policy enforcement, call mediation, audit logs, and containment techniques.
- Familiarity with infrastructure-as-code tools like Terraform, and programming in Python or Go, with experience in cloud platforms such as AWS or GCP.
Work Environment & Location
This position is located in Sydney, New South Wales, Australia, based primarily out of Canva's flagship Sydney campus. The role supports a hybrid working model, providing flexibility between remote work and in-person collaboration.
Benefits & Perks
- Participation in equity packages, sharing company success with employees.
- An inclusive parental leave policy catering to all parents and carers.
- Annual Vibe & Thrive allowance supporting wellbeing, social engagement, and home office setup.
- Flexible leave policies promoting personal recharge and social good.
Additional Information
Hiring decisions are based on experience, skills, passion, and cultural contribution. Applicants are encouraged to share their preferred pronouns and any interview accommodations needed. Canva embraces diverse backgrounds and skills and encourages applications even if qualifications do not precisely match all listed requirements. Interviews will be conducted virtually.
Level
Mid