
Squad Lead - Security Engineering
- Docklands, VIC
- Permanent
- Full-time
- Leading the development and implementation of secure infrastructure as code, application security, cloud security, and automated security tooling.
- Embedding security-by-design principles across the technology lifecycle.
- Ensuring seamless integration of security controls into development and operational environments.
- Driving compliance with regulatory frameworks such as APRA CPS 234, ISO 27001, and the Australian Privacy Principles (APPs).
- Proactively identifying and mitigating security risks across the enterprise.
- 10+ years of experience in a similar or related role, demonstrating deep expertise across security engineering domains such as cloud security, infrastructure hardening, secure software development, and security tooling.
- Proven leadership in building and managing security engineering functions, including designing and implementing scalable security controls across hybrid and cloud-native environments.
- Extensive experience embedding security into CI/CD pipelines, infrastructure-as-code (IaC), and platform engineering practices.
- Strong stakeholder engagement skills with the ability to translate complex security engineering concepts into actionable outcomes for both technical and non-technical audiences.
- Advanced problem-solving capabilities with a strategic and analytical mindset.
- Excellent verbal and written communication skills, including experience presenting to executive stakeholders.
- Comprehensive understanding and practical application of security and compliance frameworks such as APRA CPS 234, ISO 27001, ASD Essential Eight, NIST 800-53, and secure-by-design principles.
- Familiarity with secure SDLC, threat modelling, and frameworks like MITRE ATT&CK in the context of vulnerability management and secure engineering.
- Relevant certifications such as CISSP, CISM, OSCP, AWS/Azure Security Specialty, or engineering-focused credentials (e.g., HashiCorp Certified: Terraform, Certified Kubernetes Security Specialist) that demonstrate depth in security engineering strategy and delivery.