
Security Engineer (DevSecOps)
- Sydney, NSW
- Permanent
- Full-time
- Reporting to the Engineering Manager for Infrastructure, you'll play a hands-on role in ensuring we deliver the highest security standards for Q-CTRL products and maintain the trust our customers place in
- Strengthening the security of the Q-CTRL Platform through contribution to key systems like Kubernetes clusters, cloud networking, Zero Trust Network architectures, and firewalls.
- Consistently upholding compliance with security frameworks through the improvement of systems and processes. This includes access control mechanisms, data management and security guardrails.
- Applying knowledge in Forensics & Incident Response to triage incidents and raise alerts based on observability.
- Maintaining our vulnerability management systems in order to improve key security metrics for Q-CTRL.
- Other duties within the Employee's skills and experience, or with reasonable training.
- Previous experience as DevSecOps or DevOps with security engineering focus.
- Knowledge of operating Kubernetes in production; managing helm charts/operators, security configurations and hardening workloads.
- Hands-on cloud networking experience, including knowledge of ZTNA & secure network access.
- Experience with firewall technologies, both at a cloud and application level.
- Experience maintaining a vulnerability management system, including delivery of threat modelling and risk register engagements.
- Experience with Kubernetes runtime security tooling such as Falco or Sysdig.
- Security/Kubernetes certifications, for example, Certified Kubernetes Security Specialist or Offensive Security Certified Professional (OSCP).
- Red teaming experience, particularly in regards to cloud or AWS environments.
- Experience with Kubernetes runtime security tooling such as Falco or Sysdig.
- Experience using open-source observability tooling such as OpenTelemetry and Grafana to set up security alerting and alarms. Experience working with SIEM/SOC tooling such as Splunk or Microsoft Sentinel to identify and triage security alerts.