Jobiglo

No results.

Security Engineer (SaaS)

CreditorWatch · Sydney

New
Hybrid 🇬🇧 English
IAM Zero Trust DLP SSE EDR Application security Vulnerability management Threat modelling SAST SCA Secrets detection AWS Security Hub Inspector GuardDuty Python Bash OAuth OIDC SAML ISO 27001 SOC 2 OWASP Top 10

Job description

About the role

CreditorWatch is building a dedicated Security Engineering function to operate, tune, and integrate security platforms across its SaaS environment. The Security Engineer will work on both enterprise/internal security and product security, partnering with engineering teams to embed security throughout the development lifecycle.

Key responsibilities

  • Improve security posture of SaaS platforms, employee endpoints, and office networks by implementing and operating solutions such as SSE, EDR, DLP, Email Security, and IAM.
  • Enhance threat detection and response, maintain runbooks, and own security alert workflows.
  • Conduct security reviews, threat modelling, and risk‑based assessments for applications and the SDLC.
  • Embed security controls (SAST, SCA, secrets detection) into CI/CD pipelines with clear ownership and automated feedback.
  • Mentor engineers, provide guidance on secure development practices, and support vulnerability management and incident response.
  • Assist compliance activities for ISO 27001 and SOC 2.

Required profile

  • Hands‑on experience across multiple security domains as a broad generalist.
  • Experience with application security, secure code review, SAST/SCA tooling, threat modelling, and vulnerability management in cloud‑native or SaaS environments.
  • Working knowledge of cloud security (preferably AWS) and related services.
  • Familiarity with enterprise security tools such as EDR, SSE/SWG, DLP, and email security.
  • Strong communication skills to translate findings for engineers and non‑technical stakeholders.

Required skills

  • IAM, Zero Trust, DLP, SSE, EDR
  • Application security, vulnerability management, threat modelling
  • CI/CD pipeline security (SAST, SCA, secrets detection)
  • AWS services (Security Hub, Inspector, GuardDuty)
  • Python, Bash, API automation
  • Identity protocols (OAuth, OIDC, SAML)
  • Compliance frameworks (ISO 27001, SOC 2, OWASP Top 10)

What we offer

  • Fitness First Platinum gym membership
  • Barista‑made coffee, breakfast, snacks and lunches
  • $50 monthly phone credit
  • Additional wellness day each month
  • Monthly in‑house massages
  • Performance‑based bonus and employee share scheme
  • Regular team activities (sailing, pasta‑making, go‑karting, company boat)
  • Free legal services for employees

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec CreditorWatch.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:workable

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 16 hours ago

Expires 1 month from now

5 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

CreditorWatch

Sydney