Skip to content

Open nowPosted 38 days ago

Staff Security Engineer

Workable (global search)108,016 open roles

Where
Melbourne, VIC, Australia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Security EngineerWorkable (global search) · Melbourne, VIC, Australia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 38 days ago

Workable (global search) median: 7 days open

The posting

Articore runs Redbubble, TeePublic, Dashery, and Frankly Wearing — some of the largest creator marketplaces in the world, with Redbubble's catalog alone exceeding 40 billion SKUs.

The Infrastructure team stewards the foundational platform supporting our global marketplaces, driving system reliability, scalability, and performance. By delivering core infrastructure services, Infrastructure as Code (IaC) expertise, and sophisticated tooling, the team enables engineers to deploy code securely and efficiently across our hybrid architectures — predominantly built on AWS ECS and EKS (Kubernetes).

As Staff Security & Compliance Engineer, you'll be the security driver within DEAP: the person accountable for making risk visible, turning gaps into actionable work, and ensuring our core security practices are implemented and sustained across every property. This is a senior individual contributor role. You'll deliver through a combination of deep hands-on work and influence — establishing standards, running key processes, coaching engineers, and partnering with Infrastructure and DevOps to get changes shipped — rather than through line management.

Security and compliance at Articore is shared rather than centralised. You'll report to the Engineering Manager, Infrastructure, and sit within the Infrastructure team, while working closely with IT and Engineering and dividing ownership where it makes sense. It's a broad remit, and you'll have real latitude to shape how it operates.

Core Responsibilities

Compliance, PCI & Control Operations

  • Drive PCI DSS within DEAP's scope: CDE definition, SAQ/ROC, quarterly ASV scans, segmentation evidence, audit liaison.
  • Run the audit calendar so evidence is collected continuously, not assembled under pressure.
  • Keep a live risk register — owners, dates, treatment decisions — and report risk to leadership in business terms.
  • Partner with legal and privacy on data retention, deletion, and access controls.
  • Support access governance: joiner/mover/leaver, quarterly access recertification, least-privilege IAM.

Application & Platform Security

  • Keep a current inventory of applications, services, and data flows across all four marketplaces.
  • Run and tune SAST, DAST, SCA, container and infrastructure scanning — in CI/CD, not ad hoc.
  • Triage tooling and pen test findings against SLAs (critical ≤ 7 days, high ≤ 30) and drive them to closure.
  • Own secrets management: no credentials in code, and a rotation policy that's real.
  • Threat model significant new designs and review TDDs with a security lens.
  • Stand up responsible disclosure intake — a documented channel, technical triage, coordinated response.
  • Build security champions so security scales beyond one person.

Security Detection & Incident Response

  • Own security detection: what we monitor for, the rules behind it, and the quality of the alerts.
  • Define what must be logged for detection, investigation, and audit evidence — and get teams there.
  • Own the security incident process end to end: severity, escalation, comms, coordination.
  • Act as incident commander, and run post-incident reviews that are blameless, specific, and actionable.
  • Keep the IR plan tested: security runbooks and annual tabletop exercises, minimum.
  • Own the handoff points between security response and production reliability response.

Vendor & Tooling Security Stewardship

  • Help vet new vendors for security and operational risk — data access, SOC reports, DPAs — before purchase, not after onboarding.
  • Bring engineering judgment to renewal and rationalisation calls alongside IT, finance, and procurement.
  • Find ways to cut tool sprawl, get more from existing spend, and reduce avoidable risk.

Security Roadmap & Prioritisation

  • Own the prioritised security backlog and carry it into planning, so the work gets funded and shipped through the normal delivery cycle.

Requirements

  • Demonstrated ownership of a compliance program end to end, ideally PCI DSS, otherwise ISO 27001 or SOC 2, including assessor liaison and evidence.
  • Senior-level experience in security engineering, DevSecOps, security operations, or platform security for a production SaaS or marketplace platform.
  • Hands-on experience running or tuning SAST/DAST/SCA, container, and infrastructure scanning integrated into CI/CD, plus triaging penetration test findings against SLAs.
  • Detection engineering experience on a modern observability or SIEM platform, writing and tuning detection rules, and managing alert quality over time.
  • Experience running security incident response as incident commander, including blameless postmortems with tracked follow-through.
  • Comfort operating in a cloud-native environment, ideally AWS.
  • Vendor security review and IT financial stewardship experience, SOC reports, DPAs, FinOps, renewal and contract management.
  • Experience with bot management and traffic mitigation at scale (e.g. Cloudflare).
  • Experience using AI tooling in your day-to-day workflow, and curiosity about applying it more deeply.

Key attributes of success

  • Track record of driving outcomes as a senior IC through influence rather than formal authority, proposing action, building buy-in, and coaching engineers without being their manager
  • Comfortable with a remit that evolves as the security strategy solidifies, helping shape strategy, not just executing a fixed checklist
  • Demonstrated effectiveness operating in a global company, with the communication, discipline, and async judgment required to keep work moving across time zones
  • Able to translate technical complexity for non-technical stakeholders and align decision-makers around clear outcomes, including timelines, scope, and risks
  • Comfortable balancing system health against delivery pressure, and prioritising your own time across parallel, often-ambiguous efforts
  • Inclusive collaborator who engages stakeholders across disciplines, backgrounds, and seniority, and leads teams confidently through change

Benefits

Work Environment:

  • Hybrid work model, with one-two days on-site presence required.
  • Collaboration across time zones to support global teams.

What We Offer

  • High Trust Culture: Thrive in an environment built on mutual respect where your voice matters.
  • Flexible Work Arrangements: The opportunity to balance your work and personal life with flexible schedules.
  • Global Opportunities: Be part of a global organisation that offers diverse and enriching experiences.
  • Monthly Wellness Allowance: Take care of yourself with a monthly wellness allowance to spend on your health and well-being.
  • Exclusive Vouchers and Discounts: Benefit from deals and discounts on our online marketplaces.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.