← Все вакансии/CreditorWatch
HybridSydney

Security Engineer

C
CreditorWatch
Формат
Hybrid
О роли

Описание вакансии

About the company

So you might ask, who’s CreditorWatch? We are a leading Australian data and technology company that provides businesses with access to unique data and innovative products. By using our platform, our customers can confidently manage their commercial relationships, improve productivity and reduce financial risk.

As a commercial credit reporting bureau, we offer a complete suite of credit reporting products and data insights covering the entire customer lifecycle—from customer onboarding and credit decision automation to credit risk management and automated collections.

We were established in 2010 and have been named one of AFR’s Top 10 Best Places to Work, as well as certified by Great Place to Work consecutively across 2022–2025.

We are scaling at pace, making this an exciting time to join CreditorWatch.

Responsibilities
  • Improve the security posture across our SaaS platforms, employee endpoints, and office networks.
  • Implement, tune, and operate enterprise security solutions including SSE, EDR, DLP, Email Security, and IAM.
  • Enhance threat detection and response capabilities, contributing to operational runbooks and owning security alert workflows.
  • Strengthen the security posture of our platform and SDLC through security reviews, threat models, risk-based assessments.
  • Identify vulnerabilities and provide practical remediation strategies aligned to business impact.
  • Embed and operationalise security controls within CI/CD pipelines (SAST, SCA, secrets detection) with clear ownership, SLAs, and automated feedback loops.
  • Drive initiatives to harden the software supply chain and CI/CD infrastructure, enabling secure development and deployment practices.
  • Act as a trusted advisor to Engineering, providing guidance on secure development practices across CreditorWatch products and services.
  • Contribute to frameworks, guidance and tooling that enable engineers to safely adopt AI/ML capabilities in software development.
  • Mentor engineers and security champions to uplift security awareness and foster a proactive security culture.
  • Contribute to vulnerability management processes, ensuring findings are tracked, prioritised, and remediated in line with risk tolerance and SLOs.
  • Provide domain expertise in security-related incident response processes.
  • Support compliance and assurance activities (ISO 27001, SOC 2) where they intersect with engineering controls and evidence.
Requirements
  • Demonstrated hands-on experience across multiple security domains, with the ability to operate as a broad generalist.
  • Experience with application security practices, including secure code review, SAST/SCA tooling, threat modelling, and vulnerability management in cloud-native or SaaS environments.
  • Working knowledge of cloud security (preferably AWS), including IAM, networking, and services such as Security Hub, Inspector, or GuardDuty.
  • Experience embedding security into CI/CD pipelines and working closely with engineering teams to shift security left without impacting delivery.
  • Familiarity with enterprise security tools such as EDR, SSE/SWG, DLP, email security, and ASPM platforms.
  • Strong understanding of identity and access management concepts, including SSO (OAuth, OIDC, SAML), conditional access, and least privilege.
  • Exposure to relevant compliance frameworks (e.g. ISO 27001, SOC 2, OWASP Top 10).
  • Ability to script or automate workflows using tools such as Python, Bash, or APIs.
  • Strong communication skills, with the ability to translate security findings into practical guidance for engineers and articulate risk to non-technical stakeholders.
  • A genuine interest in working across a broad range of security domains and context-switching as required.
Conditions
  • Full-time opportunity offering hybrid working conditions out of our Sydney CBD Office.
  • All employees get a Fitness First Platinum gym membership.
  • Barista-made coffee, breakfast, snacks, lunches and drinks on us.
  • We pay you $50 per month to put towards your plans.
  • Receive an additional day off each month.
Стек и навыки

С чем работаем