freehire is live on Product Hunt today.

Support the launch →

Senior Cyber Security Engineer

Summary

Leads end-to-end cybersecurity for a cloud-based payroll platform, owning security engineering, compliance (ISO 27001/27701), incident response, and internal IT security support. Focuses on Azure/SaaS security, secure development, and executive risk communication.

About Payroll Metrics

Founded in 2013, Payroll Metrics delivers cloud-based payroll and workforce management software. Our platform integrates seamlessly with HR, finance, learning management, banking, and gateway systems to streamline payroll for businesses across Australia and New Zealand. We are ISO 27001, ISO 27701 and ISO 9001 certified, reflecting our strong commitment to information security, privacy and service excellence. Our workplace culture values respect, collaboration and continuous improvement, with a solutions-focused, no-blame approach that encourages innovation, accountability and practical outcomes.

Position Purpose

The Senior Cyber Security Engineer is the organisation’s most senior hands-on security practitioner and the day-to-day custodian of our security and compliance posture. The role owns the operation and continuous improvement of our security controls, the security of our multi-tenant payroll platform, the evidence base behind our ISO certifications and IRAP readiness, and the internal IT security support function.

This is a senior, self-directing role. You will set the technical direction for security engineering, advise the executive on risk in plain language, and be trusted to make sound decisions without close supervision. It suits an experienced practitioner who wants genuine ownership and breadth rather than a narrow specialist lane.

Key Responsibilities

Security engineering and operations

  • Own security monitoring and centralised logging across our Azure tenancies and SaaS platform, including detection design, tuning and alert triage.

  • Lead security incident response end to end - containment, investigation, recovery, evidence preservation and post-incident review; and run incident, continuity and disaster recovery exercises.

  • Own the vulnerability and patch management cycle to defined timeframes, including penetration test scoping and remediation to closure.

  • Maintain secure configuration baselines, endpoint protection and detection coverage across all managed devices, servers and cloud resources.

Application and platform security

  • Own application security for our multi-tenant payroll platform: tenant isolation, authorisation logic, API security, sensitive data exposure and OWASP-class risks.

  • Embed security into the software development lifecycle - threat modelling, secure design review, secure code review practices and developer guidance - in partnership with the development team.

  • Own security tooling across the CI/CD pipeline: dependency and software composition analysis, secrets scanning and SAST.

  • Manage secrets and credential lifecycle, including key rotation, managed identities and elimination of embedded or shared credentials.

  • Conduct security assessment of third-party integrations, APIs and AI-enabled capabilities before they reach production.

Compliance and assurance

  • Act as the day-to-day technical custodian of our ISO/IEC 27001, ISO/IEC 27701 and ISO 9001 management systems - implementing, operating, evidencing and improving controls.

  • Lead the ISM uplift programme and prepare the organisation for IRAP assessment, including control mapping, gap remediation and evidence management.

  • Manage internal security audits, surveillance audits and assessor engagement; own non-conformances, corrective actions and control exceptions through to closure.

  • Maintain the risk register, security documentation and policy set, and support privacy obligations and the Notifiable Data Breaches scheme.

  • Own customer security questionnaires, due diligence responses and supplier security assessments.

Identity, endpoint and cloud security

  • Administer identity and access across the environment: user lifecycle, conditional access, MFA, privileged access and periodic access reviews.

  • Manage device enrolment, configuration, compliance and application deployment across corporate endpoints and BYOD.

  • Monitor cloud security posture across tenancies and remediate misconfigurations; maintain the approved software catalogue and application control.

Internal IT security support (Level 1 and Level 2)

  • Own the Internal IT queue: triage, prioritise, resolve and close L1 and L2 requests within agreed service levels.

  • Deliver IT onboarding and offboarding, including device build, account and licence provisioning, equipment recovery and complete revocation of access on exit.

  • Manage IT asset lifecycle, licensing assignment and secure disposal or sanitisation of retired devices and media.

  • Reduce repeat demand through knowledge base content, automation and improving triage quality before escalation; deliver security awareness activity including phishing simulation.

Selection Criteria

Essential

  • Substantial hands-on cyber security engineering experience (typically 6+ years), operating security controls in a production environment with minimal supervision.

  • Demonstrated application security capability - OWASP-class risks, secure development practices, threat modelling, API and SaaS security.

  • Practical experience implementing and evidencing controls within a certified ISO/IEC 27001 management system, and supporting audits or assessments.

  • Working knowledge of ISO/IEC 27701 and ISO 9001, and of the Australian Government ISM; IRAP exposure strongly preferred.

  • Strong administration capability across Microsoft 365, Entra ID, Intune and Azure, including identity, endpoint and cloud security posture.

  • Experience owning security monitoring or SIEM, vulnerability management and incident response as the accountable person.

  • Genuine willingness to own a Level 1 and Level 2 support queue alongside senior security work, with prior ticket-based service experience.

  • Excellent written and verbal communication, including presenting risk and options to executives and non-technical teams.

Desirable

  • Certifications such as CISSP, CISM, SC-100, SC-200, AZ-500, CySA+ or ISO/IEC 27001 Lead Auditor / Lead Implementer.

  • Prior experience in SaaS, fintech, payroll or another regulated data environment.

  • Scripting and automation capability (PowerShell, KQL, Python) applied to security or IT operations.

  • Exposure to AI governance frameworks such as ISO/IEC 42001, and to secure adoption of AI tooling.

  • Degree in information technology, cyber security or a related discipline.

Key Attributes

  • Ownership – takes accountability for outcomes without waiting to be directed.

  • Judgement – balances security, delivery and commercial reality, and knows when to escalate.

  • Evidence discipline – in a certified environment, work that is not documented has not been done.

  • Service orientation – treats colleagues as customers; responsive and clear under pressure.

  • Integrity and discretion – handles privileged access and sensitive data with the judgement that trust requires.

Conditions and what we offer

  • Occasional after-hours work for change windows, patching and incident response; on-call or escalation arrangements may apply.

  • Funded training, certification and conference support, with real development pathways.

We appreciate the work recruiters do, however we manage all recruitment internally and are not seeking agency support.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available