Senior Product Security Engineer
Summary
12-month contract Senior Product Security Engineer leading threat modelling, security architecture reviews, and building reusable security patterns for a high-traffic Australian tech platform, with hands-on incident/vulnerability response and mentoring.
We're partnering with a well-known Australian technology business to bring in a Senior Security Engineer on an initial 12-month day rate engagement, supporting a significant security programme alongside proactive review work across their existing platforms.
You'll be embedded with engineering teams at the design phase leading threat modelling sessions, running security architecture reviews, and turning the output into reusable threat libraries and secure design patterns that teams can apply without you in the room.
What you'll be doing:
What you'll bring:
Experience implementing DevSecOps tooling, exposure to AI security, certifications such as OSCP, CSSLP or CISSP, and active involvement in the security community meetups, conferences, open source, CTFs or bug bounty. The client genuinely values that last one; it's written into the brief.
The details:
12 months initially, with a possible extension. ASAP start. Sydney or Melbourne preferred, Brisbane considered. 2-3 days per week onsite. Competitive daily rate get in touch for the number.
Apply through the link or reach out directly for a confidential conversation.
You'll be embedded with engineering teams at the design phase leading threat modelling sessions, running security architecture reviews, and turning the output into reusable threat libraries and secure design patterns that teams can apply without you in the room.
What you'll be doing:
- Leading threat modelling sessions and security architecture reviews across a complex, high-traffic product environment.
- Providing security guidance to engineering teams during system design and development, rather than handing over findings after the build.
- Developing and maintaining reusable threat libraries, security patterns and developer guidance.
- Working with engineering teams to prioritise and remediate security issues across products and services.
- Contributing to security automation that improves detection, prevention and remediation of application vulnerabilities.
- Supporting incident and vulnerability response hands-on when it's needed.
- Communicating complex security findings and design risk credibly to both technical and non-technical audiences.
- Mentoring a junior security engineer and contributing to team knowledge sharing.
What you'll bring:
- Demonstrable experience leading threat modelling sessions and security architecture reviews for distributed systems
- Strength across security domains at the application layer — application security, cloud security (AWS), container security, security architecture
- Working knowledge of OWASP, MITRE ATT&CK, NIST and ISO 27001
- Experience in agile engineering environments with CI/CD pipelines, microservices, APIs and cloud-native architectures
- Deep understanding of secure software design principles and common application vulnerabilities
- The ability to decompose a complex problem and then land the risk clearly with engineers and the business alike
- Initiative and ownership; comfortable working independently across cross-functional teams
Experience implementing DevSecOps tooling, exposure to AI security, certifications such as OSCP, CSSLP or CISSP, and active involvement in the security community meetups, conferences, open source, CTFs or bug bounty. The client genuinely values that last one; it's written into the brief.
The details:
12 months initially, with a possible extension. ASAP start. Sydney or Melbourne preferred, Brisbane considered. 2-3 days per week onsite. Competitive daily rate get in touch for the number.
Apply through the link or reach out directly for a confidential conversation.