Senior Security Engineer - Product & Application Security | 12 Month Contract
Summary
Lead threat modelling and security architecture reviews across distributed applications and platforms, partnering closely with engineering to embed security into design and shipping. Core technologies include AWS/GCP, container security, CI/CD pipelines, microservices, and cloud-native architectures.
We're partnering with a market leading Australian technology company with a complex, distributed engineering environment operating at genuine scale. Their Cyber Security team is a multi-disciplinary group that partners closely with product and engineering to build security into the way things get designed and shipped, not bolted on afterwards.
They're now looking for a Senior Security Engineer to lead threat modelling and security architecture reviews across their applications and platforms, working hands-on with engineering teams to identify risk and drive practical, scalable mitigation.
This is a highly visible role with executive support behind it. You'll have real influence over the security posture of products used by millions of people.
What You'll Be Doing
- Leading threat modelling sessions and security architecture reviews for new and existing systems, applications and services
- Providing expert security guidance to engineering teams during design and development
- Conducting application, cloud and infrastructure security reviews
- Building and maintaining reusable threat libraries, security patterns and developer guidance
- Partnering with engineering to prioritise and remediate security issues across products and services
- Contributing to security automation initiatives that improve detection, prevention and remediation
- Supporting Incident Response and Vulnerability Response activities as needed
- Communicating complex security findings clearly to both technical and non-technical stakeholders
- Mentoring junior security engineers and contributing to onboarding and team knowledge-sharing
- Contributing to security champion/training programs, including workshops and training materials
- Staying ahead of evolving attack techniques and application security trends
- Proven experience leading threat modelling (e.g. STRIDE) and security architecture reviews for complex, distributed systems
- Strong expertise across Application Security, Cloud Security (AWS/GCP), Container Security, Security Architecture and AI Security
- Solid grounding in secure software design principles and common application vulnerabilities
- Experience working in agile engineering environments with CI/CD pipelines, microservices, APIs and cloud-native architectures
- Demonstrated application of frameworks and standards such as OWASP, MITRE ATT&CK, NIST, ISO 27001 and CIS Controls
- Excellent stakeholder engagement and communication skills — comfortable translating technical risk into business language
- Strong analytical and investigative skills, with the initiative to work independently in a fast-paced environment
- Experience with security automation or DevSecOps tooling
- Certifications such as OSCP, CSSLP, CISSP or similar
- Comfort experimenting with AI tools to enhance security workflows
- Involvement in bug bounty programs, CTFs, security research, open-source, or speaking at industry events
This is an opportunity to apply your secure design expertise inside a large, complex technology environment with genuine influence over enterprise security practices
You'll work alongside experienced security, engineering and product professionals across a complex technology environment, giving you exposure to modern cloud, application and distributed-system security challenges.
If you're passionate about threat modelling, product security and secure-by-design principles, this is a role where your expertise can have a genuine impact.
Apply now or reach out for a confidential discussion.