This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As Senior Security Engineer you will join our Trust Team (IT, Cybersecurity, Infrastructure) at Eucalyptus and contribute to building a reliable and effective digital health platform. Reporting to the Security Engineering Manager, you will drive application and cloud security initiatives that enable innovation and protect the data of hundreds of thousands of patients. You're joining during a period of significant business transformation and international growth. Your first months will reflect that context: scaling security controls across new markets, partnering with product and engineering, and building guardrails and tooling as we adopt AI in engineering workflows.
Job Responsibility:
Partner with engineering teams: Identify and prioritise security risks in products and features, facilitate threat modelling, and grow the engineering team's security skills
Identify and manage vulnerabilities: Perform security testing against our applications and cloud infrastructure to identify vulnerabilities. Work with teams across the business to manage vulnerability remediation
Build internal security tooling: Develop security tooling and automations to shift security left and reduce manual review bottlenecks
Manage and mature our security posture: Design and implement security controls across cloud platforms and applications
Prepare for and respond to security incidents: Investigate alerts, maintain and evolve response playbooks, and lead cross-functional response when incidents occur
Requirements:
5+ years of experience in security engineering, application security, software development, or a related engineering role
You are able to code effectively in at least one modern language (Python, Go, JavaScript, etc.)
You have experience conducting security design reviews, threat modelling, and code reviews for web applications
Hands-on experience with designing, implementing and securing cloud-native systems and applications
Deep understanding of web application vulnerabilities, attack techniques and mitigation strategies
You have excellent written and verbal communication skills, particularly in explaining technical concepts to non-technical audiences
Nice to have:
Experience working with security tools such as SAST, DAST, SCA, and container security scanners
Familiarity with security standards and privacy frameworks (e.g. ISO 27001, GDPR, Australian Privacy Act)
What we offer:
Real ownership and impact at scale
Learn from some of the best engineers in the industry
Mentorship from leaders across Australia, the UK, Germany, and Japan
Collaborate with teams in the Philippines and South Africa
Explore new markets or travel internationally
Yearly Learning and Development budget for courses, books, conferences