Skip to main content
AfterDuty

Senior Product Security Engineer

iterate · Melbourne, Victoria

Type
Contract
Posted
7 days ago

Overview

Your incident response and risk assessment skills from policing are applicable.

About this role

We're partnering with a well-known Australian technology business to bring in a Senior Security Engineer on an initial 12-month engagement, supporting a significant security programme alongside proactive review work across their existing platforms. You'll be embedded with engineering teams at the design phase leading threat modelling sessions, running security architecture reviews, and turning the output into reusable threat libraries and secure design patterns that teams can apply without you in the room.

What you'll be doing

  • Leading threat modelling sessions and security architecture reviews across a complex, high-traffic product environment.
  • Providing security guidance to engineering teams during system design and development, rather than handing over findings after the build.
  • Developing and maintaining reusable threat libraries, security patterns and developer guidance.
  • Working with engineering teams to prioritise and remediate security issues across products and services.
  • Contributing to security automation that improves detection, prevention and remediation of application vulnerabilities.
  • Supporting incident and vulnerability response hands-on when it's needed.
  • Communicating complex security findings and design risk credibly to both technical and non-technical audiences.
  • Mentoring a junior security engineer and contributing to team knowledge sharing.

The role reports into the security leadership team and works closely with security, product and engineering.

What you'll bring

  • Demonstrable experience leading threat modelling sessions and security architecture reviews for distributed systems.
  • Strength across security domains at the application layer; application security, cloud security (AWS), container security, security architecture.
  • Working knowledge of OWASP, MITRE ATT&CK, NIST and ISO 27001.
  • Experience in agile engineering environments with CI/CD pipelines, microservices, APIs and cloud-native architectures.
  • Deep understanding of secure software design principles and common application vulnerabilities.
  • The ability to decompose a complex problem and then land the risk clearly with engineers and the business alike
  • Initiative and ownership; comfortable working independently across cross-functional teams.

Nice to have

Experience implementing DevSecOps tooling, exposure to AI security, certifications such as OSCP, CSSLP or CISSP, and active involvement in the security community — meetups, conferences, open source, CTFs or bug bounty. The client genuinely values that last one; it's written into the brief.

The details

12 months initially, with a possible extension. ASAP start. Sydney or Melbourne preferred, Brisbane considered. 2–3 days per week onsite.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Melbourne

Why this fits a police background

  • Training & coaching delivery

More cyber security & digital forensics jobs for ex-police

  • Control Manager Vulnerability Management

    Commonwealth Bank · Melbourne

    Full-time

    Control Manager, Vulnerability Management Do you thrive at the intersection of cyber security, technology, and stakeholder engagement? Help drive vulnerability remediation, shape governance practices, and make a real impact across the organisation.

    Posted 7 days ago

  • Information Security & Risk Analyst

    The Royal Australian College of General Practitioners (RACGP) · Melbourne

    Full-time

    Your incident command and threat assessment experience maps directly to security risk and resilience work.

    Posted 9 days ago

  • Contract

    Your experience with evidence handling and regulatory compliance maps directly to security assurance and vendor risk assessment.

    Posted 9 days ago

  • Cloud Security Engineer

    IFM Investors · Melbourne

    Full-time

    About Us JOB DESCRIPTION IFM Investors is a global asset manager, founded and owned by pension funds, with capabilities in infrastructure equity and debt, private equity, private credit, real estate and listed equities.

    Posted 14 days ago