
Principal Product Security Engineer
Job description
About the role
At MYOB, we exist to help businesses across Australia and New Zealand start, survive, and succeed. We believe that when businesses thrive, everyone thrives - owners, employees, customers, suppliers, and families. As a Principal Product Security Engineer, you will join a mission-driven team and use your expertise to secure the platforms that power our SaaS products. This role is for someone who finds excitement in designing controls that prevent bugs rather than simply reacting to them. If you have experience hunting vulnerabilities and managing security backlogs, this position offers the opportunity to shift left, embed security into the product lifecycle, and make a tangible impact. You will act as an architect, strategist, and trusted advisor, defining practical security requirements, leading threat modeling and security reviews, and mentoring teams. The role grants autonomy to experiment, build better workflows, evaluate new technologies, and create scalable security solutions without impeding product velocity.
What you'll do
You will investigate and reverse engineer complex attack vectors within our business management platform to uncover hidden risks before they reach production environments. You will champion secure-by-design principles, influencing product roadmaps and architecture decisions for critical SaaS components from inception through deployment. Through in-depth threat modeling sessions and security architecture reviews, you will translate technical findings into clear, prioritized remediation strategies for engineering teams. You will develop and maintain security playbooks, standards, and guardrails tailored to the unique workflows of our cloud products and distributed teams. Hands-on security testing will include API security assessments, authentication bypass analysis, and data exposure investigations across microservices. You will establish measurable security KPIs and dashboards to track risk reduction, control effectiveness, and the impact of security initiatives on product velocity. Collaboration with compliance, legal, and operations stakeholders will ensure security controls align with industry frameworks and regulatory obligations. You will introduce automation into security workflows, reducing manual effort and enabling product teams to integrate security seamlessly into their CI/CD pipelines. Mentoring engineers and product managers through security training, code reviews, and threat modeling workshops will build organizational capability. You will serve as the authoritative voice for application security during incident response, post-mortems, and strategic planning to elevate security maturity across the business. Evaluating emerging security tools, frameworks, and research will help you recommend scalable solutions that integrate smoothly with our cloud-native environment. You will drive security outcomes by partnering with external vendors and internal groups to ensure consistent risk management across the ecosystem.
Requirements
You have a proven track record of owning security for large-scale SaaS products or complex business management systems. You possess deep expertise in application security, including modern web applications, contemporary architectures, and SaaS infrastructure. You are fluent in attacker techniques, threat modeling methodologies, and secure design patterns used in cloud-native environments. Strong skills in security testing, including API security, authentication, authorization, and data exposure assessments, are essential. You are comfortable making high-impact security decisions despite ambiguous requirements and competing priorities. You collaborate effectively with cross-functional teams, balancing risk acceptance with the need to ship features quickly. You communicate complex security concepts clearly to both technical and non-technical stakeholders, influencing without direct authority. You are a self-starter who stays current with security trends, tooling, and research, driving your own learning and initiatives.
Nice to have
Experience with regulated industries or compliance frameworks such as ISO 27001, SOC 2, or privacy-related standards is valued. Background in identity and access management, including federation protocols like SAML and OIDC, is beneficial. Familiarity with DevSecOps tooling and secure CI/CD pipelines within cloud platforms is a plus.
Practical notes
This is a permanent, full-time position based in Sydney, Australia, aligned with the company's mission to support businesses and people every step of the way.