
Security Engineer III
Job description
About the role
This position is a hybrid role based in Sydney. You will mentor engineers and influence architectural decisions to embed security by design across the organization. The role involves evaluating, implementing, and supporting security tools to improve visibility and reduce risk across the technology landscape. You will communicate security concepts effectively to both technical and non-technical stakeholders throughout the software development lifecycle. The work is evidence-based and operates within a landscape of constant change, where new threats and new rules emerge annually. Security teams rely on heavy investment in training and tooling to stay current. Collaboration with developers, architects, and operations teams is central to securing distributed environments.
Key facts
What you'll do
Mentoring engineers and influencing architectural decisions embeds security by design across the organization.
Evaluation, implementation, and support of security tools improve visibility and reduce risk across the technology landscape.
Effective communication of security concepts serves both technical and non-technical stakeholders throughout the software development lifecycle.
Conducting security design reviews, threat modeling, and code reviews for web and cloud-based applications to identify potential weaknesses.
Identifying and remediating common application vulnerabilities, such as those outlined in the OWASP Top 10, through systematic analysis.
Utilizing security tools such as SAST, DAST, SCA, and container security scanners to automate and enhance security testing.
Communicating security risks and mitigation strategies clearly to technical and non-technical stakeholders to enable informed decision-making.
Requirements
The posting states a bachelor's degree requirement. 8 years of experience in application security, software development, or a related engineering role.
A strong understanding of secure software development practices, including work with developers to embed security into the SDLC.
Hands-on experience conducting security design reviews, threat modeling, and code reviews for web and cloud-based applications.
Familiarity with common application vulnerabilities, such as OWASP Top 10, and experience identifying and remediating them.
Experience using security tools such as SAST, DAST, SCA, and container security scanners.
The ability to communicate security concepts effectively to both technical and non-technical stakeholders.
Nice to have
Experience with AWS security best practices and securing cloud-native architectures.
Background in DevSecOps or building security automation into CI/CD pipelines.
Familiarity with Bug Bounty triage or managing responsible disclosure programs.
Experience with regulatory frameworks such as ISO 27001, SOC 2, or GDPR as they relate to product security.
Programming or scripting skills in languages such as Python, JavaScript, or Go to build internal tools or automation.
Skills & tools
Java, Spring, Rest API, Microservices, Kafka, Spark, NodeJS, AWS, Kubernetes, Terraform, AngularJS.
Practical notes
This is a hybrid role based in Sydney with no remote work option.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
Application security engineers secure software by integrating security practices, tools, and automation into development workflows. Common tools include SAST, DAST, SCA, and container scanners. Roles in this field often require close collaboration with developers, architects, and operations teams across distributed environments.
Questions to ask
Good questions to ask the employer in the interview: what does success look like in the first six months, how is the team structured, what is the current biggest challenge, and how are decisions made. Asking about growth paths and the review process is also well received. Employers expect questions, and good ones show preparation.
Career growth
Security careers grow from analyst or engineer to senior, staff, and leadership roles. Specializations include cloud security, application security, and security operations. Certifications help early; demonstrated impact matters later. Security careers reward specialization and a track record of finding and fixing real issues. Written communication of risk is a core skill at senior levels.