Senior Security Engineer - Product & Application Security | 12 Month Contract

FourQuarters Recruitment · Melbourne VIC 3004 · Contract
Posted 19d ago

Senior Security Engineer - Product & Application Security | 12 Month Contract

FourQuarters Recruitment
$120k - $150k
KEY POINTS WE FOUND
  • Lead threat modelling sessions and security architecture reviews for systems and applications.
  • Provide expert security guidance to engineering teams during design and development.
  • Contribute to security automation initiatives and support incident response activities.

  • IT & Telecomms
  • IT Security
  • Melbourne
  • Contract or Temp
  • Lead high impact product security initiatives
  • Work across AWS, DevSecOps & cloud security
  • Influence engineering and product security practices

Are you a Senior Security Engineer with a strong background in product security, application security and threat modelling?

We're partnering with a market leading Australian technology company with a complex, distributed engineering environment operating at genuine scale. Their Cyber Security team is a multi-disciplinary group that partners closely with product and engineering to build security into the way things get designed and shipped, not bolted on afterwards.

They're now looking for a Senior Security Engineer to lead threat modelling and security architecture reviews across their applications and platforms, working hands-on with engineering teams to identify risk and drive practical, scalable mitigation.

This is a highly visible role with executive support behind it. You'll have real influence over the security posture of products used by millions of people.

What You'll Be Doing

  • Leading threat modelling sessions and security architecture reviews for new and existing systems, applications and services
  • Providing expert security guidance to engineering teams during design and development
  • Conducting application, cloud and infrastructure security reviews
  • Building and maintaining reusable threat libraries, security patterns and developer guidance
  • Partnering with engineering to prioritise and remediate security issues across products and services
  • Contributing to security automation initiatives that improve detection, prevention and remediation
  • Supporting Incident Response and Vulnerability Response activities as needed
  • Communicating complex security findings clearly to both technical and non-technical stakeholders
  • Mentoring junior security engineers and contributing to onboarding and team knowledge-sharing
  • Contributing to security champion/training programs, including workshops and training materials
  • Staying ahead of evolving attack techniques and application security trends

What You'll Bring

  • Proven experience leading threat modelling (e.g. STRIDE) and security architecture reviews for complex, distributed systems
  • Strong expertise across Application Security, Cloud Security (AWS/GCP), Container Security, Security Architecture and AI Security
  • Solid grounding in secure software design principles and common application vulnerabilities
  • Experience working in agile engineering environments with CI/CD pipelines, microservices, APIs and cloud-native architectures
  • Demonstrated application of frameworks and standards such as OWASP, MITRE ATT&CK, NIST, ISO 27001 and CIS Controls
  • Excellent stakeholder engagement and communication skills — comfortable translating technical risk into business language
  • Strong analytical and investigative skills, with the initiative to work independently in a fast-paced environment

Nice to have:

  • Experience with security automation or DevSecOps tooling
  • Certifications such as OSCP, CSSLP, CISSP or similar
  • Comfort experimenting with AI tools to enhance security workflows
  • Involvement in bug bounty programs, CTFs, security research, open-source, or speaking at industry events

Why this opportunity?

This is an opportunity to apply your secure design expertise inside a large, complex technology environment with genuine influence over enterprise security practices

You'll work alongside experienced security, engineering and product professionals across a complex technology environment, giving you exposure to modern cloud, application and distributed-system security challenges.

If you're passionate about threat modelling, product security and secure-by-design principles, this is a role where your expertise can have a genuine impact.

Apply now or reach out for a confidential discussion.

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 22 matched
AdaptableAi securityAnalytical and investigative skillsApplication securityAws/gcp cloud platformsCi/cd pipelinesCloud securityContainer securityMentoring and knowledge sharingMicroservices and apisProblem solvingSecure software design principlesSecurity architectureSecurity automation/devsecops toolsSecurity frameworks (owasp, mitre att&ck, nist, iso 27001, cis controls)Security incident responseStakeholder engagementStrong work ethicTeamwork and collaborationThreat modellingThreat modelling (e.g., stride)Vulnerability response

Licenses & certifications

0 of 3 matched
CisspCsslpOscp

FourQuarters Recruitment

More details

Expiring date
Senior Security Engineer - Product & Application Security | 12 Month Contract | FourQuarters Recruitment | Australian Ageing Agenda