Join our companies in their quest to drive powerful, positive, change that endures.

Security Engineer - Threat Detection (Open to remote across ANZ)

Canva

Canva

Sydney, NSW, Australia
Posted on Wednesday, March 9, 2022
Join the team redefining how the world experiences design.
Hey, g'day, mabuhay, kia ora,你好, hallo, vítejte!
Thanks for stopping by. We know job hunting can be a little time consuming and you're probably keen to find out what's on offer, so we'll get straight to the point.
Where and how you can work
Our flagship campus is in Sydney. We also have a campus in Melbourne and co-working spaces in Brisbane, Perth and Adelaide. But you have choice in where and how you work. That means if you want to do your thing in the office (if you're near one), at home or a bit of both, it's up to you.
What you’d be doing in this role
As Canva scales change continues to be part of our DNA. But we like to think that's all part of the fun. So this will give you the flavour of the type of things you'll be working on when you start, but this will likely evolve.
About Threat Detection Engineers
As a Threat Detection Engineer, you’ll be maintaining critical threat detection services and developing the logic to catch threats at the earliest stages of the attack chain.
You will also be building automated response capabilities based on detected threats. Another responsibility will be participating in and leading hunts for potential malicious activity. Outside of this are opportunities to participate in other security initiatives across the group.
About the Security Group
The Security Group is responsible for protecting Canva systems and data from information security threats. Our teams work together, and with other groups, to deliver preventive and detective controls and processes that reduce security risk.
The group runs programs across Identity and Access Management, Application Security, Risk Management, and Threat Detection and Response domains.

What you'll be doing!

  • Manage, maintain and utilize diverse, ever-growing collection of telemetry to develop detections for potential threats on Canva's network and systems
  • Build automation workflows to enhance response to alerts
  • Maintain systems and services vital to threat detection capabilities
  • Lead hunts for potential malicious activity on Canva's network and systems
  • Assist with Incident Response function through tactical threat detection and hunting
  • Participate in the on-call roster for threat detection & hunting
  • Assist in the promotion of a security mindset and the establishment of best practices across a wide range of security areas: secure development, cryptography, network security, security operations, and incident response
  • Identify trends, research, new technologies, and emerging threats models, which may impact the business
  • Contribute to projects that enhance the security positioning of the business

Required Experience:

  • First and foremost, have a curious detective mindset and be driven to solve ambiguous problems with simple solutions
  • Experience with Google Cloud Platform (GCP) preferred, AWS or Azure considered
  • Knowledge/Experience with threat detection engineering practices
  • Familiarity with hypothesis-based hunting and detections
  • Authoring threat detection and alert logic as code
  • Knowledge of web protocols, common attacks, and deep knowledge of Linux/Unix tools and architecture
  • Documentation, communication, and stakeholder management skills; the ability to work alongside technical and non-technical colleagues
  • The ability to prioritize multiple tasks and projects in a dynamic environment
  • High-level familiarity with a modern programming or scripting language (Python, Java, Golang, etc.)

Nice to haves; not required!

  • Subject-matter expertise of AWS and associated technologies and products within the AWS ecosystem, especially IAM and security-specific services
  • Familiarity with infrastructure as code (e.g Terraform)
  • Experience in managing Endpoint Detection and Response solutions
What's in it for you?
Achieving our crazy big goals motivates us to work hard - and we do - but you'll experience lots of moments of magic, connectivity and fun woven throughout life at Canva, too. We also offer a stack of benefits to set you up for every success in and outside of work.
Here's a taste of what's on offer:
• Equity packages - we want our success to be yours too
• Inclusive parental leave policy that supports all parents & carers
• An annual Vibe & Thrive allowance to support your wellbeing, social connection, office setup & more
• Flexible leave options that empower you to be a force for good, take time to recharge and supports you personally
Check out lifeatcanva.com for more info.
Other stuff to know
We make hiring decisions based on your experience, skills and passion, as well as how you can enhance Canva and our culture. When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.
Please note that interviews are conducted virtually.