Principal Advisor Cyber Security Architecture (AppSec)

Rio Tinto

Perth, City of Brisbane

On-site

AUD 180,000 - 260,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Annual incentive
Private health insurance
Share ownership plan
Salary packaging options
Career development
Parental leave
Employee discounts

Job summary

Rio Tinto seeks a Principal Adviser - Cyber Security Architecture (AppSec) to lead the Application Security domain. This role owns the strategy, standards, architecture and roadmap for secure software development and security services across Rio Tinto.

You will collaborate with Enterprise Architecture, software engineering and platform teams to embed security into design, deployment and operations, turning requirements into practical guidance and tooling.

Qualifications

  • Strong experience in Application Security architecture, Secure SDLC, DevSecOps, threat modelling, vulnerability management and security-by-design.
  • Experience creating and embedding security standards, patterns and guidance across development teams in a large, complex organisation.
  • Proven experience owning or supporting Application Security platforms such as Snyk, including developer onboarding and tooling integrations.
  • Practical communication style with the ability to build relationships across Cyber, architecture, engineering and business teams.

Responsibilities

  • Own the enterprise Application Security strategy, standards, reference architectures and service roadmap.
  • Lead and continually improve Secure SDLC, DevSecOps, threat modelling and secure application development practices.
  • Embed security requirements into engineering standards, delivery processes and CI/CD pipelines.
  • Own and support Application Security tooling and services (Snyk); integrate with GitHub, Azure DevOps and Artifactory.
  • Guide teams in identifying and remediating vulnerabilities; improve remediation processes.
  • Define reusable security patterns and requirements for apps, APIs, cloud-native workloads, containers and AI-enabled solutions.
  • Review designs for high-risk initiatives and provide clear security guidance to projects.
  • Mentor architects and lift Application Security capability across Rio Tinto.

Skills

AppSec architecture
Secure SDLC
DevSecOps
Threat modelling
Vulnerability mgmt
Security by design
Security standards
Stakeholder collaboration

Education

Cyber security certs
Software engineering basics

Tools

Snyk
GitHub
Azure DevOps
Artifactory

Job description

  • Own and shape Application Security architecture, standards and services across Rio Tinto
  • Lead our Secure SDLC standards and manage the Snyk application security capability
  • Permanent full-time opportunity based in Perth or Brisbane, working with a practical and collaborative Cyber Architecture team

We're Finding Better Ways to provide materials the world needs, now and in the future. Our values - care, courage and curiosity - guide how we work and how we treat each other.

About The Role

We are looking for a Principal Adviser - Cyber Security Architecture (AppSec) to lead the Application Security domain within Cyber Security. This role owns the strategy, standards, architecture and roadmap for secure software development and application security services across Rio Tinto.

You will work closely with Enterprise Architecture, software engineering, platform teams and business stakeholders to make security a practical part of how applications are designed, built, deployed and supported.

The role combines enterprise security architecture with hands-on ownership of key Application Security capabilities. It suits someone who can set direction, work directly with development teams, and turn security requirements into standards, patterns, tooling and practical guidance.

What You’ll Be Doing

Reporting to the Manager of Cyber Security Architecture and working within the Cyber Architecture team, you will

  • Own the enterprise Application Security strategy, standards, reference architectures and service roadmap
  • Lead and continually improve Secure SDLC, DevSecOps, threat modelling and secure application development practices.
  • Work with development, architecture and platform teams to embed practical security requirements into engineering standards, delivery processes and CI/CD pipelines
  • Own and support Application Security tooling and services, including Snyk and integrations with GitHub, Azure DevOps and Artifactory, working with vendors and internal teams to improve adoption and value
  • Guide teams in identifying, prioritising and remediating application and dependency vulnerabilities, and improve the processes used to manage them
  • Define reusable security patterns and requirements for applications, APIs, cloud-native workloads, containers, secrets and AI-enabled solutions
  • Review solution designs for higher-risk initiatives, and provide clear security advice to projects and development teams
  • Build strong relationships across Cyber, IS&T and the development community, mentor other architects and help lift Application Security capability across the organisation
About You

We're looking for someone with strong Application Security experience who can operate at an enterprise scale while remaining practical and approachable. You do not need to meet every 'helpful for success' item to apply. If you bring relevant experience and are interested in the opportunity.

Required for Success
  • A commitment to the safety of yourself and your team
  • Strong experience in Application Security architecture, Secure SDLC, DevSecOps, threat modelling, vulnerability management and security-by-design
  • Experience creating and embedding security standards, patterns and guidance across development teams in a large, complex organisation
  • Proven experience owning or supporting Application Security platforms such as Snyk, including developer onboarding, platform integrations, service improvement and vulnerability remediation
  • A practical communication style and the ability to build strong working relationships across Cyber, architecture, engineering, platform and business teams
  • Relevant qualifications or certifications in cyber security, information security, software engineering or a related discipline, or equivalent practical experience
Helpful for Success
  • Experience with GitHub, Azure DevOps, Artifactory, CI/CD security, API security, secrets management, container security or software supply chain security
  • Experience supporting cloud-native and AI-enabled software development, including the security risks introduced by AI coding tools and AI-enabled applications
  • Familiarity with frameworks and guidance such as OWASP, NIST, ISO 27001, CIISec or OFIA, and exposure to security architecture across identity, cloud, OT or infrastructure domains
What We Offer
  • A work environment where safety is always the number one priority
  • A permanent position working directly for Rio Tinto
  • A competitive base salary reflective of your skills and experience with annual incentive program
  • Comprehensive medical benefits including subsidised private health insurance for employees and immediate family
  • Attractive share ownership plan
  • Company provided insurance cover
  • Extensive salary sacrifice & salary packaging options
  • Career development & education assistance to further your technical or leadership ambitions
  • Ongoing access tofamily-friendly health and medical wellbeingsupport
  • Leave for all of life’s reasons (vacation/annual, paid parental, sick & cultural leave)
  • Exclusive employee discounts (banking, accommodation, cars, retail and more)
Where you’ll be working
IS&T

Information Systems and Technology (IS&T) is a global function delivering integrated and critical IT services and support to Rio Tinto’s mines, refineries, smelters, remote operations centres and corporate offices. IS&T’s mission is to power Rio Tinto’s pioneers with data and technology, enhancing safety, productivity, and value for the business. Through our collaborative partnerships and a deep understanding of our mining and metals business, IS&T carefully balances the implementation of ‘here and now’ solutions with emerging technologies that will help to create the digitally-optimised Rio Tinto of tomorrow.

About Rio Tinto

Rio Tinto is a leading global mining and materials company. We operate in 35 countries where we produce iron ore, copper, aluminium, critical minerals, and other materials needed for the global energy transition and for people, communities, and nations to thrive.

We have been mining for 150 years and operate with knowledge built up across generations and continents. Our purpose is finding better ways to provide the materials the world needs – striving for innovation and continuous improvement to produce materials with low emissions and to the right environmental, social and governance standards. But we can’t do it on our own, so we’re focused on creating partnerships to solve problems, create win‑win situations and meet opportunities.

Respect and Inclusion

At Rio Tinto, we particularly welcome and encourage applications from Aboriginal and Torres Strait Islander people, women, the LGBTQ+ community, mature workers, people with disabilities and people from different cultural backgrounds.

We are committed to an inclusive environment where people feel comfortable to be themselves. We want our people to feel that all voices are heard, all cultures respected and that a variety of perspectives are not only welcome – they are essential to our success. We treat each other fairly and with dignity regardless of race, gender, nationality, ethnic origin, religion, age, sexual orientation or anything else that makes us different.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Adviser Cyber Risk & Advisory
Principal Adviser Cyber Risk & Advisory

Rio Tinto • City of Brisbane

Hybrid
AUD 180,000 - 230,000
Permanent role
Competitive salary
Medical benefits
+5
Principal Adviser Data & AI Architecture
Principal Adviser Data & AI Architecture

Rio Tinto • City of Brisbane

Hybrid
AUD 270,000 - 360,000
Safety‑first culture
Permanent Rio Tinto employee
Competitive base salary with annual +
+9
Principal Adviser Civil/Structural Engineering
Principal Adviser Civil/Structural Engineering

Bell Bay Aluminium plc • Perth, City of Brisbane

Hybrid
AUD 180,000 - 240,000
Permanent position
Annual incentive program
Medical benefits
+3
Manager Data & AI Roadmap
Manager Data & AI Roadmap

Rio Tinto • City of Brisbane

On-site
AUD 180,000 - 260,000
Safety-first environment
Permanent position
Competitive base salary + incentive
+8
Senior Adviser Operational Readiness
Senior Adviser Operational Readiness

Rio Tinto • City of Brisbane

On-site
AUD 140,000 - 190,000
Competitive base salary
Annual incentive
Medical benefits
+7
Principal Adviser – Performance Reporting & Analytics
Principal Adviser – Performance Reporting & Analytics

Rio Tinto • City of Brisbane

On-site
AUD 170,000 - 230,000
Comprehensive medical benefits
Attractive share ownership plan
Career development assistance
+6
Principal Adviser Energy & Carbon Controllership
Principal Adviser Energy & Carbon Controllership

Rio Tinto • City of Brisbane

On-site
AUD 150,000 - 200,000
Private health insurance
Share ownership plan
Salary packaging options
+1
Senior Specialist Digital Learning Designer
Senior Specialist Digital Learning Designer

Rio Tinto • City of Brisbane

Hybrid
AUD 90,000 - 130,000
Flexible working
Career development
Inclusive environment
Adviser Laboratory and Building Services
Adviser Laboratory and Building Services

Rio Tinto • City of Melbourne

On-site
AUD 95,000 - 125,000
Permanent position
Private health insurance
Share ownership plan
+3
Senior Adviser - Payroll Advisory
Senior Adviser - Payroll Advisory

Rio Tinto • Western Australia

On-site
AUD 90,000 - 130,000
Competitive base salary
Comprehensive medical benefits
Career development
+4