Security Engineer, Application

United States Digital Space LLC

Sydney

On-site

AUD 150,000 - 210,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

the company Technologies is seeking a Senior Security Engineer, Application to own application security for the company AI Cloud and internal software. You will secure public APIs, services, and tenant isolation across the platform, working with engineers, operators, and AI agents to ensure secure, scalable delivery.

You will lead threat modelling, define security requirements for API integrations, and push automation to minimize manual security work while enabling rapid delivery.

Qualifications

  • Bachelor's degree in computer science or related field.
  • 7+ years in application security, product security, or software engineering with a security focus.
  • Experience securing a public cloud or multi-tenant platform with a public API.
  • Deep knowledge of OWASP Top 10 and OWASP API Security Top 10; multi-tenant APIs; identity and RBAC/ABAC controls.

Responsibilities

  • Own the CI/CD security gates that production repositories pass through: SAST, DAST, SCA, secrets detection, SBOM generation.
  • Build systems for repeatable security work: triage, dependency uplift, evidence collection, threat models.
  • Ship secure paved roads: reusable libraries, service templates, developer tooling.
  • Write and review code in protected services, including security-critical paths.

Skills

7+ years in application security
Public cloud security
OWASP Top 10
Threat modelling
CI/CD security gates
Python
Go
TypeScript
Incident response
English communication

Education

Bachelor's degree in computer science or related field

Tools

Python
Go
TypeScript

Job description

the company Technologies

the company Technologies is a globalleader pioneering the development and operation of efficient AI infrastructure across Asia Pacific.

Founded in Australia in 2019, our mission is to create the most efficient AI infrastructure by combiningcutting-edgetechnology with a steadfast commitment to sustainability.

At the company, we are unique in our approach. We design, build, andoperate a new class of digital infrastructure – the AI Factory. Through our model-to-grid technology approach, we have pushed the boundaries of multi-generational liquid cooling systems, energy management, AI software orchestration, and construction. For our customers, this approach allows us to make every watt count and deliver low-cost AI tokens globally.

the company AI Cloud

Our large-scale GPU cloud platform, the company AI Cloud, is purpose-built to deliver energy-efficient AIcomputeat scale to customers.

It empowers developers, enterprises, educational institutions, and government users to train and deploy AI models with unmatched efficiency and cost savings. With an ever-growing suite of services and applications, we are committed to delivering a cloud experience that is market-leading, proprietary, and built to scale.

ROLE SUMMARY

the company Technologies is seeking a Senior Security Engineer, Application for our Engineering and Technology team. You own application security for the company AI Cloud and the internal software that runs it. Automation is how you scale that ownership.Customers provision GPU compute throughAPI and console,software engineersbuild against it, and our operators run the platform through the same control plane. You own the security of that software: the public APIs, the services behind them, how tenants stay separated inside the application, and theAIassistants and agents we ship on top.

KEYRESPONSIBILITIESAutomation and secure delivery
  • Own the CI/CD security gates that every production repository passes through: SAST, DAST, SCA, secrets detection, and SBOM generation.
  • Build the systems that do the repeatable work: finding triage, dependency uplift, evidence collection, and draft threat models.
  • Ship thesecurepaved roads other teams build on: reusable libraries, service templates, and developer tooling.
  • Write and review code in the services you protect, including the security-critical paths that tools miss.
Security architecture and standards
  • Set the application security standardand controlfor authentication, authorisation between services, tenant isolation at the application boundary, secrethandlingand logging.
  • Lead threat modelling and secure design review. Define what an attacker can do and whatmustbe true before it ships.
  • Set the security requirements for the AI assistants and agents we ship e.g. prompt injection, context poisoning.
  • Govern which tools and tool servers ourAIagents andsoftware engineersmay reach, and how those integrations are scoped, allow-listed, and audited.
Assurance and vulnerability management
  • Own application security posture across our services: what is covered, what is open, what is accepted with a named owner and an expiry, and what is overdue.
  • Prioritise fixes on exploitability and exposure alongside CVSS and hold them to the the company vulnerability SLAs.
  • Drive remediation with the teams that own the code so issues close at the source.
  • Extend SOC 2 Type 2 and ISO 27001 into the software delivery path as services and sites grow. Evidence that a control ran should be a query, not a spreadsheet exercise.
Enablement and escalation
  • Coach security champions inside each team so secure design decisions get made without waiting for you.
  • Provide application-securityexpertiseduring incidents and convert recurring failure modes into gates, tests, standards, or developer tooling.
  • Give engineering leadership a straight read on application risk and release readiness. Join customer conversations when the question is application security.
SKILLS AND EXPERIENCE
  • Bachelor's degree in computer science or a related technical field.
  • 7+ years in application security, product security, or software engineering with a security focus.
  • Experience securing a public cloud or multi-tenant platform with a public API.
  • Deep, practical knowledge of the OWASP Top 10 and the OWASP API Security Top 10. Has threat modelled multi-tenant APIs in production: identity, authorisation between services, tenant isolation, and the ways a client abuses a published contractusingSTRIDE or an equivalent method, both forREST andgRPC.
  • Has improved the security posture of software built by other engineering teams through standards, tooling, review, or secure-by-default patterns.
  • Hasowned CI/CD security gates in production (SAST, DAST, SCA, secrets detection, SBOM) andtuned them to deliver actionable findings with low false-positive rates that engineers trusted and acted upon.
  • Writes production-quality code in at least one of Python, Go, or TypeScript.
  • Has replaced manual security work with automation: finding triage, dependency uplift, evidence collection, or regression tests that run without someone watching them.
  • Hands-on with LLM-backed or agentic features: prompt injection, tool misuse, agent identity and delegated credentials, cross-tenant data leakage, and controls on generated code reaching production. Familiar with OWASP guidance for LLM and agentic applications.
  • Deep practical experience with OAuth, OIDC, JWT, RBAC or ABAC, application-layer cryptography, token handling, and secrets in software.
  • Has worked under SOC 2 Type 2 or ISO 27001 and can produce evidence that a control ran.
  • Willing to join incident response for application and API security.
  • Willing to travel overseas occasionally when the role requires it.
  • Clear and effective written and verbal communication in English
BonusPoints
  • Experience securing AI agents, sandboxed code execution environments, or systems where AI-generated output can trigger automated actions.
  • Has run a vulnerability disclosure programme.
  • Security certifications with application-security depth, such as CSSLP or OSWE.
LOCATION

SingaporeorAustralia

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security Engineer
Senior AI Security Engineer

United States Digital Space LLC • Sydney

On-site
AUD 120,000 - 180,000
Senior AI Security Engineer
Senior AI Security Engineer

Matchbox • Sydney

Hybrid
AUD 150,000 - 210,000
Senior AI Security Engineer
Senior AI Security Engineer

Firmus Technologies • Sydney

On-site
AUD 150,000 - 210,000
Senior AI Security Engineer
Senior AI Security Engineer

Talenza • Sydney

On-site
AUD 180,000 - 240,000
Senior Security Engineer, AI Cloud Applications
Senior Security Engineer, AI Cloud Applications

United States Digital Space LLC • Sydney

On-site
AUD 150,000 - 210,000
Cloud Security Engineer
Cloud Security Engineer

Michael Page • City of Melbourne

On-site
AUD 150,000 - 200,000
Associate Security Solution Architect, APJC Customer Security (AWS)
Associate Security Solution Architect, APJC Customer Security (AWS)

Amazon • City of Melbourne

On-site
AUD 110,000 - 150,000
Head of Security & Compliance
Head of Security & Compliance

Checkbox • Sydney

On-site
AUD 180,000 - 260,000
Hybrid work in Sydney CBD
Competitive salary and equity
Learning budget
+3
Staff AI Application Security Engineer
Staff AI Application Security Engineer

Relevance AI • Sydney

On-site
AUD 260,000 - 360,000
ESOP
AI tools stipend
Parental leave
+3
Senior Cloud Infrastructure Security Engineer
Senior Cloud Infrastructure Security Engineer

SafetyCulture • Council of the City of Sydney

Hybrid
AUD 180,000 - 230,000
Equity with growth potential
Flexible work arrangements
Hackathons & Workshops