Our 'black belt' specialists are leaders in their domains: digital champions, delivery-focused experts, top-tier security professionals, AI thought leaders, and engineering best practice advocates.
As 1 of Australia’s fastest-growing software businesses, Software at Scale delivers cutting‑edge technology solutions that power mission‑critical platforms. We solve complex engineering challenges at scale, driving quality, performance, and resilience through the strength of our people.
The Role & The Challenge
We are seeking an exceptional, highly proactive Senior Cyber Security Engineer to drive an engineering‑led security transformation for a major financial and payments ecosystem.
This is not a tick‑the‑box, paper‑pushing compliance security role. We are looking for a hands‑on technical practitioner to help anchor an elite, engineering‑led security program. You will take complete technical ownership of hardening mission‑critical digital perimeters, designing enterprise Web Application Firewalls (WAF), advanced DDoS protection, and modern Identity and Access Management (IAM/CIAM) ecosystems.
If you are content with waiting for rigid audit specs or manual security reviews, this is not the role for you. You will step into a high‑trust, empowered environment where you will architect robust security controls, secure high‑volume API gateways, and automate threat defences from the ground up.
Access to AI Tooling: We believe in removing friction so you can focus on solving hard problems. You will have full access to enterprise AI tooling, including Claude Code to assist you in accelerating security log analysis, policy tuning, script automation, and vulnerability remediation.
Key Responsibilities
- Network & Application Defence: Design, deploy, and support enterprise‑grade WAF, DDoS protection, and bot management services across complex cloud, hybrid, and on‑premises environments.
- Identity & Access Modernisation: Architect and enhance secure customer identity (CIAM) capabilities, supporting modern authentication controls, multi‑factor authentication (MFA), and federated identity protocols (OAuth 2.0, OpenID Connect, SAML).
- API & Perimeter Security: Secure web applications and high‑volume APIs against OWASP Top 10 threats, malicious traffic, and protocol‑layer attacks.
- Security Automation & Infrastructure as Code: Develop automation scripts using Python or PowerShell and leverage modern CI/CD pipelines to enforce security configurations continuously.
- AI‑Assisted Operations: Utilise modern AI tooling and Claude Code to assist in automating threat detection analysis, streamlining incident response playbooks, and optimizing security rulesets.
- Cross‑Functional Collaboration: Partner closely with network, cloud, application development, and DevOps squads to embed security‑by‑design principles natively into the delivery lifecycle.
What You Bring (Attitude & Mindset)
- Thrives in Ambiguity: You are exceptionally comfortable walking into complex, ambiguous security environments. Rather than waiting for a rigid checklist, you take the initiative to rapidly distill requirements and map out robust defense paths.
- Fearless Continuous Learner: When faced with a novel threat vector, an unfamiliar protocol, or a complex integration gap, you do not freeze—you lean in, rapidly upskill, bridge the divide, and master the domain.
- The Desire for a Challenge: You actively seek out difficult security constraints and thrive when protecting high‑scale, mission‑critical financial systems.
- Radical Communication & Ownership: You communicate transparently, collaborate openly with engineering squads, challenge security blind spots early, and take uncompromising personal accountability for protecting the platform.
What You Bring (Technically)
- Security Engineering Mastery: Deep commercial experience in network security engineering, WAF operations, DDoS mitigation, cloud security, or enterprise IAM/CIAM.
- Core Technical Depth: Comprehensive understanding of TCP/IP, HTTP/S, TLS, DNS, load balancing, routing, reverse proxies, and CDN technologies.
- Identity & Access Expertise: Strong practical experience with enterprise identity platforms (such as Microsoft Entra ID / External ID) and federated authentication standards (OAuth 2.0, OIDC, SAML).
- Automation & Scripting: Strong coding and automation background using Python, PowerShell, or REST APIs.
- Tooling Fluency: A practical, delivery‑focused mindset on how to leverage modern AI tools (like Claude Code) to assist in security automation and threat analysis.
What We Offer
- The chance to work for 1 of Australia's fastest‑growing and most innovative software businesses.
- Access to the latest AI tooling to assist you in achieving your technical goals.
- Meaningful, hands‑on security engineering work on mission‑critical financial platforms.
- Clear growth pathways from Senior to Staff and beyond.
- A low‑ceremony, delivery‑focused environment that values engineers who own outcomes.
- Competitive remuneration and benefits.