refresh

Trending companies

Trending companies

Canva
Canva

Empowering the world to design.

Senior Security Engineer - Detection & Response (remote across Australia) at Canva

RoleSecurity
LevelSenior
LocationSydney
WorkRemote
TypeFull-time
Posted1 day ago
Apply now

About the role

Join the team redefining how the world experiences design.

Hey, hello, hiya, g'day, mabuhay, kia ora, 你好, hallo, vítejte!

Thanks for stopping by. We know job hunting can be a little time consuming and you're probably keen to find out what's on offer, so we'll get straight to the point.

Where and how you can work

Our flagship campus is in Sydney. We also have a campus in Melbourne and co-working spaces in Brisbane, Perth and Adelaide. But you have choice in where and how you work. That means if you want to do your thing in the office (if you're near one), at home or a bit of both, it's up to you.

What you’d be doing in this role

As Canva scales change continues to be part of our DNA. But we like to think that's all part of the fun. So this will give you the flavour of the type of things you'll be working on when you start, but this will likely evolve.

As a Senior Security Engineer, you will deliver high-impact security engineering solutions across our detection and platform engineering service streams. You will design and implement detection capabilities, automate security workflows, and enhance our security platform infrastructure. Your work will directly strengthen Canva's security posture by enabling faster threat detection, reducing analyst toil through automation, and scaling our security operations capabilities.
We are not looking for someone who checks every single box, we’re looking for lifelong learners and people who can make us better with their unique experiences.

  • Leading incident response coordination and acting as escalation point for security incidents across Canva's cloud-native infrastructure, including participation in the on-call rotation

  • Investigating and triaging security alerts, coordinating containment, eradication, and recovery activities across a range of security events

  • Leading and contributing to post-incident reviews, translating incident learnings into improved detections, playbooks, and response processes

  • Building and maintaining automation workflows and response playbooks that streamline investigation, triage, and response, reducing analyst toil and improving mean-time-to-respond

  • Partnering with CTI, Application Security, and Red Team to turn threat intelligence and emerging risks into practical detection and response outcomes

  • Developing and improving security response tooling and capabilities across areas including case management, automation, SOAR, SIEM, and forensics

You're probably a match if

  • You have demonstrable experience in incident response, DFIR, or security operations, with a proven track record coordinating security events from detection through resolution

  • You've worked extensively with enterprise security platforms including SIEM (Elastic Security, Splunk, or similar), EDR (Sentinel One, Crowd Strike, Microsoft Defender, or similar), and SOAR platforms

  • You have an investigative mindset with the ability to solve ambiguous security problems and make risk-based decisions under pressure

  • You possess working knowledge in at least one of the major cloud providers (AWS, GCP, or Azure) and cloud attack techniques.

  • You have working knowledge of infrastructure-as-code (Terraform/Ansible) and DevOps practices

  • You excel at documentation, communication, and stakeholder management during incidents

  • You are proficient in scripting and programming languages (Python, Go, or similar)

  • You have experience with advanced detection techniques: behavioural analytics, anomaly detection, GenAI workflows and GenAI harnesses

Beneficial Experience (not required, but helpful)

  • Experience with Threat Hunting or Threat Intelligence

  • Background in forensic acquisition and analysis, including maintaining chain of custody

  • Incident response in containerised and Kubernetes environments

  • Publishing research in blogs or contributing to open-source security tools

About the team

The Detection & Response organisation protects Canva from security threats through detection, investigation, incident response, and security operations. We operate at the intersection of security engineering and security operations, building and improving the capabilities, workflows, and tools that enable Canva to identify, investigate, and respond to threats at scale.

What's in it for you?

Achieving our crazy big goals motivates us to work hard - and we do - but you'll experience lots of moments of magic, connectivity and fun woven throughout life at Canva, too. We also offer a stack of benefits to set you up for every success in and outside of work.

Here's a taste of what's on offer:

  • Equity packages - we want our success to be yours too

  • Inclusive parental leave policy that supports all parents & carers

  • An annual Vibe & Thrive allowance to support your wellbeing, social connection, office setup & more

  • Flexible leave options that empower you to be a force for good, take time to recharge and supports you personally

Check out lifeatcanva.com for more info.

Other stuff to know

We see AI as a powerful amplifier of creativity and technology at Canva. We’re evolving how we assess AI skills in our Technology hiring experience - you’ll tackle interactive, real-time challenges that reflect the kind of work we do. In some interviews, you may also be asked to solve a problem using an AI tool to show how you approach challenges with tech by your side. Your recruitment partner will walk you through what to expect.

We make hiring decisions based on your experience, skills and passion, as well as how you can enhance Canva and our culture. When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.

Please note that interviews are conducted virtually.

Required skills

detection engineering

incident response

security automation

security platform engineering

threat detection

Total Views

0

Total Apply Clicks

0

Total Mock Apply

0

Total Bookmarks

0

About Canva

Canva

Canva

Series D

An online design and visual communication platform that provides design tools for non-designers.

1,001-5,000

Employees

Sydney

Headquarters

$40B

Valuation

Reviews

10 reviews

4.2

10 reviews

Work-life balance

3.8

Compensation

2.5

Culture

4.3

Career

4.0

Management

4.2

78%

Recommend to a friend

Pros

Flexible schedules and hours

Supportive team and leadership

Growth and learning opportunities

Cons

Fast-paced and demanding workload

Can be overwhelming or stressful

Occasional long hours

Salary Ranges

31 data points

Junior/L3

L2

L6

L3

L4

L5

Junior/L3 · Cybersecurity Analyst

0 reports

$194,880

total per year

Base

-

Stock

-

Bonus

-

$165,648

$224,112

Interview experience

2 interviews

Difficulty

3.0

/ 5

Duration

14-28 weeks

Experience

Positive 0%

Neutral 50%

Negative 50%

Interview process

1

Application Review

2

Online Assessment/Portfolio Review

3

Recruiter Screen

4

Hiring Manager Interview

5

Team Interview

6

Offer

Common questions

Technical Knowledge

Portfolio/Design Questions

Behavioral/STAR

Culture Fit

Past Experience