Senior Security Engineer - Detection & Response (remote Across Australia)

Canva Canva · Enterprise · Sydney, Australia · Information Technology

This role is for a Senior Security Engineer focused on Detection & Response within Canva's cloud-native infrastructure. The primary responsibilities include designing and implementing detection capabilities, automating security workflows, enhancing security platform infrastructure, leading incident response, and investigating security alerts. The role requires experience with enterprise security platforms (SIEM, EDR, SOAR), cloud providers, scripting languages, and advanced detection techniques, including mention of GenAI workflows. While AI tools may be used in interviews and GenAI is mentioned as an advanced detection technique, the core craft of the role is not AI/ML model building.

What you'd actually do

  1. Leading incident response coordination and acting as escalation point for security incidents across Canva's cloud-native infrastructure, including participation in the on-call rotation
  2. Investigating and triaging security alerts, coordinating containment, eradication, and recovery activities across a range of security events
  3. Leading and contributing to post-incident reviews, translating incident learnings into improved detections, playbooks, and response processes
  4. Building and maintaining automation workflows and response playbooks that streamline investigation, triage, and response, reducing analyst toil and improving mean-time-to-respond
  5. Partnering with CTI, Application Security, and Red Team to turn threat intelligence and emerging risks into practical detection and response outcomes

Skills

Required

  • incident response
  • DFIR
  • security operations
  • SIEM (Elastic Security, Splunk, or similar)
  • EDR (SentinelOne, CrowdStrike, Microsoft Defender, or similar)
  • SOAR platforms
  • investigative mindset
  • risk-based decisions
  • AWS, GCP, or Azure
  • cloud attack techniques
  • infrastructure-as-code (Terraform/Ansible)
  • DevOps practices
  • documentation
  • communication
  • stakeholder management
  • Python
  • Go
  • behavioural analytics
  • anomaly detection
  • GenAI workflows
  • GenAI harnesses

Nice to have

  • Threat Hunting
  • Threat Intelligence
  • forensic acquisition and analysis
  • chain of custody
  • containerised and Kubernetes environments
  • Publishing research in blogs
  • contributing to open-source security tools

What the JD emphasized

  • proven track record coordinating security events from detection through resolution
  • working knowledge in at least one of the major cloud providers (AWS, GCP, or Azure) and cloud attack techniques
  • proficient in scripting and programming languages (Python, Go, or similar)
  • experience with advanced detection techniques: behavioural analytics, anomaly detection, GenAI workflows and GenAI harnesses