Role details
Cloud security across AWS and GCP, embedded in the SDLC, with a real mandate to shape the security roadmap.
You'll own the intersection of cloud engineering and security operations, keeping infrastructure patched and compliant while building out security controls across networks, systems, and applications. Day to day that means monitoring alerts and investigating incidents, running vulnerability assessments, and working with the broader tech team to bake security into every stage of the development lifecycle.
The team runs on AWS and GCP, with Kubernetes (EKS), Docker, Terraform, and Python forming the core of the toolset. CI/CD pipelines are already in place, so you're refining and securing what exists rather than building from scratch. There's genuine scope to automate repetitive tasks and bring AI tooling into the mix where it makes sense.
You'll have a seat at the table with the Security Committee and cross-functional IT teams, which means your security awareness work actually lands rather than sitting in a slide deck. The company takes governance seriously, with NIST, ISO 27001, and Essential 8 as live frameworks, not aspirational ones. There's also mentoring responsibility for junior infrastructure team members if that kind of work interests you.
What You'll Do
- Maintain and patch cloud infrastructure across AWS and GCP, monitoring alerts and investigating potential incidents against SLA and security standards.
- Design and implement security controls across networks, systems, and applications, including vulnerability assessments and support for penetration testing.
- Embed security throughout the SDLC and deliver security awareness training to IT teams and the Security Committee.
- Support Business Continuity and Disaster Recovery planning, contribute to the security roadmap, and coach junior infrastructure team members.
What You'll Need
- 5+ years in DevOps or CloudOps on AWS and/or GCP, with at least 3 years building secure infrastructure and managing firewalls, IDS, SIEMs, and vulnerability scanners.
- Advanced hands-on experience with Kubernetes (EKS), Docker, Terraform, Python, and CI/CD pipelines.
- Working knowledge of NIST, ISO 27001, the Privacy Act, and Essential 8.
- Certifications such as CISSP, CCSP, AWS Security Specialty, or equivalent GCP certs are a bonus, as is experience securing Google Workspace.
About the Company
They're a well-known Australian comparison platform, helping consumers make informed financial decisions across products like home loans, credit cards, and insurance. The technology team builds and operates the core systems powering those services at scale, for both internal teams and millions of external users.
Apply
Please click the 'Apply' button. Don't worry if your CV isn't up to date - just send what you have.
