Canva logo
CanvaPosted 3 weeks ago

Senior Security Engineer – Investigations

HybridSydney, New South Wales, Australia

Full TimeSenior LevelLarge

Job Summary

Lead high-complexity investigations involving sophisticated techniques, legal, and regulatory considerations while coordinating with Legal, People, and Security teams on scope, evidence handling, and response activities. Write detailed investigation reports documenting findings, evidence, impact, and recommendations for technical and non-technical stakeholders. Respond to security events from detection through containment, remediation, and resolution, and create or improve detection logic, correlation rules, and alerts across SIEM and EDR platforms. Proactively run threat hunting and anomaly detection exercises, design scalable tooling, and act as an escalation point during active incidents. Participate in a collaborative on-call rotation supporting critical security investigations and incident response activities. Mentor teammates through knowledge sharing and operational guidance.

Required Qualifications

  • Experience leading or coordinating security investigations, digital forensics, or incident response activities in complex environments
  • Comfortable working cross-functionally with Legal, People, and Security teams, and can communicate clearly during high-pressure situations
  • Able to translate complex technical concepts for diverse audiences, including non-technical stakeholders
  • Built or improved detection, automation, case management, or response workflows at scale
  • Hands-on experience investigating macOS environments, alongside Linux and Windows systems
  • Comfortable designing, building, and improving security tooling and operational workflows
  • Confident working with SIEM, EDR, endpoint telemetry, and security investigation tooling
  • Enjoy solving ambiguous problems and proactively improving systems, processes, and operational maturity
  • Bring empathy, sound judgement, humility, and a collaborative mindset to sensitive investigations and incident coordination
  • Programming or scripting experience in languages such as Python, Golang, or Java

Desired Qualifications

  • Experience with insider threat programs or user behaviour analytics (UBA/UEBA)
  • Familiarity with DLP technologies and endpoint monitoring solutions
  • Experience building security automation or orchestration tooling
  • Exposure to legal evidence handling, privacy investigations, or law enforcement collaboration
  • Experience operating in cloud-native or large-scale SaaS environments

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce