Role details
our client is a dynamic online trading provider focused on delivering great trading tools and professional trading insight to enable smarter trading. With a commitment to excellence and a passion for delivering trading technology directly to clients and via our network of strategic partners, we blend the agility of a fintech innovator with the trust and stability of a regulated financial institution. Our mission is to empower clients to succeed in the markets through seamless, secure, and intuitive trading experiences. With a fast-paced, collaborative, and innovative culture, our client continues to evolve as a leader in the online trading space.
The company is headquartered in Melbourne, Australia, with support offices in the UK, Cyprus, Bulgaria, Seychelles and the Bahamas.
Recently recognised as Broker of the Year 2024 and Best Partner and Affiliate Program 2025 at the Global Forex Awards, we pride ourselves on innovation, outstanding customer service, and unwavering integrity in everything we do.
We are seeking an experienced Cyber Security Engineer to support our client’s growth by delivering and continuously improving security capabilities across security operations, cloud and corporate security architecture, identity and access management, and governance risk and compliance initiatives.
The ideal candidate will have a strong background in cyber security engineering, cloud security, and security operations, with a proven ability to deliver scalable security solutions in a fast paced, high performance environment. This role plays a key part in protecting our client’s trading platforms, client data, corporate systems, and global operations while supporting our mission to provide an exceptional experience to both our clients and team.
Security Engineering & Delivery
● Deliver and continuously improve security capabilities across cloud, corporate, and trading environments
● Build, implement, and maintain security controls, tooling, and automations that strengthen protection, resilience, and operational efficiency
● Contribute security engineering input to projects, infrastructure changes, and technology decisions across the business
● Identify opportunities to simplify security processes by replacing repeatable manual work with scalable automated solutions
● Support the uplift of our client’s internal security capability through practical engineering, documentation, and knowledge sharing
Security Operations & Incident Response
● Contribute to security operations capability across monitoring, alert triage, investigation, response, and remediation activities
● Develop and improve detection logic, alerting workflows, response processes, and operational tooling to increase signal quality and reduce manual effort
● Support incident response activities including technical investigation, containment, remediation, and post-incident improvement actions
● Work with internal teams and third party providers to ensure security events are effectively investigated and resolved
● Maintain and improve operational playbooks, response processes, and security visibility across key environments
Cloud Security & Architecture
● Contribute to the design and implementation of security improvements across cloud platforms and supporting infrastructure
● Partner with engineering and cloud teams to strengthen architecture, remediate vulnerabilities, and improve overall security posture
● Support secure design and review of new systems, services, and technical changes
● Maintain and improve cloud security tooling to ensure outputs are actionable and support measurable risk reduction
● Contribute to the evolution of security standards and architectural patterns aligned with business needs, emerging threats, and industry practice
Identity & Access Security
● Implement and improve identity and access controls across corporate systems, cloud platforms, and business critical applications
● Support adoption and operation of strong access control practices including MFA, SSO, RBAC, least privilege, and privileged access management
● Contribute to access governance activities such as access reviews, remediation of inappropriate access, and improvement of joiner mover leaver controls
● Build and enhance automation and tooling that strengthens identity governance and reduces manual administrative effort
Governance, Risk & Compliance
● Contribute to governance risk and compliance initiatives including control design, evidence collection, remediation tracking, and audit support
● Support alignment with regulatory obligations, internal standards, and security frameworks including ISO 27001 aligned practices where applicable
● Partner with stakeholders across the business to identify, assess, and address information security risks in a pragmatic and technically informed way
● Support continuous improvement of policies, standards, and control effectiveness through practical engineering input
Business Support & Cross Functional Engagement
● Provide practical security guidance and support to stakeholders across engineering, cloud, product, corporate, and business teams
● Contribute to technical and operational discussions with a focus on enabling secure and pragmatic business outcomes
● Support a team culture where traditionally separate security functions are shared and engineers take ownership of improving delivery of security outcomes
● Collaborate across the team to balance delivery, operational support, and continuous improvement priorities
Essential
● Proven experience in a cyber security engineering, cloud security, infrastructure security, or related technical security role within a modern enterprise environment
● Strong engineering capability with hands on experience building and maintaining security tooling, automations, scripts, or internal applications
● Experience working in modern development environments using Git, branching strategies, pull requests, CI/CD pipelines, and controlled release practices
● Experience securing corporate technology environments including endpoints, productivity platforms, SaaS applications, device management, corporate networks, wireless environments, and third party applications
● Experience working with identity platforms and identity and access management controls including MFA, SSO, RBAC, least privilege, privileged access, access reviews, and lifecycle controls
● Experience contributing to security operations and incident response activities including investigation and remediation of security incidents, detection engineering, alert tuning, and use of SIEM, XDR, and SOAR tooling
● Demonstrated willingness to contribute across shared security responsibilities including elements of security operations, governance risk and compliance, and broader security support across the business
● Strong judgement, initiative, and ability to work effectively in ambiguous environments while building collaborative relationships with stakeholders across the organisation
Desired
● Experience working within financial services, fintech, trading platforms, or other regulated environments
● Experience working with platforms such as AWS, Google Workspace, Entra ID, Microsoft Sentinel, Microsoft Defender, or similar enterprise security technologies
● Experience supporting security audits, control uplift activities, and frameworks aligned to ISO 27001
● Experience securing hybrid environments across AWS, SaaS platforms, endpoint environments, and corporate technology domains
● Relevant cyber security, cloud, or engineering certifications
Benefits
● Ongoing investment in your career development (technical and professional training)
● Wellness and lifestyle perks like monthly corporate massages
● Reward & recognition
● Drinks every Friday at 4pm
● Parental leave
● Staff referral bonus program
● Annual flu vaccinations
● Purchased leave
● Novated leasing options for vehicle financing and management
● Great CBD location with easy access to public transport
● Multicultural environment
● Collaborative team culture
● Regular social activities
