Senior Security Engineer - Incident Response

Canva
Summary
Join Canva's Digital Forensics & Incident Response (DFIR) team as a Senior Security Engineer and play a pivotal role in safeguarding Canva's systems, data, and user information. You will act as an escalation point for security incidents, actively respond to security events, monitor systems for attacks, and contribute to the team's knowledge and experience. Proactive threat detection, tool development, and incident report maintenance are also key responsibilities. The ideal candidate possesses strong incident response experience, excels in building security tooling, and enjoys mentoring others. Collaboration with cross-functional teams and clear communication under pressure are essential. Canva offers a range of benefits, including equity packages, inclusive parental leave, a wellbeing allowance, and flexible leave options.
Requirements
- You have strong experience in security incident response and coordinating complex investigations
- Youβre confident in building and maintaining security tooling and infrastructure
- You love mentoring and developing others and have experience leading small technical teams
- You're passionate about improving systems and processes to prevent future incidents
- Youβre comfortable working with cross-functional teams and communicating clearly under pressure
- You bring empathy, humility, and generosity to everything you do
Responsibilities
- Acting as an escalation point and incident coordinator for security incidents across Canva's systems
- Actively responding to security events from detection through to resolution, including the rollout of solutions and mitigations to prevent a recurrence
- Monitoring Canva's internal and production systems for possible attacks and intrusions
- Contributing to the knowledge and experience of your peers on the security team
- Proactively run threat detection exercises and search for anomalous behaviour
- Building out and developing the tools and foundations for security incident alerting, management, communication, and response
- Maintaining incident response documentation, participating in post-incident reviews, and contributing to incident reports
- Participating in the on-call roster for security incident response
- Identifying trends, research, new technologies, and emerging threats models, which may impact the business
Benefits
- Equity packages β we want our success to be yours too
- Inclusive parental leave policy that supports all parents & carers
- An annual Vibe & Thrive allowance to support your wellbeing, social connection, office setup & more
- Flexible leave options that empower you to be a force for good, take time to recharge and support you personally