Information Security Engineer

The Decipher Bureau · Melbourne VIC 3004 · Full time
Posted 24d ago

Information Security Engineer

The Decipher Bureau
~$160k(Estimated)
KEY POINTS WE FOUND
  • Assess current-state Cloudflare / web proxy posture and lead the uplift once recommendations are agreed.
  • Contribute to Microsoft cloud controls and posture assessment including SaaS visibility.
  • Engage directly with stakeholders to gather context and form clear recommendations.

Information Security Engineer:
 
Cloud security & web proxy uplift (18-month FTC, $160k + super)
  
This organisation is one of Australia's largest not-for-profit health insurers, and their information security engineering team is growing as part of a well-funded, genuinely strategic security transformation program. This is a full-time fixed-term role for 18 months, reporting to the Information Security Engineering Lead, with 2 days a week on-site and the remainder remote, genuinely flexible on location for the right candidate.
  
The core of this role is assessing where current cloud and web-proxy controls sit (Cloudflare is already deployed) and mapping out where they need to get to, then leading the uplift once that's agreed. You'll also get involved in Microsoft cloud posture and SaaS visibility work, and some vulnerability management. It's a hands-on role, but it's also genuinely a figure-it-out-and-present-back kind of job; you'll be given a steer, not a script, so the organisation cares more about your judgment and self-direction than a perfect skills checklist.
  
What you'll be doing

  • Assess current-state Cloudflare / web proxy posture, identify gaps, and lead the uplift once recommendations are agreed
  • Contribute to a Microsoft cloud controls and posture assessment including SaaS visibility and E5 licensing utilisation across a modern, SaaS-heavy stack
  • Support the organisation's vulnerability management uplift, working alongside external consultants currently assessing the current state
  • Pick up integration engineering work as new security capability continues to be built out
  • Engage directly with stakeholders (infrastructure, cloud, service delivery teams) to gather context, form a current-state picture, and bring back clear, concise recommendations
  • Keep documentation, runbooks and escalation procedures current as new tooling and controls are rolled out

What you'll bring
Must-have:

  • Strong, hands-on cloud security experience, ideally Microsoft/Azure/M365
  • Comfortable self-directing, able to take a high-level steer, find the right people, gather what's needed, and form your own recommendations
  • Experience defining technical Information Security controls and assessing risk
  • Understanding of NIST CSF and NIST Controls
  • Tertiary qualification in Information Security or Information Technology (or significant equivalent experience in broader technology-based roles)

Desirable:

  • Experience with Cloudflare or similar web proxy / CASB-type platforms
  • Vulnerability management experience from an engineering perspective
  • Broader SOC/SIEM and security operations background
  • Experience in private health insurance or another similarly regulated industry
  • Technical cyber security certifications or vendor-specific certifications
  • Familiarity with regulatory requirements (e.g. CPS 234, Privacy Act) and industry standards 

What's in it for you:

  • Hybrid working model  flexibility to split time between the office and off-site
  • Discounted health insurance for you and, after probation, your immediate family
  • Salary sacrifice options, including novated car leasing and additional super
  • 14 weeks' paid parental leave, plus the option to purchase up to 4 weeks' extra annual leave
  • A modern, sustainability-rated office with end-of-trip facilities
  • Ongoing training and development, plus 24/7 wellbeing support and an Employee Assistance Program

About Decipher Bureau
The Decipher Bureau is Australia's leading cyber security recruitment specialist, partnering with organisations across government, critical infrastructure and enterprise to identify and secure exceptional talent. We take the time to understand both the technical requirements of a role and a candidate's cultural fit, in the belief that the right placement will always outweigh a quick one.
  
Interested?
Reach out for a confidential chat:

  • Anthony Buccat — ************
  • **************************

(We are committed to creating a diverse and inclusive workplace. All qualified applicants will be considered for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, or disability.)

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 15 matched
Cloud securityCloudflareCyber security certificationsMicrosoft azureNist csfRegulatory requirements (e.g., cps 234, privacy act)Risk assessmentSaas visibilitySecurity controls assessmentSecurity documentationSelf-directionStakeholder engagementTechnical controls definitionVulnerability managementWeb proxy

Perks & benefits

0 of 3 matched
14 weeks paid parental leaveDiscounted health insuranceHybrid working model flexibility

The Decipher Bureau