Canva logo

Canva

Staff Security Engineer

Work from home

Remote role where the employee must remain based in a particular country.

Australia only

Employer listed it 9 days ago · Added yesterday

First listed 9 days ago and still open.

Salary

Not stated

Location

Australia only

Timezone

APAC

Contract

Full-time

Experience

Lead

Category

Software

This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 596 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Work from home

This is a remote role, but the employee must be based in Australia. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Sydney, , Australia, Sydney, au, Remote"
  • Job description states: "based in Sydney"

What Nomaders makes of it

  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

 

 

Staff Enterprise Security Engineer

Join the team redefining how the world experiences design.

Hey, gday, mabuhay, kia ora, 你好, hallo, vítejte!

Thanks for stopping by. We know job hunting can be a little time-consuming, and you're probably keen to find out what's on offer, so we'll get straight to the point.

About the team

The Security Group protects Canva's systems and data from information security threats, across Application Security, Risk Management, Enterprise Security, and Threat Detection and Response. Internal Systems Security is the team inside that focused on Canva's own environment.

What you'd be doing in this role

The Internal Systems Security team secures the environment Canvanauts work in every day. Laptops, networks, identities, the SaaS tools everyone relies on, and now the AI agents doing real work alongside us.

Most of this work used to follow a playbook. That's no longer true. Canvanauts now run AI agents that act on their behalf, which is a very different security problem to a person at a laptop. One of the questions on our plate right now: where does the policy layer sit for MCP tool calls, when we want decisions made per action rather than per application, and evaluated fast enough that nobody notices them?

This is a Staff level individual contributor role. You'd set technical direction without managing anyone.

At the moment, that means:

Going out to teams across the business, working out where their real risks sit, and building the roadmap with them rather than handing them one.

Helping those teams turn on AI workflows safely, instead of being the reason they can't.

Reviewing new tools and agents before they land. We're the team that says yes, no, or yes with these settings.

Threat modelling newer patterns like MCP, agentic workflows and SaaS to SaaS integrations, then turning what you find into controls people adopt.

Setting the standards other teams build against, and automating the work so a multiplying workload doesn't need a bigger team.

You're probably a match if:

You go looking for problems. You can point to something you found yourself, got other people to care about, and saw through to a fix.

You can bring people with you. You've convinced an IT or engineering lead to take on something that wasn't on their roadmap, without a mandate.

You've done hands-on enterprise, corporate or internal security engineering, and built and run security services in production. Endpoints, networks, identity, SaaS estates.

You value concepts over tools. Knowing the tooling matters. Knowing why a control works matters more.

You write and review code to a standard other engineers trust, and you automate by default.

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Canva, mentioning your remote working experience and working hours (APAC).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 1d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $200k–$275k · You'll be taken to the employer's careers page.