About the job
About Australian Payments Plus
Australian Payments Plus (AP+) is shaping the future of payments in Australia. The team delivers solutions that support businesses, government, and consumers, including a domestic debit network, real-time payments infrastructure, secure bill payments, digital identity verification, QR payments, and open wallet services.
Role Overview: Senior Cyber Security Engineer
This Sydney-based role focuses on protecting AP+ payment services across both cloud and on-premise environments. The Senior Cyber Security Engineer designs, develops, and implements enterprise security controls and platforms. As the technical escalation point, this person also sets platform roadmaps, mentors other engineers, and drives risk reduction through secure-by-design engineering, automation, and detection and response improvements.
Main Responsibilities
- Architect and engineer security solutions, setting reference patterns and guardrails for cloud, network, endpoint, and application security.
- Oversee platform roadmaps and manage the lifecycle for EDR/XDR, SIEM/SOAR, vulnerability management, secrets/PKI/KMS, PAM/IAM, and vendor/MSSP relationships.
- Develop detection engineering strategies, including use cases and SOAR playbooks; monitor detection metrics such as precision, recall, and dwell time.
- Support major incident response, coordinating cross-team actions, conducting root cause analysis, and implementing system hardening.
- Manage exposure and vulnerability assessments, prioritize risks, enforce SLA compliance, and oversee exception governance.
- Promote DevSecOps practices, secure CI/CD pipelines and Infrastructure as Code, and enhance security for containers and Kubernetes environments.
- Strengthen identity and access management by defining standards for PAM, JIT, and JEA, and automating joiner, mover, and leaver processes.
- Ensure compliance by mapping and evidencing controls to frameworks such as ISO 27001, ASD Essential Eight, PCI DSS, and APRA CPS 234; prepare for audits.
- Conduct security design reviews, provide sign-off for high-risk designs, and advise senior stakeholders.
- Scale security efforts through automation and mentorship, developing reusable modules and policies (using Terraform, Python, or PowerShell) and building engineering capability across the team.
