SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Canva is seeking a Staff Security Engineer to join the Internal Systems Security team, which protects Canva's internal environment—laptops, networks, identities, SaaS tools, and AI agents. This is a Staff-level individual contributor role focused on setting technical direction without managing people.
The role addresses emerging security challenges as Canva scales AI agent adoption. Key responsibilities include:
• Collaborating with teams across the business to identify real risks and build roadmaps together, rather than imposing top-down solutions
• Enabling safe AI workflows and agent adoption by reviewing new tools and agents before deployment
• Threat modeling emerging patterns such as MCP (Model Context Protocol), agentic workflows, and SaaS-to-SaaS integrations, then translating findings into adopted controls
• Setting technical standards that other teams build against and automating work to prevent team scaling as workload multiplies
• Reviewing and approving tool and agent deployments with a yes/no/yes-with-settings approach
The Internal Systems Security team operates in a rapidly evolving landscape where traditional playbooks no longer apply. A key current challenge: determining where policy enforcement sits for MCP tool calls—decisions made per action rather than per application, evaluated fast enough to be transparent to users.
You are a strong match if you:
• Proactively identify problems, build consensus across teams, and drive solutions to completion without formal mandate
• Have hands-on experience in enterprise, corporate, or internal security engineering, having built and operated security services in production (endpoints, networks, identity, SaaS estates)
• Prioritize conceptual understanding over tool familiarity; you know why controls work, not just how to deploy them
• Write and review code to standards other engineers trust and automate by default
• Can bring stakeholders along on security initiatives that weren't originally on their roadmap
Nice-to-have experience includes:
• Security work across diverse business functions (marketing, sales, etc.)
• macOS fleet management at scale: device trust, posture signals, zero trust, certificate-based device attestation
• SaaS security posture management: configuration baselines, SSPM, OAuth and third-party integration risk, non-human identity management
• Securing AI agents, MCP servers, or agentic workflows—action-level policy, tool call mediation, audit trails, and containment
• Terraform, Python, or Go; AWS or GCP cloud experience
Canva's Sydney campus is in Surry Hills and serves as the flagship office. The role is based in Sydney with a hybrid working model that balances remote flexibility with in-person collaboration when it matters most.