SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Canva is seeking a Staff Security Engineer to join the Internal Systems Security team, which protects Canva's internal environment—laptops, networks, identities, SaaS tools, and AI agents. This is a Staff-level individual contributor role focused on setting technical direction without managing people.
The role addresses emerging security challenges as Canva scales AI agent adoption. Key responsibilities include:
• Collaborating with teams across the business to identify real risks and build roadmaps together, rather than imposing top-down solutions.
• Enabling AI workflows safely by working with teams to turn on new capabilities without creating blockers.
• Reviewing new tools and agents before deployment, making approval decisions with appropriate guardrails.
• Threat modeling emerging patterns such as MCP (Model Context Protocol), agentic workflows, and SaaS-to-SaaS integrations, then translating findings into controls that teams will actually adopt.
• Setting technical standards for other teams to build against and automating work to prevent team scaling issues.
You'll work in a hybrid model based in Sydney, with flexibility to work remotely and collaborate on campus when it matters most.
Qualifications:
• Demonstrated ability to identify problems independently, gain stakeholder buy-in, and drive solutions to completion.
• Proven track record convincing IT or engineering leaders to prioritize security work without formal mandate.
• Hands-on experience in enterprise, corporate, or internal security engineering, with production experience running security services (endpoints, networks, identity, SaaS estates).
• Strong conceptual understanding of security controls—knowing why a control works matters more than knowing which tool to use.
• Code writing and review skills trusted by other engineers; preference for automation-first approaches.
Nice to have:
• Security experience across diverse business functions (marketing, sales, etc.).
• macOS fleet management at scale: device trust, posture signals, zero trust, certificate-based device attestation.
• SaaS security posture management: configuration baselines, SSPM, OAuth risk, third-party integration security, non-human identity management.
• Experience securing AI agents, MCP servers, or agentic workflows, including action-level policy, tool call mediation, audit trails, and containment.
• Proficiency in Terraform, Python, or Go; experience with AWS or GCP.