Security Engineer
Mable
Apply to this jobWe are seeking an experienced Security Engineer to help design, build, and maintain the security posture of Mable's platform and infrastructure. This is a senior individual contributor role that sits at the intersection of engineering and security - you will embed security thinking directly into how we build and operate systems, rather than sitting outside the process as an auditor or gatekeeper.
The ideal candidate brings both technical depth and the ability to work cross-functionally, partnering with engineers, product, infrastructure, and leadership to ensure that security is a consideration across everything we build. You are comfortable moving between proactive security work (threat modelling, secure design, vulnerability assessment) and reactive response (incident support, remediation), and you bring a practical, risk-based mindset to both.
Key accountabilities
-
Design and implement security controls across Mable's platform, applications, and infrastructure - including access controls, encryption, network segmentation, and endpoint protection
-
Embed security into the software development lifecycle: participate in design reviews, threat modelling sessions, and code reviews to identify and address risks early
-
Lead vulnerability assessments and coordinate remediation efforts across engineering teams, prioritising based on risk and business impact
-
Monitor systems and infrastructure for suspicious activity; support incident response including investigation, containment, and post-incident analysis
-
Define and maintain security standards, guidelines, and sensible defaults for engineering teams - making the secure path the easy path
-
Partner with Engineering Team Leads and engineers to build security literacy across squads, providing advice and guidance on secure coding practices and tooling
-
Contribute to the assessment and adoption of security tooling - including SIEM, vulnerability scanning, secrets management, and intrusion detection
-
Support compliance and risk management obligations relevant to Mable's operating environment (e.g. Australian Privacy Act, ISO 27001 alignment, Essential Eight)
-
Monitor the external threat landscape and emerging attack vectors; translate findings into practical recommendations for the business
-
Collaborate with Infrastructure Engineers on secure cloud architecture, CI/CD pipeline security, and secrets management practices
Skills, Knowledge and Experience
-
8+ years of experience in a security engineering, application security, or systems security role
-
Strong understanding of secure software design principles, common vulnerability classes (OWASP Top 10, CWE), and how to remediate them in a modern cloud-native environment
-
Hands-on experience with cloud security - AWS preferred - including IAM, network security groups, secrets management, and secure infrastructure configuration
-
Experience with security tooling across at least several of: SIEM, vulnerability scanners, DAST/SAST, intrusion detection, endpoint protection, and secrets management
-
Demonstrated ability to conduct threat modelling and security design reviews
-
Working knowledge of relevant compliance frameworks and privacy obligations applicable in Australia (Privacy Act, Essential Eight, ISO 27001)
Summary
Design, implement, and monitor security controls; embed security in development; respond to incidents.
Job title
Security Engineer
Experience level
8+ years
Minimum experience
8+ years exp
Industry
healthtech
Location requirements
Sydney-based with hybrid work allowed, remote work option present
Salary
Not specified
Visa sponsorship
H-1B sponsor history
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
Sydney NSW, Australia