Security Engineer

Avertro|New South Wales, Australia|Full-time|Entry level

Ready to Use Your Security Expertise to Build Secure-by-Design Software and Fortify Technical Defenses?


Join Avertro, a venture-backed cybersecurity startup building a platform that empowers security leaders to manage cyber risk with confidence. We’re on the lookout for a talented Security Engineer who is passionate about integrating deep technical security principles directly into the software development lifecycle and strengthening our corporate cyber defenses.


We’re solving one of the industry’s biggest challenges: turning raw security and business data into clarity for decision-makers. If you're a hands-on engineer who thrives at the intersection of development and defense, this is your chance to contribute to a world-class, intrinsically secure SaaS product and protect our critical infrastructure.


The Opportunity

As a Security Engineer at Avertro, you will be a key player in ensuring our platform remains secure, scalable, and resilient. You will embed hands-on security controls, champion advanced secure coding practices, and lead initiatives to automate security tasks across the organisation. Your work will directly influence our platform's security architecture and the robustness of our internal systems. You’ll join us at a critical growth stage, where our platform is live with enterprise customers and rapidly extending its capabilities.


🧩 What You’ll Do

  • Application Security (AppSec): Perform hands-on static and dynamic analysis (SAST/DAST), collaborate on code reviews, and conduct penetration testing to proactively find and eliminate vulnerabilities in our core platform and APIs.
  • Cloud Infrastructure Security: Architect, implement, and automate technical security controls for our AWS environment, focusing on least privilege, network segmentation, and hardening of services (e.g. Lambda, ECS, S3).
  • Security Architecture & Design: Partner with engineering teams to perform in-depth security architecture reviews and design secure-by-default features from conception.
  • Automated Security Tooling: Design and build automation scripts and tools to continuously monitor security posture, manage secrets, and streamline deployment of security agents.
  • GRC Automation & Engineering: Design, implement, and maintain automated controls, continuous monitoring, and evidence collection pipelines to ensure systematic compliance with security frameworks (e.g., SOC 2, ISO 27001) and internal security policies.
  • Security Operations & Incident Response: Enhance logging, monitoring, and detection capabilities (SecOps). Lead the technical investigation, containment, and remediation of security incidents across corporate and product environments.
  • Identity and Access Management (IAM): Own and optimize technical IAM policies and systems across product and corporate accounts to enforce robust Zero Trust principles.


🔍 What We’re Looking For

  • Proven experience as a Security Engineer, Software Engineer, DevOps Engineer, or a similar hands-on technical role.
  • Deep expertise in applying cybersecurity principles, common vulnerabilities (e.g., OWASP Top 10), and practical mitigation techniques in a cloud-native environment.
  • Strong experience with secure coding practices and security testing in a modern stack (e.g., React, Node.js, Python, GraphQL).
  • Practical experience translating compliance requirements (such as SOC 2 or ISO 27001) into technical security controls and engineering solutions for automated evidence collection and auditing.
  • Demonstrated proficiency in AWS security, including IAM, VPC, security groups, and using Infrastructure-as-Code (Terraform/CloudFormation).
  • Hands-on experience with security tools such as SAST/DAST scanners, vulnerability management platforms, and SIEM/logging solutions.
  • Strong communication skills to articulate complex technical risks and collaborate effectively across engineering and product teams.


 Bonus Points

  • Experience in a scaling startup or high-growth B2B SaaS environment.


💥 Why You’ll Love Working With Us

  • Grow with us: Your career will progress in line with the company’s growth.
  • Be part of a venture-backed startup solving a mission-critical problem in cybersecurity.
  • Join a collaborative, high-trust team that values autonomy and curiosity.
  • Flexible working hours as long as you meet your commitments.
  • Competitive package: salary and equity options.
  • Influence the product and strategic direction of the company as one of our early hires.
  • Grow with us: Your career will progress in line with the company’s growth.


✨ Interested?


If you love solving complex problems and want your work to have real-world impact, we’d love to hear from you.


Please note, only shortlisted candidates will be contacted. No agencies please.



AI Sourcing Intelligence

Sourcing Advice for This Role

AI-powered analysis of recruitment difficulty and recommended sourcing channels for this position.

Recruitment Difficulty Analysis

Key challenge: This is an entry level Security Engineer role in a high-growth Australian cybersecurity startup. The biggest challenge is sourcing hands-on, cloud‑security‑savvy candidates locally in New South Wales who have practical experience with secure SDLC practices, SAST/DAST, and AWS, given intense national competition from larger tech employers.

Recommended Sourcing Channels

LinkedIn Groups

Best Channel

Niche, locally focused groups let you reach early-career security professionals active in Australia and NSW, enabling targeted outreach and discussion about a startup security role.

Recommended Groups on StrategyBrain:

LinkedIn Search (Boolean)

Supplementary

Boolean search broadens reach to active candidates who may not engage groups/events, serving as a scalable feeder for the pipeline.

Recommended Boolean query:
(Security Engineer OR Cyber Security Engineer OR InfoSec Engineer) AND (New South Wales OR NSW OR Sydney) AND (Australia)(AppSec OR application security OR SAST OR DAST OR secure coding OR penetration testing) AND (React OR Node.js OR Python OR GraphQL) AND (AWS OR cloud OR CloudFormation OR Terraform)(Junior OR Graduate OR New grad) AND (Startup OR SaaS OR high growth) AND (Australia OR NSW)

Suggested Search Criteria

Job Titles to Search
Security EngineerJunior Security EngineerInformation Security EngineerAppSec EngineerSecurity Analyst
Key Skills
Application securitySASTDASTAWS securityTerraform
Location Radius
Prioritize candidates located in New South Wales, especially Sydney metro; consider near NSW or willing to relocate within Australia; remote work with occasional on-site collaboration is acceptable if candidates can align with Australian business hours.
Experience Level
0-3 years Prioritize hands-on security internships, capstone projects, or junior roles that demonstrate practical exposure to cloud security, secure SDLC, and DevSecOps concepts.

AI Matched Candidates

Based on this job's requirements, AI has identified top candidates from our talent pool.

Experience AI Recruiter

$0 to start. Don't let your competitors get the AI advantage first.

Join over 10,000 companies using AI-driven recruitment solutions to automate your hiring process and save 80% in time costs.

33% off, only 48 hours left!
Try AI Free

24/7 automated operation

AI-powered candidate screening

Recruitment without geographical or time zone limitations

Personalized intelligent communication

Automated assessment of candidate engagement

Intelligently mimics and replicates your recruitment style

4-month money-back guarantee

Ensures LinkedIn account security