Implements and operates enterprise security controls across identity, endpoints, cloud, SaaS, networks, and data. Automates security workflows using scripts, APIs, infrastructure as code, and CI/CD checks. Maintains IAM, endpoint protection, DLP, device posture, and secure configuration baselines. Supports vendor risk reviews, insider-risk monitoring, physical access integrations, incident troubleshooting, on-call operations, documentation, and remediation of security gaps across corporate technology environments.
The Enterprise Security Engineer is a hands-on engineer who implements, operates, and improves security controls across corporate architecture, SaaS platforms, cloud services, endpoints, identity, data, and workforce technologies. This role translates enterprise security strategy into practical, measurable controls and secure-by-default solutions that reduce risk without slowing the business.
The engineer partners with Enterprise IT, Corporate Engineering, SRE and Platform teams, Business Systems, Product Security, Legal, Privacy, and other stakeholders to deliver scalable security improvements across Atlassian's corporate environment. As part of Atlassian's "Customer Zero" initiative, the engineer helps validate and improve security capabilities internally before broader adoption.
Enterprise Security Engineering
Identity, Access & Human Risk
Cloud, SaaS & Endpoint Protection
Automation & Operational Excellence
SaaS Supply Chain & Third-Party Risk
How You'll Measure Success (first 6-12 months)
Key Skills and Experience
The engineer partners with Enterprise IT, Corporate Engineering, SRE and Platform teams, Business Systems, Product Security, Legal, Privacy, and other stakeholders to deliver scalable security improvements across Atlassian's corporate environment. As part of Atlassian's "Customer Zero" initiative, the engineer helps validate and improve security capabilities internally before broader adoption.
Enterprise Security Engineering
- Design, implement, operate, and maintain security controls across identity, endpoints, network, cloud (AWS/GCP), SaaS, and data-protection domains.
- Remediate identified gaps in access controls, device posture, SaaS configurations, and sensitive data protections.
- Assist with the rollout and adoption of secure baseline configurations and paved-path implementations across internal teams.
- Participate in security reviews for new tools, internal workflows, and SaaS integrations under the guidance of senior engineers.
- Support cyber-related physical security operations, including maintaining integrations between physical access-control systems and identity platforms, monitoring access lifecycles, and addressing facility-related cyber risks.
Identity, Access & Human Risk
- Strengthen identity lifecycle management, privileged access, authentication, authorisation, and access reviews.
- Help validate agentic identity, AI-native governance, data-protection, and access controls internally before broader release.
- Monitor insider risk signals, anomalous access patterns, and policy violations to support triage and response.
- Support the secure implementation of service accounts and automated bot credentials.
Cloud, SaaS & Endpoint Protection
- Implement and monitor security guardrails and posture baselines across cloud environments (AWS/GCP) and SaaS suites (Google Workspace, Slack, Okta).
- Maintain endpoint security agents, device compliance policies, and configuration baselines across macOS and Windows fleets.
- Help implement and tune Data Loss Prevention (DLP) and data-classification controls to safeguard internal and customer information.
Automation & Operational Excellence
- Build scripts, API integrations, and automations (e.g., Python, Bash, Go) to eliminate repetitive tasks and streamline security operations.
- Maintain infrastructure-as-code and CI/CD security checks for enterprise tooling.
- Track operational metrics, monitor control health, and contribute to standard operating procedures (SOPs) and runbooks.
- Participate in on-call rotations, troubleshooting, and post-incident reviews (PIRs) for security tooling outages, pipeline failures, and platform availability issues.
SaaS Supply Chain & Third-Party Risk
- Execute security evaluations and vendor risk reviews for new SaaS tooling and browser extensions against defined security criteria.
- Track remediation of identified vendor vulnerabilities and configuration risks.
How You'll Measure Success (first 6-12 months)
- Execution and Delivery: Successfully deliver scoped technical tasks, control deployments, and automation milestones on time with high code and configuration quality.
- Operational Excellence: Triage and resolve security escalations, access tickets, and alert queues within established SLOs, actively reducing backlog and manual toil.
- Automation and Tooling: Write reliable scripts and workflow automations that reduce manual operational effort and improve control reliability.
- Security Hygiene & Remediation: Close identified posture gaps across SaaS, endpoints, or IAM systems, demonstrating measurable improvements in baseline compliance.
- Collaboration & Learning: Partner effectively with senior engineers and cross-functional teams, actively expanding your technical depth across enterprise security domains.
Key Skills and Experience
- 3-5+ years of experience in cybersecurity, security engineering, cloud security, systems engineering, or enterprise technology.
- Experience implementing, operating, and maintaining security controls across identity, endpoint, SaaS, cloud, network, and data protection domains.
- Hands-on experience with IAM, directory services, SSO/MFA, and access governance (e.g., Okta, Google Workspace, Azure AD / Entra ID).
- Practical experience securing cloud environments (AWS or GCP) and enterprise SaaS collaboration suites (e.g., Google Workspace, Slack).
- Experience automating security tasks and operational workflows using scripting (e.g., Python, Bash, Go), REST APIs, and CI/CD pipelines.
- Working knowledge of endpoint security architectures, device posture management (MDM), and data protection / DLP controls across macOS and Windows.
- Understanding of SaaS vendor risk assessments, third-party integration risks, and secure baseline standards.
- Foundational awareness of cyber-related physical access-control systems and their integration with enterprise identity lifecycles.
- Strong troubleshooting and communication skills, with the ability to write clear runbooks and technical documentation, and collaborate effectively across engineering and operations teams.
Atlassian Australia Office
Atlassian Australia Office
Similar Jobs at Atlassian
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Implements, operates, and improves enterprise security controls across identity, endpoints, cloud, SaaS, networks, and data. Builds automation using scripts, APIs, infrastructure-as-code, and CI/CD security checks. Supports IAM, endpoint protection, DLP, vendor risk assessments, physical access integrations, incident troubleshooting, and security operations. Partners with engineering, IT, legal, privacy, and business teams to deploy secure baselines, remediate risks, monitor control health, and improve enterprise security capabilities.
Top Skills:
AWSAzure AdBashCi/CdDlpEntra IdGCPGoGoogle WorkspaceIammacOSMdmMfaOktaPythonRest ApisSaaSSlackSsoWindows
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Implements, operates, and improves enterprise security controls across identity, endpoints, cloud, SaaS, networks, and data. Builds automation using scripts, APIs, infrastructure-as-code, and CI/CD security checks. Supports IAM, endpoint protection, DLP, vendor risk assessments, physical access integrations, incident troubleshooting, and security operations. Partners with engineering, IT, legal, privacy, and business teams to deploy secure baselines, remediate risks, monitor control health, and improve enterprise security capabilities.
Top Skills:
AWSAzure AdBashCi/CdDlpEntra IdGCPGoGoogle WorkspaceIammacOSMdmMfaOktaPythonRest ApisSaaSSlackSsoWindows
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Lead regional security incident response for high-severity enterprise incidents, directing investigations, communications, coordination, and remediation. Build incident response tools, systems, playbooks, and programs; conduct exercises and post-incident reviews; mentor team members; collaborate across security teams; engage law enforcement and industry bodies; and produce threat intelligence. The role requires expertise across multiple security domains, cloud and network technologies, scripting, and incident response leadership.
Top Skills:
FirewallsGCPGoIntrusion Detection Systems (Ids)Network ProtocolsPython
What you need to know about the Sydney Tech Scene
From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.

