
Staff Security Engineer
Articore runs Redbubble, TeePublic, Dashery, and Frankly Wearing - some of the largest creator marketplaces in the world, with Redbubble's catalog alone exceeding 40 billion SKUs.
The Infrastructure team stewards the foundational platform supporting our global marketplaces, driving system reliability, scalability, and performance. By delivering core infrastructure services, Infrastructure as Code (IaC) expertise, and sophisticated tooling, the team enables engineers to deploy code securely and efficiently across our hybrid architectures – predominantly built on AWS ECS and EKS (Kubernetes).
As Staff Security Engineer, you'll be the security driver within DEAP: the person accountable for making risk visible, turning gaps into actionable work, and ensuring our core security practices are implemented and sustained across every property. This is a senior individual contributor role. You'll deliver through a combination of deep hands-on work and influence — establishing standards, running key processes, coaching engineers, and partnering with Infrastructure and DevOps to get changes shipped — rather than through line management.
The remit will evolve as our security strategy solidifies. We're looking for someone who wants to help shape that strategy, not just execute a fixed checklist.
Core Responsibilities
Application & Platform Security
- Maintain a current inventory of applications, services, and data flows across Redbubble, TeePublic, FranklyWearing, and Dashery.
- Run and tune security assurance across the delivery lifecycle - SAST, DAST, dependency/SCA, container and infrastructure scanning - integrated into CI/CD, not ad hoc.
- Triage findings from automated tooling and external penetration testing (e.g. Cobalt) against defined remediation SLAs (e.g. critical ≤ 7 days, high ≤ 30) and track them to closure.
- Build security champions in delivery teams so security scales beyond one person.
Compliance, PCI & Control Operations
- Drive PCI DSS activities within DEAP's scope: CDE scope definition, SAQ/ROC completion, quarterly ASV scans, segmentation evidence, and audit liaison.
- Run the audit calendar so evidence is collected continuously, not assembled under pressure.
- Maintain a working risk register - owners, due dates, treatment decisions, review cadence — and report risk and compliance status to leadership in business terms.
- Partner with legal and privacy on GDPR/CCPA-adjacent technical controls: retention, deletion, and access.
- Support access governance: joiner/mover/leaver process, quarterly recertification of production and admin access, and least-privilege IAM.
Security Incident Response
- Own and improve the security incident process end to end: severity definitions, escalation paths, comms templates, and response coordination.
- Act as incident commander for security-led and security-relevant incidents.
- Ensure post-incident reviews are blameless, specific, and tracked to completion.
- Partner with Infrastructure and DevOps on handoffs between security response and production reliability response.
Bot, Log & Signal Stewardship
- Own bot management proactively: monitor bot load and cost impact (e.g. Cloudflare) and tune mitigation with relevant teams and vendors ahead of overages, not after them.
- Improve logging hygiene and drive toward zero-error logs — errors triaged and reduced over time, not tolerated as background noise.
Vendor & Tooling Security Stewardship
- Evaluate new technical vendors for security and operational risk - data access, SOC reports, DPAs - before purchase, not after onboarding.
- Contribute engineering judgment to renewal and rationalisation decisions alongside IT, finance, and procurement, identifying ways to get more value from existing spend.
Security Roadmap & Prioritisation
- Own a prioritised backlog of security improvements across DEAP and carry it into engineering and product planning so the work gets funded and shipped through the normal delivery cycle.
- Senior-level experience in security engineering, DevSecOps, security operations, or platform security for a production SaaS or marketplace platform.
- Hands-on experience running or tuning SAST/DAST/SCA, container, and infrastructure scanning integrated into CI/CD, plus triaging penetration test findings against SLAs.
- Experience running security incident response as incident commander, including blameless postmortems with tracked follow-through.
- Working knowledge of PCI DSS (or an equivalent control regime) and practical audit and evidence requirements — risk registers, access recertification, and reporting risk to leadership in plain business language.
- Comfort operating in a cloud-native environment, ideally AWS.
- A track record of driving outcomes as a senior IC through influence rather than formal authority — proposing action, building buy-in, and coaching engineers who don't report to you.
- Vendor security review and IT financial stewardship experience — SOC reports, DPAs, FinOps, renewal and contract management.
- Experience with bot management and traffic mitigation at scale (e.g. Cloudflare).
- Experience using AI tooling in your day-to-day workflow, and curiosity about applying it more deeply
Key attributes of success
- Track record of driving outcomes as a senior IC through influence rather than formal authority — proposing action, building buy-in, and coaching engineers without being their manager
- Comfortable with a remit that evolves as the security strategy solidifies — helping shape strategy, not just executing a fixed checklist
- Demonstrated effectiveness operating in a global company, with the communication, discipline, and async judgment required to keep work moving across time zones
- Able to translate technical complexity for non-technical stakeholders and align decision-makers around clear outcomes, including timelines, scope, and risks
- Comfortable balancing system health against delivery pressure, and prioritising your own time across parallel, often-ambiguous efforts
- Inclusive collaborator who engages stakeholders across disciplines, backgrounds, and seniority — and leads teams confidently through change
Work Environment:
- Hybrid work model, with one-two days on-site presence required.
- Collaboration across time zones to support global teams.
What We Offer
- High Trust Culture: Thrive in an environment built on mutual respect where your voice matters.
- Flexible Work Arrangements: The opportunity to balance your work and personal life with flexible schedules.
- Global Opportunities: Be part of a global organisation that offers diverse and enriching experiences.
- Monthly Wellness Allowance: Take care of yourself with a monthly wellness allowance to spend on your health and well-being.
- Exclusive Vouchers and Discounts: Benefit from deals and discounts on our online marketplaces.
Similar roles
Chief Technology Officer-Digital workplace experience servicedesk,enduser,field
Tap Growth ai·Singapore, Singapore
We're Hiring: Chief Technology Officer - Digital Workplace Experience! We are in search of an innovative and strategic Chief Technology Officer (CTO) to lead our digital workplace experience, focusing on servicedesk, end-user support, and field operations. The ideal candidate will possess extensive expertise in technology leadership, driving digital transformation, and enhancing user experiences across the organization. Location: Singapore, Singapore ⏰…
- Full-time
- Tech.Pass — self-sponsored, 2-yr
Database Administrator
Castle Trust Bank·Basingstoke, United Kingdom
Database Administrator “Build Resilient Data Services. Keep the Bank Running.” At Castle Trust Bank, we pride ourselves in being a fintech challenger bank, providing specialist property mortgages, retail finance lending and savings accounts to a variety of customers. We are looking for an experienced Database Administrator to support the reliability, security and performance of our database estate. Working closely with…
- Hybrid
- Full-time
Business Development Manager
Commify·Melbourne, Australia
At Commify, we're not just a company - we're a globally connected team of innovators who love what we do. As a CPaaS leader with 25 years of groundbreaking experience, we're the force behind over 5 billion customer interactions each year, enabling businesses worldwide to connect via advanced channels like SMS, RCS, and complex mobile journeys. Our culture is our…
- Hybrid
- Full-time
- Skilled Independent 189 — PR, no sponsor
Junior IT Support Manager (m/w/d)
Kienzle Automotive GmbH·Mülheim, Germany
Du hast Spaß daran, technische Probleme zu lösen, Anwender zu unterstützen und dafür zu sorgen, dass unsere IT im Arbeitsalltag zuverlässig funktioniert? Dann werde Teil unseres Teams! Seit 80 Jahren ist die Kienzle Automotive GmbH ein starker Partner der Transportwirtschaft. Von bewährten Fahrtschreibern bis zu smarten Telematiklösungen entwickeln wir Technologien, die Fahrzeugflotten effizienter, digitaler und nachhaltiger machen. Für unseren Standort…
- On-site
- Full-time
- Blue Card — tied; settle 21–33mo
Assistant Store Manager / Store Supervisor (Melbourne)
APM Monaco·Melbourne, Australia
Who are we? Founded in 1982, APM, Ariane Prette Monaco, is a contemporary fashion jewelry brand that associates itself with the chicness of Monaco and South of France lifestyle. We are looking for a passionate and dedicated individual to join our Melbourne boutique team. Your mission will be to develop and optimize the boutique's performance and profitability, while ensuring your…
- Full-time
- Skilled Independent 189 — PR, no sponsor
Manager - Tax Advisory
BlueRock·Melbourne, Australia
A smart human once said, “Do things you 💙 with people you care about and good things happen”, and at BlueRock, we are a growing team who love what we do. We’re B-Corp certified and a Great Place to Work - we take the responsibility of having fun seriously. 🥳 We strive to have a positive impact on the world.…
- Full-time
- Skilled Independent 189 — PR, no sponsor
Senior Planning Associate
Lyka·Alexandria, Australia
Who are we? Lyka is an Australian founded pet wellness company that's shaking up an outdated industry and paving the way for happier, healthier pets. Despite medical advancements, animal lifespans are on the decline. Today, the average pet only reaches 37% of their full potential lifespan and statistics have shown us that many suffer from dental disease, cancer, and obesity.…
- Hybrid
- Full-time
- Skilled Independent 189 — PR, no sponsor
Talent Acquisition Partner (Contract)
CreditorWatch·Sydney, Australia
⭐️ ⭐️ This is a 3-4 Month fixed-term contract, looking for an immediate start ⭐️ ⭐️ WHO ARE WE? So you might ask, who’s CreditorWatch? We are a leading Australian data and technology company that provides businesses with access to unique data and innovative products. By using our platform, our customers can confidently manage their commercial relationships, improve productivity and…
- Hybrid
- Full-time
- Skilled Independent 189 — PR, no sponsor