Security Engineer

Posted Yesterday
Be an Early Applicant
Melbourne, Victoria, AUS
In-Office
Senior level
Transportation
The Role
Lead and improve RightShip’s cybersecurity roadmap across cloud, infrastructure, applications, identity, networks, and data. Manage risk registers, vulnerability remediation, penetration testing, incident response, security automation, access governance, compliance frameworks, and resilience planning. Partner with engineering and business stakeholders to embed secure practices, translate technical risk for leadership, and implement sustainable controls. The role requires broad hands-on security expertise, independent judgment, and experience across application and infrastructure security.
Summary Generated by Built In

The Company 

RightShip is the maritime industry's leading safety and risk intelligence platform. We exist to advance the vision of a Zero Harm maritime industry by enabling better safety decisions across the ecosystem.

By combining trusted standards, AI-native technology, rich maritime data and industry expertise, RightShip transforms complex safety and operational risk into intelligence our customers can act on with confidence.

More than 1,000 organisations worldwide rely on RightShip to strengthen safety, improve resilience, simplify compliance and raise standards across global shipping. As RightShip evolves into a scalable intelligence platform, we continue to connect the global supply chain around a shared ambition: safer people, safer vessels and a safer, more sustainable industry.

To find out more visit RightShip.com. 

What we offer 

We offer a place where you know you are contributing to an organization who are constantly working to ensure ships are safe as possible so that crew and cargo are protected. We are passionate about maritime efficiency, safety and sustainability practices. 

We offer generous rewards. Our base salary is competitive, we support employee wellbeing and provide our employees with a Healthy Living Allowance and our annual incentive scheme is awesome. We have some great talent who are happy to share their experience and skills to help you on your way and we are committed to professional development to make sure your career keeps growing while you’re working with us.

 

What makes RightShip a great place to work at:

RightShip is an equal opportunity employer, and we champion diversity. Our teams are composed of individuals from different geographies, cultures, religions, ethnicities, races, genders, sexual orientations, abilities, and generations. We believe that a diversity of experiences makes us stronger—as individuals, as communities and as an organization.

Don’t meet every single requirement of this role? Still apply! Research tells us that that women and underrepresented groups are less likely to apply unless they meet every single requirement.  At RightShip we believe that the right hire is someone who makes an addition to our culture, rather than someone who fits in and conforms to our status quo. We want to add team members who not only value RightShip standards and workplace culture, but also bring an aspect of diversity that positively contributes to our work environment. If you are excited about this role, or about our company in general, we would love to hear from you!

About the role
We're looking for a Senior Cyber Security Engineer to work closely with our Head of Technology and Security to build and shape the security roadmap at RightShip.
This is a hands-on senior role with genuine scope. You'll be a trusted voice on platform, infrastructure and application security, and you'll help mature a security function that is still being built out. You'll spend your time solving real technical problems rather than administering someone else's controls, and you'll have direct access to the leaders making investment decisions.
It suits someone who enjoys depth across a broad set of security technologies, is comfortable owning outcomes end to end, and wants their work to visibly improve the organisation's security posture.

What you'll do

Security strategy and risk
•    Work alongside the Head of Technology and Security to build the security roadmap, set standards, and advise on posture and investment priorities
•    Build and maintain a formal risk register covering vulnerabilities, remediation progress and residual risk
•    Translate technical risk into clear, decision-ready advice for senior leadership
Cloud and platform security
•    Assess and improve our cloud security configuration, including network architecture, IAM policies, secrets management, audit logging and posture management tooling
•    Work with DevOps and platform engineers to harden infrastructure, and review infrastructure-as-code and CI/CD pipelines
•    Design and implement security controls across enterprise and production environments, spanning identity, endpoint, network and data protection
Vulnerability management and application security
•    Lead vulnerability assessments and drive remediation with engineering teams, including managing third-party penetration test engagements
•    Support application security across the OWASP Top 10, contributing to code review and secure SDLC guidance for development teams
•    Identify and close gaps in access control, database security and secrets handling
Detection, response and resilience
•    Lead incident detection, investigation and response across the platform, including escalation-level incidents and root cause analysis
•    Implement sustainable remediation rather than one-off fixes
•    Contribute to business continuity and recovery planning, including validating backup and restoration procedures
Automation and continuous improvement
•    Drive security automation to improve detection, response and reporting, and reduce manual effort
•    Operationalise controls end to end, with documentation that outlives any one person
Governance and collaboration
•    Support compliance with recognised frameworks and standards, and maintain investigation processes that are consistent and defensible
•    Own data access governance: who can access what, under what conditions, and with what audit trail
•    Partner with technology and business stakeholders to embed security practice into projects early, balancing risk, usability and delivery pace

About you
You're a hands-on security professional who enjoys technical problems and works well across a broad range of technologies. You have strong infrastructure and application security knowledge, and you're motivated by lifting cyber maturity in a complex environment.

You'll bring:
•    5+ years of hands-on cyber security experience, with depth in both application and infrastructure security
•    Solid cloud security knowledge covering IAM, network security, logging, secrets management and posture tooling
•    Practical experience with enterprise security tooling such as EDR, IAM, firewalls, SASE, SIEM or vulnerability management platforms
•    Proven ability to identify and remediate vulnerabilities in production environments
•    Experience with security risk management: building a risk register, prioritising remediation, and communicating risk to non-technical stakeholders
•    Exposure to cyber security frameworks such as Essential Eight, Soc2, ISO 27001 or similar
•    Clear communication skills, able to translate technical risk for leadership and turn security requirements into practical guidance for engineers
•    Sound judgement and the ability to work independently across competing priorities
Highly regarded
•    Penetration testing capability across web applications, APIs, network and cloud
•    Experience with security automation and workflow platforms
•    Privileged Access Management (PAM) experience, including access reviews and privileged access controls
•    Familiarity with database security across relational and NoSQL systems
•    Understanding of Australian privacy obligations and, where relevant, UK/EU data protection requirements including GDPR
•    Experience mentoring junior security staff
•    Prior experience in SaaS, maritime, logistics or other data-intensive environments

Qualifications
Preferred
•    Industry-recognised certifications such as OSCP, CISSP, CISM, CRISC, GIAC or cloud security certifications
•    Tertiary qualification in Cyber Security, Information Technology, Computer Science or a related discipline, or equivalent practical experience
We recognise expertise is gained in different ways. If you meet most, but not all, of the above, we'd still like to hear from you.

RightShip is an Equal Opportunity Employer and values diversity, enables access and promotes inclusion in our workplace. You must have the right to live and work in this location to apply for this job.

Skills Required

  • 5+ years of hands-on cybersecurity experience
  • Experience in both application and infrastructure security
  • Cloud security knowledge covering IAM, network security, logging, secrets management, and posture tooling
  • Practical experience with enterprise security tools such as EDR, IAM, firewalls, SASE, SIEM, or vulnerability management platforms
  • Experience identifying and remediating vulnerabilities in production environments
  • Security risk management experience, including risk registers, remediation prioritization, and communicating risk to nontechnical stakeholders
  • Exposure to cybersecurity frameworks such as Essential Eight, SOC 2, or ISO 27001
  • Clear communication skills for translating technical risk and security requirements
  • Ability to work independently across competing priorities
  • Penetration testing across web applications, APIs, networks, or cloud
  • Security automation and workflow platform experience
  • Privileged Access Management experience, including access reviews and privileged access controls
  • Database security experience across relational and NoSQL systems
  • Understanding of Australian privacy obligations and UK/EU data protection requirements, including GDPR
  • Experience mentoring junior security staff
  • Experience in SaaS, maritime, logistics, or other data-intensive environments
  • Industry-recognized certification such as OSCP, CISSP, CISM, CRISC, GIAC, or a cloud security certification
  • Tertiary qualification in Cybersecurity, Information Technology, Computer Science, or a related discipline, or equivalent practical experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Melbourne
103 Employees
Year Founded: 2001

What We Do

RightShip is the world's leading ESG-focused digital maritime platform, providing expertise in global safety, sustainability, and social responsibility practices to drive operational improvements in the maritime industry.

Similar Jobs

Xero Logo Xero

Security Engineer

Cloud • Fintech • Information Technology • Machine Learning • Software
Hybrid
Melbourne, Victoria, AUS
4500 Employees

DXC Technology Logo DXC Technology

Security Engineer

Information Technology
In-Office
Melbourne, Victoria, AUS
86261 Employees

DXC Technology Logo DXC Technology

Security Engineer

Information Technology
In-Office
5 Locations
86261 Employees
In-Office
Redbank, Victoria, AUS
3705 Employees

Similar Companies Hiring

Blissway Thumbnail
Computer Vision • Fintech • Hardware • Internet of Things • Machine Learning • Software • Transportation
Denver, CO
24 Employees
Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account