What you'll be doing
- Security Monitoring & Incident Response
- Optimise and fine-tune SIEM rules, policies, and thresholds in collaboration with the MSSP.
- Lead incident response efforts, including containment, mitigation, and resolution.
- Conduct post-incident analysis, forensic investigations.
- Security automation (SOAR) implementation.
- Monitor and investigate security alerts from EDR, DLP, and email security tools.
- SaaS & Identity Security
- Oversee security configurations for SaaS applications (Google Workspace, Slack, Okta, etc.).
- Manage authentication policies and access controls within SaaS tools and IAM.
- Conduct security audits and ensure SaaS tools align with compliance requirements.
- Endpoint, Network, and Email Security
- Manage and secure endpoint protection (EDR), antivirus, firewalls, and VPN security.
- Enforce network security best practices and assist in vulnerability management efforts.
- Oversee email security configuration, phishing prevention, and spam filtering.
- Compliance & Risk Management
- Perform security audits and risk assessments for systems, vendors, and applications.
- Collaborate with leadership to develop and implement risk mitigation strategies, ensure PCI and SOX compliance, and maintain GDPR regulatory compliance through proactive security control monitoring.
- Vendor Collaboration & Continuous Improvement
- Participate in security vendor meetings (MSSP, Crowdstrike, and others) to enhance security posture.
- Stay up-to-date on industry trends, security threats, and best practices.
- Be aware and accountable to your responsibilities in relation to workplace health and safety obligations.
About you
- 5+ years of experience in IT security or cybersecurity engineering.
- Proficiency with SIEM tools (Sumo Logic) and SOC operations.
- Hands-on experience with EDR, DLP, firewalls, VPNs, IAM, and security automation.
- Ideally experience in fast growing digital companies, requiring agile planning to manage fast growing operations.
- Familiarity with a variety of information security standards and frameworks, (e.g PCI/DSS, NIST Cybersecurity Framework, ISO27001).
- Familiarity with current and evolving international privacy obligations (e.g. Australian Privacy Principles, European Privacy principles: DPD, GDPR, EU-US-Shield..etc)
- Experience securing SaaS tools and applications.
- Scripting and automation skills (Ruby, Python) preferred.
- Relevant industry certifications (CISSP, CISM, CEH, GCIH, or equivalent) preferred
Similar Jobs
What We Do
Hi there! We're so happy you found us. Founded in a Sydney garage in 2006, Envato was born from a desire to make a positive impact. Now, 15 years later, we remain independently owned and committed to creating opportunities for our creatives to thrive. As a proud B Corp, we focus on a long-term vision, balancing purpose and profit for sustainable growth. We’re one of the world’s leading online creative communities for creative assets and tools. We provide genuine opportunities for creators worldwide to create, earn and grow. In the process, we're striving to make creative success accessible and achievable for all, both independently and as part of a global community. There are many ways to work, and flexibility is key. A remote-first culture is in our DNA, and wherever our people are in the world, we pledge to provide a unique and caring work environment. We have offices in Melbourne, Guadalajara, and Los Angeles, with over 600 people worldwide. From engineers and product owners to designers and marketers, our global and diverse teams are packed with talented and creative individuals who are fiercely passionate about working in a values-driven business. Envato is about more than just the bottom line. It’s work made with heart.







