Security Engineering Manager - Vulnerability Management, Application Security

16 Hours ago • 6-8 Years • Cyber Security

Job Summary

Job Description

As a Security Engineering Manager for Vulnerability Management at Canva, you will lead a team responsible for identifying, assessing, and automating the resolution of security vulnerabilities across Canva's global ecosystem. Key responsibilities include delivering application security solutions for a large-scale, cloud-native SaaS application stack, fostering a security-first engineering culture, driving technical decision-making, and supporting engineer growth and development. You'll collaborate across teams, manage large projects, and work with vendors. The role requires experience leading engineering or security teams, a strong technical background, expertise in vulnerability management, and excellent communication skills. Canva's approach prioritizes building secure solutions while maintaining speed and scale of delivery.
Must have:
  • Lead engineering/security teams
  • Technical hands-on leadership
  • Cloud experience (AWS, GCP, Azure)
  • Vulnerability management expertise
  • Strong communication skills
Good to have:
  • AWS subject matter expertise
  • Experience scaling security solutions via automation
  • Experience with vulnerability management at scale
Perks:
  • Equity packages
  • Inclusive parental leave
  • Vibe & Thrive allowance
  • Flexible leave options

Job Details

Job Description

Join the team redefining how the world experiences design.

Hey, g'day, mabuhay, kia ora, 你好, hallo, vítejte!

Thanks for stopping by. We know job hunting can be a little time consuming and you're probably keen to find out what's on offer, so we'll get straight to the point.

Where and how you can work

Our flagship campus is in Sydney. We also have a campus in Melbourne and co-working spaces in Brisbane, Perth and Adelaide. But you have choice in where and how you work, we trust our Canvanauts to choose the balance that empowers them and their team to achieve their goals.

What you’d be doing in this role

As Canva scales change continues to be part of our DNA. But we like to think that's all part of the fun. So this will give you the flavour of the type of things you'll be working on when you start, but this will likely evolve.

At the moment, this role is focused on:

  • Own the delivery of Application Security solutions for our large-scale, cloud-native and SaaS application stack, to enable Canva to understand its vulnerability landscape, and have remediation built into our development lifecycle.
  • Support a security-first engineering culture by making the optimally secure solution the easiest one for software engineering teams to use 
  • Drive technical decision making support to your team in a fast-paced, innovation-focused environment
  • Foster a culture of communication, bridging the communication gap between teams, groups, and company leaders
  • Invest in working with engineers on growth and development opportunities to help further their skillset and grow into new roles, with an ability to deliver relevant and timely feedback (positive & constructive) to help them to continuously improve and learn
  • Be involved in hiring; build and grow high-performing and highly engaged teams of world-class engineers by attracting, interviewing, and selecting talent for your group
  • Coordinate across various specialties and parts of the business to understand the impact and feasibility of strategic goals within the group, and how that impacts your own roadmap.
  • Drive delivery of large, cross team and cross group initiatives and projects from ideation to completion.

You're probably a match if

  • You’ve led engineering or security teams and love growing people from all levels, while scaling systems.
  • You’re a technical hands on leader (with previous experience as a Software or Security engineer), who is comfortable getting into the thick of it when needed using software engineering fundamentals and security first principles to guide technical decision making
  • Previous experience in cloud-based environments (AWS, Google Cloud, Azure) with a working knowledge of broad infrastructure functions - CI/CD pipelines, automation, site reliability etc.
  • You bring deep understanding of vulnerability management practices — across infrastructure, application security, and cloud environments.
  • You’re comfortable working with ambiguity, designing programs, and influencing beyond your immediate team.
  • You can communicate clearly with technical and non-technical audiences and love turning complex problems into simple, effective solutions.
  • Experience making careful engineering tradeoffs, particularly around "Build vs Buy", evaluating potential third party systems to partner with, and managing and working with vendors to meet Canva's business needs
  • Strong customer focus to understand the use cases and requirements of internal stakeholders, and identify opportunities to empower them to do their best work

While not required, you’ll have an edge if you bring:

  • Subject-matter expertise of Amazon Web Services and associated technologies and products within the AWS ecosystem
  • Previous experience leading teams to scale security solutions through automation, continuously reducing the tax that security requirements can impose on software development and operations
  • Experience working on delivering vulnerability management at scale in a fast paced, rapid growth environment

About the role

As a Security Engineering Manager for the Vulnerability Management team, you’ll lead a team dedicated to identifying, assessing, and automating the resolution of security vulnerabilities across Canva’s global ecosystem. Your mission is to empower engineers with the tools and context they need to make secure decisions by default—making the secure path the easiest path. We need to be able to ship robust and secure features without sacrificing speed and scale of delivery.

Our Vulnerability Management team takes a strategic, build-versus-buy approach to deliver robust capabilities that offer visibility, early detection, and actionable insights. We're focused on reducing toil, abstracting away complexity, and driving remediation at scale—so product teams can focus on building, not fixing. You'll guide engineers as they develop and scale security solutions, navigate complex problem spaces, and balance security rigor with Canva's pace of innovation.


About the Security Group

The Security Group’s mission is to protect our community, people, and company from online threats by making the most secure actions simple. Our teams work together, and with other groups, to deliver preventive and detective controls and processes that reduce security risk. The group runs programs across Identity and Access Management, Application Security, Risk Management, and Threat Detection and Response domains.  Within this group, the Vulnerability Management team ensures we’re proactively identifying and reducing risk across Canva’s systems and codebase. We partner deeply with product teams and platform engineers — building shared tooling, defining scalable processes, and helping Canva grow securely.

What's in it for you?

Achieving our crazy big goals motivates us to work hard - and we do - but you'll experience lots of moments of magic, connectivity and fun woven throughout life at Canva, too. We also offer a range of benefits to set you up for every success in and outside of work.

Here's a taste of what's on offer:

  • Equity packages - we want our success to be yours too
  • Inclusive parental leave policy that supports all parents & carers
  • An annual Vibe & Thrive allowance to support your wellbeing, social connection, office setup & more
  • Flexible leave options that empower you to be a force for good, take time to recharge and supports you personally

Check out lifeatcanva.com for more info.

Other stuff to know

We make hiring decisions based on your experience, skills and passion, as well as how you can enhance Canva and our culture. When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.

We celebrate all types of skills and backgrounds at Canva so even if you don’t feel like your skills quite match what’s listed above - we still want to hear from you!

Please note that interviews are conducted virtually.

Similar Jobs

Canva - China App Store Marketing Partnerships Specialist

Canva

Beijing, Beijing, China (Remote)
3 Weeks ago
Canva - Revenue Accounting Manager, Online Sales

Canva

Los Angeles, California, United States (Remote)
1 Month ago
Canva - Staff Data Scientist – Marketing

Canva

Sydney, New South Wales, Australia (Remote)
1 Month ago
Canva - Public Sector Business Development Representative (French or German Speaking)

Canva

London, England, United Kingdom (Remote)
1 Month ago
Canva - Security Engineering Manager - Vulnerability Management, Application Security

Canva

Surry Hills, New South Wales, Australia (Remote)
1 Week ago
PwC - Senior Consultant - RDC TC MSOFT

PwC

Kolkata, West Bengal, India (On-Site)
6 Months ago
PwC - Senior Associate_ETL Data Engineers_Advisory_  MSOFT_Kolkata

PwC

Kolkata, West Bengal, India (On-Site)
5 Months ago
ION - Markets Product Security Engineer - UK

ION

London, England, United Kingdom (On-Site)
6 Months ago
Barracuda Networks  Inc  - Principal Application Security Engineer

Barracuda Networks Inc

United States (Remote)
3 Weeks ago
ByteDance - Tech Lead Manager, Network Security

ByteDance

San Jose, California, United States (On-Site)
1 Day ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Canva - Lead Data Scientist - ANZ Remote

Canva

Melbourne, Victoria, Australia (Remote)
1 Week ago
Canva - Machine Learning Engineering Manager (m/f/x) - Canva Austria

Canva

Vienna, Vienna, Austria (Remote)
5 Months ago
Pragma - Marketing Manager

Pragma

United States (Remote)
3 Weeks ago
Canva - Software Engineer Internship (Infrastructure)

Canva

Sydney, New South Wales, Australia (Remote)
1 Week ago
Lakshya Digital - Senior Trainer - Learning & Development

Lakshya Digital

Gurugram, Haryana, India (On-Site)
3 Weeks ago
Canva - Senior Data Scientist - International Marketing

Canva

Surry Hills, New South Wales, Australia (Remote)
3 Weeks ago
Canva - Machine Learning Engineer Lead - User Voice

Canva

Melbourne, Victoria, Australia (Remote)
6 Days ago
Canva - Senior Backend Software Engineer - Security Platform Engineering

Canva

Auckland, Auckland, New Zealand (Remote)
3 Weeks ago
Canva - Senior Applied Scientist - AI Research

Canva

Surry Hills, New South Wales, Australia (Remote)
1 Month ago
Canva - Senior Engineering Manager (BE) - Visual Suite Platform - Remote across ANZ

Canva

Auckland, Auckland, New Zealand (Remote)
4 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Surry Hills, New South Wales, Australia

Ziff Davis - Backend Software Engineer II

Ziff Davis

Malaga, Western Australia, Australia (Remote)
3 Months ago
Canva - Software Engineer Internship (Infrastructure)

Canva

Sydney, New South Wales, Australia (Remote)
1 Week ago
Trek - Store Manager

Trek

Wollongong, New South Wales, Australia (On-Site)
2 Months ago
Flying Bark Productions - Senior 3D Modeller

Flying Bark Productions

New South Wales, Australia (Hybrid)
1 Month ago
Easygo - Sportsbook Manager

Easygo

Melbourne, Victoria, Australia (On-Site)
4 Weeks ago
Canva - Staff Machine Learning Engineer - User Voice

Canva

Melbourne, Victoria, Australia (Remote)
6 Days ago
Canva - Senior Machine Learning Engineer - Specialist Platform and Experience

Canva

Melbourne, Victoria, Australia (Remote)
3 Weeks ago
Canva - Staff Frontend Engineer - Apps API Platform

Canva

Sydney, New South Wales, Australia (Remote)
1 Month ago
Canva - AI Product Localization Specialist

Canva

Sydney, New South Wales, Australia (Remote)
2 Weeks ago
Immutable - Head of Growth - Performance

Immutable

Sydney, New South Wales, Australia (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Tencent - Security Operations - PUBG Mobile

Tencent

Shenzhen, Guangdong Province, China (On-Site)
2 Months ago
ByteDance - AI Security Researcher - Security Flow

ByteDance

San Jose, California, United States (On-Site)
5 Months ago
ByteDance - Senior Software Engineer - Network Security

ByteDance

San Jose, California, United States (On-Site)
1 Day ago
The Walt Disney Company - Security Specialist, Compliance

The Walt Disney Company

Burbank, California, United States (On-Site)
1 Day ago
PwC - IN-Senior Manager – ERP - Sales-Ms Dynamics– Advisory  - Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
6 Months ago
PwC - Workday specialist in benefits & compensations

PwC

Buenos Aires, Buenos Aires, Argentina (On-Site)
6 Months ago
ION - Senior Security Architect

ION

Collecchio, Emilia-Romagna, Italy (On-Site)
6 Months ago
ION - Intermediate IT Auditor, Italy

ION

Collecchio, Emilia-Romagna, Italy (On-Site)
6 Months ago
PwC - Workday - Senior Consultant-  Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
6 Months ago
PwC - Financial Sector Cyber Security Strategy Manager

PwC

Amsterdam, North Holland, Netherlands (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Wellington, Wellington, New Zealand (Remote)

Sydney, New South Wales, Australia (Remote)

Sydney, New South Wales, Australia (Remote)

Melbourne, Victoria, Australia (Remote)

Surry Hills, New South Wales, Australia (Remote)

Surry Hills, New South Wales, Australia (Remote)

Sydney, New South Wales, Australia (Remote)

Mexico City, Mexico City, Mexico (Remote)

Los Angeles, California, United States (Remote)

View All Jobs

Get notified when new jobs are added by Canva

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug