资深安全工程师
Staff Security Engineer
资深企业安全工程师
加入我们,重新定义世界体验设计的方式。
嗨,你好,欢迎,你好,你好,您好,欢迎!
感谢您的关注。我们知道找工作可能有点耗时,您可能很想了解有哪些机会,所以我们直入主题。
关于团队
安全团队保护Canva的系统和数据免受信息安全威胁,涵盖应用安全、风险管理、企业安全以及威胁检测与响应。内部系统安全是该团队中专注于Canva自身环境的小组。
您在这个职位中的工作内容
内部系统安全团队保障Canvanaut日常工作的环境安全。包括笔记本电脑、网络、身份、每个人依赖的SaaS工具,以及现在与我们共同完成实际工作的AI代理。
过去大部分工作都遵循既定的流程。但现在情况不同了。Canvanaut现在运行AI代理代表他们执行任务,这与人在笔记本电脑前的安全问题完全不同。我们目前面临的一个问题:当希望根据每个操作而非每个应用程序做出决策,并且评估速度足够快以至于没人注意到时,MCP工具调用的策略层应放在哪里?
这是一个资深级别的个人贡献者职位。您将设定技术方向,但不管理任何人。
目前,这意味着:
· 走访公司各个团队,了解他们的真正风险所在,并与他们共同制定路线图,而不是直接交给他们一个方案。
· 帮助这些团队安全地启用AI工作流,而不是成为他们无法启用的原因。
· 在新工具和代理上线前进行审查。我们是那个决定“可以”、“不可以”或“可以但需要特定设置”的团队。
· 对MCP、代理工作流和SaaS到SaaS集成等新模式进行威胁建模,然后将发现转化为人们愿意采用的控制措施。
· 设定其他团队需要遵循的标准,并自动化工作,这样工作量增加时不需要扩大团队规模。
如果您符合以下条件,可能会是一个合适的人选:
· 您主动寻找问题。您可以指出自己发现的问题,让其他人关注,并推动解决。
· 您能带动他人。您曾说服IT或工程负责人接受原本不在他们计划中的任务,而无需正式指令。
· 您有实际的企业、公司或内部安全工程经验,并在生产环境中构建和运行过安全服务。包括终端设备、网络、身份和SaaS资产。
查看英文原文
Staff Enterprise Security Engineer
Join the team redefining how the world experiences design.
Hey, gday, mabuhay, kia ora, 你好, hallo, vítejte!
Thanks for stopping by. We know job hunting can be a little time-consuming, and you're probably keen to find out what's on offer, so we'll get straight to the point.
About the team
The Security Group protects Canva's systems and data from information security threats, across Application Security, Risk Management, Enterprise Security, and Threat Detection and Response. Internal Systems Security is the team inside that focused on Canva's own environment.
What you'd be doing in this role
The Internal Systems Security team secures the environment Canvanauts work in every day. Laptops, networks, identities, the SaaS tools everyone relies on, and now the AI agents doing real work alongside us.
Most of this work used to follow a playbook. That's no longer true. Canvanauts now run AI agents that act on their behalf, which is a very different security problem to a person at a laptop. One of the questions on our plate right now: where does the policy layer sit for MCP tool calls, when we want decisions made per action rather than per application, and evaluated fast enough that nobody notices them?
This is a Staff level individual contributor role. You'd set technical direction without managing anyone.
At the moment, that means:
· Going out to teams across the business, working out where their real risks sit, and building the roadmap with them rather than handing them one.
· Helping those teams turn on AI workflows safely, instead of being the reason they can't.
· Reviewing new tools and agents before they land. We're the team that says yes, no, or yes with these settings.
· Threat modelling newer patterns like MCP, agentic workflows and SaaS to SaaS integrations, then turning what you find into controls people adopt.
· Setting the standards other teams build against, and automating the work so a multiplying workload doesn't need a bigger team.
You're probably a match if:
· You go looking for problems. You can point to something you found yourself, got other people to care about, and saw through to a fix.
· You can bring people with you. You've convinced an IT or engineering lead to take on something that wasn't on their roadmap, without a mandate.
· You've done hands-on enterprise, corporate or internal security engineering, and built and run security services in production. Endpoints, networks, identity, SaaS estates.
· You value concepts over tools. Knowing the tooling matters. Knowing why a control works matters more.
· You write and review code to a standard other engineers trust, and you automate by default.
Nice to have
· Security work across a broad enterprise, especially somewhere less obvious like marketing or sales.
· macOS at fleet scale: device trust, posture signals, zero trust, certificate-based device attestation.
· SaaS security posture: configuration baselines, SSPM, OAuth and third party integration risk, non-human identities.
· Securing AI agents, MCP servers or agentic workflows. Action level policy, tool call mediation, audit trails and containment.
· Terraform, Python or Go, and cloud in AWS or GCP.
Where and how you can work
Our flagship Sydney campus is uniquely Canva, an extension of our Surry Hills neighbourhood. It's a thoughtfully designed space with plenty of room to collaborate, focus, and connect. This role is based in Sydney, and we're looking for someone who calls it home. Our hybrid way of working gives you the flexibility to work remotely, and to come together on campus for meaningful in-person collaboration and connection when it matters most. We trust our Canvanauts to choose the balance that empowers them and their team to achieve their goals.
What's in it for you?
Achieving our crazy big goals motivates us to work hard, and we do, but you'll experience lots of moments of magic, connectivity and fun woven throughout life at Canva too. We also offer a range of benefits to set you up for every success in and outside of work.
Here's a taste of what's on offer:
· Equity packages, because we want our success to be yours too
· Inclusive parental leave policy that supports all parents and carers
· An annual Vibe & Thrive allowance to support your wellbeing, social connection, office setup and more
· Flexible leave options that empower you to be a force for good, take time to recharge, and support you personally
Check out lifeatcanva.com for more info.
Other stuff to know
We make hiring decisions based on your experience, skills and passion, as well as how you can enhance Canva and our culture. When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.
We celebrate all types of skills and backgrounds at Canva, so even if you don't feel like your skills quite match what's listed above, we still want to hear from you.
Please note that interviews are conducted virtually.