资深企业安全工程师
Staff Enterprise Security Engineer
#### 公司简介
#### 职位描述
**高级企业安全工程师**
加入我们,重新定义世界体验设计的方式。
嘿,你好,欢迎!我们了解找工作可能很耗时,你可能希望快速了解有哪些机会,所以我们直入主题。
**关于团队**
安全团队保护Canva的系统和数据免受信息安全威胁,涵盖应用安全、风险管理、企业安全以及威胁检测与响应。内部系统安全是该团队中专注于Canva自身环境的部分。
**你将在此职位中做些什么**
内部系统安全团队保障Canvanauts日常工作的环境。包括笔记本电脑、网络、身份验证、每个人依赖的SaaS工具,以及现在与我们并肩工作的AI代理。
大多数工作过去都遵循既定的流程。但现在情况不同了。Canvanauts现在运行着代表他们行动的AI代理,这与一个人在笔记本电脑前的安全问题完全不同。我们目前面临的一个问题:当希望根据每个操作而非每个应用程序做出决策,并且评估速度足够快以至于没人注意到时,MCP工具调用的策略层应放在哪里?
这是一个高级别的个人贡献者职位。你不需要管理任何人,但会设定技术方向。
**目前这意味着:**
- 前往公司各处的团队,找出他们真正的风险点,并与他们共同制定路线图,而不是直接交给他们。
- 帮助这些团队安全地启用AI工作流,而不是成为他们无法启用的原因。
- 在新工具和代理上线前进行审查。我们是那个说“是”、“否”或“是,但需要这些设置”的团队。
- 对MCP、代理工作流和SaaS到SaaS集成等新模式进行威胁建模,然后将发现转化为人们愿意采用的控制措施。
- 设定其他团队可以依据的标准,并自动化工作,这样工作量增加时也不需要更大的团队。
**如果你符合以下条件,可能会是一个合适的人选:**
- 你主动寻找问题。你能指出你自己发现的问题,让其他人关注,并推动解决。
- 你能带动他人。你曾说服IT或工程负责人接受他们路线图之外的事情,而无需正式授权。
- 你有实际的企业、公司或内部安全工程经验,并构建和运行过安全系统。
查看英文原文
#### Company Description
#### Job Description
**Staff Enterprise Security Engineer**
Join the team redefining how the world experiences design.
Hey, gday, mabuhay, kia ora, 你好, hallo, vítejte!
Thanks for stopping by. We know job hunting can be a little time-consuming, and you're probably keen to find out what's on offer, so we'll get straight to the point.
**About the team**
The Security Group protects Canva's systems and data from information security threats, across Application Security, Risk Management, Enterprise Security, and Threat Detection and Response. Internal Systems Security is the team inside that focused on Canva's own environment.
**What you'd be doing in this role**
The Internal Systems Security team secures the environment Canvanauts work in every day. Laptops, networks, identities, the SaaS tools everyone relies on, and now the AI agents doing real work alongside us.
Most of this work used to follow a playbook. That's no longer true. Canvanauts now run AI agents that act on their behalf, which is a very different security problem to a person at a laptop. One of the questions on our plate right now: where does the policy layer sit for MCP tool calls, when we want decisions made per action rather than per application, and evaluated fast enough that nobody notices them?
This is a Staff level individual contributor role. You'd set technical direction without managing anyone.
**At the moment, that means:**
- Going out to teams across the business, working out where their real risks sit, and building the roadmap with them rather than handing them one.
- Helping those teams turn on AI workflows safely, instead of being the reason they can't.
- Reviewing new tools and agents before they land. We're the team that says yes, no, or yes with these settings.
- Threat modelling newer patterns like MCP, agentic workflows and SaaS to SaaS integrations, then turning what you find into controls people adopt.
- Setting the standards other teams build against, and automating the work so a multiplying workload doesn't need a bigger team.
**You're probably a match if:**
- You go looking for problems. You can point to something you found yourself, got other people to care about, and saw through to a fix.
- You can bring people with you. You've convinced an IT or engineering lead to take on something that wasn't on their roadmap, without a mandate.
- You've done hands-on enterprise, corporate or internal security engineering, and built and run security services in production. Endpoints, networks, identity, SaaS estates.
- You value concepts over tools. Knowing the tooling matters. Knowing why a control works matters more.
- You write and review code to a standard other engineers trust, and you automate by default.
**Nice to have**
- Security work across a broad enterprise, especially somewhere less obvious like marketing or sales.
- macOS at fleet scale: device trust, posture signals, zero trust, certificate-based device attestation.
- SaaS security posture: configuration baselines, SSPM, OAuth and third party integration risk, non-human identities.
- Securing AI agents, MCP servers or agentic workflows. Action level policy, tool call mediation, audit trails and containment.
- Terraform, Python or Go, and cloud in AWS or GCP.
**Where and how you can work**
Our flagship Sydney campus is uniquely Canva, an extension of our Surry Hills neighbourhood. It's a thoughtfully designed space with plenty of room to collaborate, focus, and connect. This role is based in Sydney, and we're looking for someone who calls it home. Our hybrid way of working gives you the flexibility to work remotely, and to come together on campus for meaningful in-person collaboration and connection when it matters most. We trust our Canvanauts to choose the balance that empowers them and their team to achieve their goals.
**What's in it for you?**
Achieving our crazy big goals motivates us to work hard, and we do, but you'll experience lots of moments of magic, connectivity and fun woven throughout life at Canva too. We also offer a range of benefits to set you up for every success in and outside of work.
**Here's a taste of what's on offer:**
- Equity packages, because we want our success to be yours too
- Inclusive parental leave policy that supports all parents and carers
- An annual Vibe & Thrive allowance to support your wellbeing, social connection, office setup and more
- Flexible leave options that empower you to be a force for good, take time to recharge, and support you personally
Check out lifeatcanva.com for more info.
**Other stuff to know**
We make hiring decisions based on your experience, skills and passion, as well as how you can enhance Canva and our culture. When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.
We celebrate all types of skills and backgrounds at Canva, so even if you don't feel like your skills quite match what's listed above, we still want to hear from you.
Please note that interviews are conducted virtually.