Staff Product Security Engineer
Security Engineer · Staff · Full Time
Opens Airwallex's application page
Role
What you'll do.
Staff Product Security Engineer at Airwallex, a leading global payments and financial platform serving 250,000+ businesses worldwide. This senior role involves designing and implementing comprehensive security controls, managing incident response workflows, conducting threat investigations, and embedding security practices across infrastructure and applications. Requires 8+ years of security engineering or incident response experience with deep cloud platform expertise and strong understanding of attacker methodologies in a high-growth fintech environment.
Responsibilities
- Design and Implementation of Security Controls: Create and build scalable security controls that protect Airwallex's infrastructure, applications, and services as the platform grows. Design security improvements across the entire application stack, infrastructure, and software delivery pipeline to prevent unauthorized access, data exfiltration, and service disruption in a high-transaction fintech environment.
- Incident Response and Threat Investigation: Develop and operationalize detection strategies, response workflows, and incident investigation procedures that improve the speed and effectiveness of threat response. Investigate, contain, and remediate cybersecurity incidents with depth and precision, leveraging forensic analysis and threat intelligence to reduce organizational risk and strengthen defensive capabilities.
- Telemetry Analysis and Threat Detection: Leverage and analyze endpoint, network, and cloud telemetry from multiple data sources to identify, investigate, and mitigate threats. Conduct threat hunting activities and tactical forensics to proactively discover indicators of compromise, understand attacker tactics, and strengthen the security posture across cloud and on-premise environments.
- Cybersecurity Infrastructure Development: Design, implement, and maintain robust cybersecurity infrastructure including SIEM systems, endpoint detection and response (EDR), network monitoring, and security orchestration tools. Build and enhance secure systems through strong integration, testing, operations, and maintenance practices that improve resilience and reduce mean-time-to-detection (MTTD) and mean-time-to-response (MTTR).
- Security Assessment and Vulnerability Management: Assess and improve system and network security posture by identifying vulnerabilities, misconfigurations, and remediation opportunities across cloud platforms and on-premise infrastructure. Conduct security reviews of new applications and services, and drive continuous improvement through automated scanning, code analysis, and configuration hardening.
- Security Culture and Cross-functional Collaboration: Partner with product engineering, infrastructure, and DevOps teams across Airwallex to embed security into the software development lifecycle, CI/CD pipelines, and infrastructure-as-code practices. Provide technical security guidance, conduct secure architecture reviews, and drive continuous improvement in security practices without creating unnecessary friction in development velocity.
- Threat Intelligence and Forensic Analysis: Collect, analyze, and operationalize threat intelligence and forensic evidence to better understand, track, and disrupt threats targeting financial services platforms. Maintain awareness of emerging threats, attacker methodologies, and exploit techniques relevant to fintech and payments infrastructure, and communicate findings to stakeholders at all technical levels.
- Compliance and Security Standards: Support security audits, compliance frameworks (PCI-DSS, SOC 2, regulatory requirements), and the development of security standards that align with industry best practices. Document security controls, maintain runbooks for incident response, and help demonstrate compliance with financial industry regulations and data protection requirements.
Qualifications
What we look for.
Technical
Cloud Platform Security
In-depth expertise with at least one major cloud platform (AWS, GCP, or Azure), including IAM policies, network security, cloud-native security tools, and shared responsibility model implementation. Experience hardening cloud infrastructure, managing cloud security posture, and responding to cloud-specific attack vectors.
Software Development and CI/CD Security
Strong knowledge of software development tools, infrastructure, and CI/CD pipelines. Understanding of secure software development practices, container security, Kubernetes orchestration, secrets management, artifact repositories, and securing the entire software delivery pipeline from code commit to production deployment.
Incident Response and Forensics
Demonstrated ability to investigate cybersecurity incidents with high depth and quality of analysis. Expertise in incident response procedures, threat hunting, digital forensics, log analysis, timeline reconstruction, and evidence collection from endpoints, networks, and cloud environments.
Attacker Tools and Techniques Knowledge
Comprehensive understanding of common attacker tools, techniques, and procedures (TTPs), including post-exploitation activities, lateral movement, privilege escalation, and data exfiltration. Ability to detect, prevent, and respond to advanced persistent threats (APTs) and insider threat scenarios in production environments.
Security Monitoring and SIEM
Expertise with security information and event management (SIEM) platforms, particularly Splunk. Proficiency in writing detection rules, creating correlation searches, understanding log sources, and building dashboards and alerts for security monitoring and incident detection.
Programming and Scripting
Experience with Python, Java, or Kotlin for security automation, custom tooling, and security analysis scripts. Ability to write parsers, analysis tools, and integrations to enhance security operations and automate repetitive security tasks.
Identity and Access Management
Experience with cloud-based identity and access management solutions such as Okta, GSuite, and security protocols. Understanding of authentication mechanisms, single sign-on (SSO), multi-factor authentication (MFA), and access control policies in enterprise environments.
Network Security and VPN
Knowledge of network security architecture, cloud-native and traditional VPN services, network segmentation, firewall rules, and monitoring network traffic for anomalies and indicators of compromise in both cloud and on-premise environments.
Education
Bachelor's Degree in Cybersecurity or Computer Science
Bachelor's degree in Cybersecurity, Computer Science, Information Security, or a related technical field. This provides foundational knowledge in security principles, cryptography, network fundamentals, and software engineering concepts required for the role.
Security Certifications
Recognized cybersecurity certifications such as Offensive Security Certified Professional (OSCP), GIAC certifications (GCIH, GCIA, GSEC, GWAPT), or Certified Ethical Hacker (CEH). These demonstrate commitment to security knowledge and hands-on capability in security practices and techniques.
Continuous Learning and Knowledge Sharing
Demonstrated commitment to continuous learning and professional development in cybersecurity. Published articles, technical blogs, or research papers related to cybersecurity, threat intelligence, incident response, or security engineering showcases thought leadership and depth of expertise.
Experience
Security Engineering and Incident Response
8+ years working in security engineering, incident response, detection engineering, or threat research roles within technology companies, preferably in high-growth, fast-paced environments. Experience working directly with security teams, infrastructure teams, and product engineering to implement security improvements at scale.
Production Environment Security
Hands-on experience designing, developing, and managing infrastructure projects, processes, and security standards for protecting networks, systems, and applications in production environments. Experience building security controls that scale with organizational growth and increasing transaction volumes.
Cloud Infrastructure at Scale
Demonstrated experience working with cloud platforms in production environments, including designing secure cloud architectures, implementing cloud security controls, and responding to cloud-specific security incidents. Experience with infrastructure-as-code and DevOps practices in cloud environments.
DevOps and Infrastructure Background
Past experience with DevOps, Site Reliability Engineering (SRE), or infrastructure engineering roles, particularly with Kubernetes and container orchestration. Understanding of how infrastructure teams operate helps in building practical, operationalizable security solutions.
Financial Services or Payments Security
Experience securing high-transaction environments, payments platforms, or financial services infrastructure where security incidents have significant business and customer impact. Familiarity with payment card industry (PCI) requirements and financial services compliance frameworks is valuable.
Skills
Required
Security Architecture and Design
Ability to design comprehensive, layered security architectures that protect systems from multiple attack vectors. Understanding of security principles, defense-in-depth strategies, and secure system design patterns.
Incident Investigation and Analysis
Expert-level ability to investigate security incidents, analyze logs and telemetry, identify root causes, and provide actionable remediation recommendations. Proficiency in digital forensics and evidence handling.
Cloud Platform Security
Deep expertise in AWS, GCP, Azure, or Alibaba Cloud security features, including identity and access management, network security, data protection, and audit logging. Knowledge of cloud-native threat models and security best practices.
CI/CD and DevSecOps
Understanding of continuous integration and continuous deployment pipelines, secure software development lifecycle practices, container security, and integrating security controls into development workflows without impeding developer velocity.
Threat Detection and Hunting
Proficiency in identifying indicators of compromise, writing detection rules, conducting proactive threat hunting, and analyzing telemetry from multiple sources to uncover threats before they cause damage.
Communication and Stakeholder Management
Excellent ability to explain complex technical security concepts and findings to non-technical audiences, including executives and business stakeholders. Strong written and verbal communication skills for incident reports, security recommendations, and training materials.
Linux and Operating System Security
Deep knowledge of Linux/Unix security hardening, system administration, kernel concepts, and file system security. Understanding of how operating systems operate and security mechanisms at the OS level.
Problem Solving and Critical Thinking
Strong analytical and problem-solving abilities with the capacity to think like an attacker while designing defensive controls. Ability to work through ambiguous security challenges and propose practical solutions.
Preferred
Splunk Security Monitoring
Nice to haveAdvanced experience with Splunk for security event processing, creating detection rules, building dashboards, and performing investigation searches. Familiarity with other SIEM platforms and security analytics tools.
Python Programming
Nice to haveProficiency in Python for security automation, threat intelligence analysis, custom tool development, and security research. Ability to write scripts that integrate with security systems and process telemetry data.
Java or Kotlin Development
Nice to haveExperience with Java or Kotlin for understanding application-level security vulnerabilities, secure coding practices, and contributing to security-focused development efforts in polyglot environments.
Kubernetes and Container Security
Nice to haveExperience with Kubernetes orchestration, Docker containers, and container security best practices. Understanding of supply chain security and securing containerized applications in production environments.
GCP or Alibaba Cloud
Nice to haveHands-on experience with Google Cloud Platform (GCP) or Alibaba Cloud beyond the primary cloud platform. Knowledge of unique security features and compliance capabilities of alternative cloud providers.
Okta and Cloud Identity
Nice to haveExperience implementing and managing Okta for identity and access management, including SSO, MFA, and conditional access policies. Understanding of identity-first security strategies.
Red Team and Penetration Testing
Nice to haveBackground in penetration testing, adversarial security assessments, or red team engagements. Experience simulating attacker tactics to identify security weaknesses and validate defensive controls.
Threat Intelligence and Cybersecurity Research
Nice to havePublished research, articles, or significant contributions to cybersecurity knowledge sharing. Active participation in security communities, conferences, or open-source security projects.
Compensation
Pay and benefits.
Base·USD 180,000 – 250,000
Equity·Stock options
Full posting
Original listing.
About Airwallex
Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 250,000 businesses worldwide – including Brex, Navan, Qantas, SHEIN and many more – with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale.
Proudly founded in Melbourne, we have a team of over 2,300 of the brightest and most innovative people in tech across 27 offices around the globe. Valued at US$11 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you’re ready to do the most ambitious work of your career, join us.
Attributes We Value
We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you’re motivated by our mission and operating principles. You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor.
You're humble and collaborative; turn zero‑to‑one ideas into real products, and you “get stuff done” end-to-end. You use AI to work smarter and solve problems faster. Here, you’ll tackle complex, high‑visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let’s build what’s next.
About the team
Airwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data, and employees while enabling the business to move quickly. The team helps build and maintain strong security practices across the company—from secure product and infrastructure design to risk reduction, incident response, audits, and compliance—so security is built into how we operate, not treated as a blocker.
What you'll do
As a Staff Product Security Engineer at Airwallex, you will be a trusted member of the Information Security team and work closely with Infrastructure, Product and Engineering teams across the business.
Reporting directly to the Product Security Engineering Manager, this role will see you being a critical part of Airwallex, helping to identify, protect, detect, respond and recover the organisation from cybersecurity threats.
This is a dynamic and hands-on role that requires experience in designing, developing and managing infrastructure projects, processes and standards related to the security of our networks, systems and applications.
This role is based in San Francisco, or Sydney or Melbourne
Responsibilities:
Create and build security controls that strengthen Airwallex’s ability to scale securely.
Design and deliver security improvements across applications, software, and services.
Develop and operationalise detection strategies and response workflows that improve the speed and effectiveness of incident response.
Build and enhance secure systems through strong integration, testing, operations, and maintenance practices.
Leverage and analyse endpoint, network, and cloud telemetry to identify, investigate, and mitigate threats.
Design, implement, and maintain cybersecurity infrastructure that improves resilience across the Airwallex environment.
Investigate, contain, and respond to cybersecurity incidents to reduce risk and strengthen defensive capability.
Assess and improve system and network security by identifying vulnerabilities, configuration issues, and remediation opportunities.
Collect and analyse threat intelligence and forensic evidence to better understand, track, and disrupt threats.
Conduct and support defensive operations, tactical forensics, and threat hunting to strengthen security outcomes.
Partner with teams across Airwallex to embed security into new and existing applications, software, and services and drive continuous improvement.
Who you are
We’re looking for people who meet the minimum qualifications for this role. The preferred qualifications are great to have, but are not mandatory.
Minimum qualifications:
8+ years working in a security engineering or incident response role within a tech company
In depth expertise with at least one major cloud platform
Strong knowledge of common software development tools and infrastructure, including CI/CD tooling and pipelines
Comprehensive understanding of common attacker tools and techniques, how they can be detected and prevented, and ability to respond to incidents with high depth and quality of investigation
Strong communication skills with the ability to explain technical security and software concepts to a non-technical audience
A passion for solving the complex challenges of high-growth startups
Self motivation and drive to learn new skills, or dive deeper into existing skills
Preferred qualifications:
Bachelor's degree in Cybersecurity, Computer Science or similar
Recognised training or cybersecurity certifications (eg OSCP, GIAC, CEH)
Strong experience with Splunk and other common security monitoring tools
Past DevOps/SRE experience with Kubernetes
Experience with GCP or Alibaba Cloud (with or without certification)
Experience with Okta, GSuite, and cloud-based VPN services
Experience with Python, Java/Kotlin
Published articles, journals or blogs related to cybersecurity
Applicant Safety Policy: Fraud and Third-Party Recruiters
To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @airwallex.com email address. Please apply only through careers.airwallex.com or our official LinkedIn page.
Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary.
Equal opportunity
Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don’t regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know.
Redirects to Airwallex's application page.
Other roles
More at Airwallex.
IT Support Engineer
Junior
Senior Cloud Network Engineer, Infra
Senior
Senior Software Engineer, Regulatory Reporting
Senior
Software Engineer Intern (Jan to Jun 2027)
Intern
Engineering Director, Payments Platform
Director