# Staff Product Security Engineer
**Company:** [Airwallex](https://scaleengineer.com/companies/airwallex)
Airwallex is seeking a Staff Product Security Engineer to join their Information Security team in Melbourne, Australia. The role focuses on developing robust cybersecurity strategies, implementing advanced security controls, and protecting the company's global financial technology infrastructure through proactive threat detection, incident response, and continuous security improvement.
**Role:** Staff Product Security Engineer
**Seniority:** Staff
**Locations:** AU - Melbourne
**Salary:** 160000–260000 AUD
[Apply](https://jobs.ashbyhq.com/airwallex/f77a698d-b8f1-481a-8827-eb2262acc177)
Canonical: https://scaleengineer.com/jobs/airwallex/staff-product-security-engineer
---
## Responsibilities

- Security Control Development: Create and build security controls to strengthen Airwallex's secure scaling capabilities
- Threat Detection: Develop and operationalize detection strategies and response workflows to improve incident response effectiveness
- System Resilience: Design, implement, and maintain cybersecurity infrastructure to enhance resilience across Airwallex's environment
- Threat Intelligence: Collect and analyze threat intelligence and forensic evidence to understand and disrupt potential security threats
- Collaborative Security: Partner with cross-functional teams to embed security into new and existing applications, software, and services

## Requirements

### education

- {"name":"Academic Background","description":"Bachelor's degree in Cybersecurity, Computer Science, or related field preferred"}

### technical

- {"name":"Cloud Security","description":"Expertise in cloud platform security and infrastructure protection"}
- {"name":"Incident Response","description":"Advanced skills in cybersecurity incident investigation and mitigation"}
- {"name":"Security Tooling","description":"Proficiency with security monitoring, forensic, and threat hunting tools"}

### experience

- {"name":"Professional Experience","description":"8+ years in security engineering or incident response within a tech company"}
- {"name":"DevOps/SRE","description":"Demonstrated experience with DevOps practices and site reliability engineering"}

## Skills

### required

- {"name":"Cloud Platform Expertise","description":"In-depth expertise with at least one major cloud platform"}
- {"name":"Software Development Tools","description":"Strong knowledge of CI/CD tooling and infrastructure"}
- {"name":"Incident Response","description":"Comprehensive understanding of attacker tools, detection, and prevention techniques"}
- {"name":"Communication","description":"Ability to explain technical security concepts to non-technical audiences"}

### preferred

- {"name":"Cloud Certifications","description":"Experience with GCP or Alibaba Cloud certifications"}
- {"name":"Programming Languages","description":"Experience with Python, Java, or Kotlin"}
- {"name":"Security Certifications","description":"OSCP, GIAC, or CEH certifications"}
- {"name":"Security Monitoring","description":"Experience with Splunk and other security monitoring tools"}

## Tech stack

### tools

- {"name":"Splunk","description":"Security information and event management"}
- {"name":"Okta","description":"Identity and access management"}
- {"name":"Kubernetes","description":"Container orchestration platform"}

### others

- {"name":"Cloud Platforms","description":"GCP, Alibaba Cloud"}
- {"name":"VPN Services","description":"Cloud-based secure network access"}

### databases

### languages

- {"name":"Python","description":"Scripting and automation"}
- {"name":"Java","description":"Enterprise application development"}
- {"name":"Kotlin","description":"Modern application development"}

### frameworks

## Benefits

### benefits

- {"name":"Equity","description":"Stock options available as part of compensation package"}
- {"name":"Performance Bonus","description":"Annual bonus potential based on individual and company performance"}
- {"name":"Global Opportunity","description":"Work with a fast-growing fintech company operating across 26 global offices"}
- {"name":"Learning Environment","description":"Opportunity for accelerated learning and career growth in a high-impact startup"}

## Compensation

- **max:** 260000
- **min:** 160000
- **currency:** AUD
- **stockOptions:** true

## Interview process

### steps

- {"name":"Initial Screening","description":"Review of resume and initial qualifications"}
- {"name":"Technical Interview","description":"In-depth discussion of security engineering experience and technical capabilities"}
- {"name":"Practical Assessment","description":"Security-focused technical challenge or case study evaluation"}
- {"name":"Team Interview","description":"Meeting with Information Security team members to assess cultural fit and collaboration potential"}
- {"name":"Final Interview","description":"Discussion with Product Security Engineering Manager and final decision-making"}

## Full description
## **About Airwallex**

Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 200,000 businesses worldwide – including Brex, Rippling, Navan, Qantas, SHEIN and many more – with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale.

Proudly founded in Melbourne, we have a team of over 2,200 of the brightest and most innovative people in tech across 26 offices around the globe. Valued at US$8 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you’re ready to do the most ambitious work of your career, join us.

## **Attributes We Value**

We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you’re motivated by our mission and [operating principles](https://www.airwallex.com/us/operating-principles). You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor.

You're humble and collaborative; turn zero‑to‑one ideas into real products, and you “get stuff done” end-to-end. You use AI to work smarter and solve problems faster. Here, you’ll tackle complex, high‑visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let’s build what’s next.

**About the team**

Airwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data, and employees while enabling the business to move quickly. The team helps build and maintain strong security practices across the company—from secure product and infrastructure design to risk reduction, incident response, audits, and compliance—so security is built into how we operate, not treated as a blocker.

**Your role**

As a Staff Product Security Engineer at Airwallex, you will be a trusted member of the Information Security team and work closely with Infrastructure, Product and Engineering teams across the business.

Reporting directly to the Product Security Engineering Manager, this role will see you being a critical part of Airwallex, helping to identify, protect, detect, respond and recover the organisation from cybersecurity threats.

This is a dynamic and hands-on role that requires experience in designing, developing and managing infrastructure projects, processes and standards related to the security of our networks, systems and applications.

**What you’ll be doing**

* Create and build security controls that strengthen Airwallex’s ability to scale securely.
* Design and deliver security improvements across applications, software, and services.
* Develop and operationalise detection strategies and response workflows that improve the speed and effectiveness of incident response.
* Build and enhance secure systems through strong integration, testing, operations, and maintenance practices.
* Leverage and analyse endpoint, network, and cloud telemetry to identify, investigate, and mitigate threats.
* Design, implement, and maintain cybersecurity infrastructure that improves resilience across the Airwallex environment.
* Investigate, contain, and respond to cybersecurity incidents to reduce risk and strengthen defensive capability.
* Assess and improve system and network security by identifying vulnerabilities, configuration issues, and remediation opportunities.
* Collect and analyse threat intelligence and forensic evidence to better understand, track, and disrupt threats.
* Conduct and support defensive operations, tactical forensics, and threat hunting to strengthen security outcomes.
* Partner with teams across Airwallex to embed security into new and existing applications, software, and services and drive continuous improvement.

**Minimum Qualifications (must-have)**

* 8+ years working in a security engineering or incident response role within a tech company
* In depth expertise with at least one major cloud platform
* Strong knowledge of common software development tools and infrastructure, including CI/CD tooling and pipelines
* Comprehensive understanding of common attacker tools and techniques, how they can be detected and prevented, and ability to respond to incidents with high depth and quality of investigation
* Strong communication skills with the ability to explain technical security and software concepts to a non-technical audience
* A passion for solving the complex challenges of high-growth startups
* Self motivation and drive to learn new skills, or dive deeper into existing skills

**Highly Desired**

* Bachelor's degree in Cybersecurity, Computer Science or similar
* Recognised training or cybersecurity certifications (eg OSCP, GIAC, CEH)
* Strong experience with Splunk and other common security monitoring tools
* Past DevOps/SRE experience with Kubernetes
* Experience with GCP or Alibaba Cloud (with or without certification)
* Experience with Okta, GSuite, and cloud-based VPN services
* Experience with Python, Java/Kotlin
* Published articles, journals or blogs related to cybersecurity

## **Applicant Safety Policy: Fraud and Third-Party Recruiters**

_To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @_[_airwallex.com_](http://airwallex.com) _email address. Please apply only through_ [_careers.airwallex.com_](http://careers.airwallex.com) _or our official LinkedIn page._

_Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary._

## **Equal opportunity**

Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don’t regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know.
