Senior Security Operations Engineer

Auckland, Auckland, New Zealand

Applications have closed

Lightspeed Commerce

Lightspeed is the fast, intuitive POS and payments platform helping the world’s best retail, hospitality and golf businesses get even better.

View company page

Hi there! Thanks for stopping by 👋 

We are looking for a Senior Security Operations Engineer to join our team in Newmarket. We are a lean, multidisciplinary team driving to be progressive in our approach to security. We aim to cultivate trust with people by keeping their data and systems resilient to threats.

You will build and manage security tooling to detect and respond to systems security issues, stay up to date with the latest security vulnerabilities, participate in incident response and work closely with engineering teams to advise on secure architecture, practices and help secure our environment as a whole.

What you’ll be doing: 

Security Operations (50%)

  • Conduct security threat modelling of existing and emerging systems and technologies at Lightspeed.
  • Implement, maintain, and improve security infrastructure in AWS.
  • Assist in vulnerability management and remediation processes, and contribute to remediation plans.
  • Help lead incident response through in-depth, technical analysis and remediation (playbook creation...).

DevOps (25%)

  • Build scalable tools, systems, and processes that allow engineers to ship world-class software.
  • Participate with the resolution of security-related infrastructure configurations or failures

Documentation & Communication (15%)

  • Create requirements and documentation for security systems.
  • Tracking and maintaining operational security metrics (i.e. threats, risks, issues).
  • Effectively communicate security remediation strategies.

Software Engineering + Security (10%)

  • Provide technical guidelines, security tooling integrated into CI/CD and secure engineering patterns for deploying new systems and infrastructure
  • Raise awareness and be a subject matter expert to tech teams, empowering them to maintain security throughout the SDLC

What you need to bring:

  • Experience working on both security and operations, monitoring, tooling, and running a highly complex cloud infrastructure. 
  • Working experience with at least one language (eg. Python, Go, etc).
  • Experience working with engineers to create and ingest the right logs, configure meaningful risk-based alerting.
  • Experience of developing and documenting security processes and plans based on common information security management frameworks (ISO 270x, SOC 2, NIST or CIS).
  • Technical knowledge of security engineering, identity and access management, applied cryptography, and security protocols.
  • Demonstrated cloud experience with AWS or similar (e.g. IAM best practices, networking, securing multi-account setups, IDS/GuardDuty, etc.).
  • Excellent communication skills, keen eye for detail, and knack for solving difficult problems.

What’s in it for you?

  • Ability to do your job in a truly flexible environment;
  • Genuine career opportunities in a company that’s creating new jobs everyday;
  • Work in a team big enough for growth but lean enough to make a genuine impact.

Plus, we have a range of benefits that’ll keep you happy, healthy and (not) hungry:

  • Lightspeed share scheme (we are all owners)
  • Unlimited paid time off policy
  • Work remotely from anywhere in the world for up to 60 days per year
  • Flexible working policy
  • Health and wellness benefit of $500 per year
  • Mental health online platform and counselling & coaching services
  • Paid leave and assistance for new parents
  • LinkedIn Learning license
  • Volunteer day

Please note that we ask applicants to disclose any criminal convictions, and we conduct criminal record checks as part of our hiring process for this role.

To all recruitment agencies: Lightspeed does not accept unsolicited agency resumes. If we have not directly engaged your company in writing to supply candidates for a specific vacancy, Lightspeed will not be responsible for any fees related to unsolicited resumes.

Where to from here?
Obviously, this has to be mutually beneficial: we want you to step into a role you love, and we want to offer you a place you’re proud to come to every day. For a glimpse into our world check out our career page here.

Lightspeed is building communities through commerce, and we need people from all backgrounds and lived experiences to do that. We were founded in 2005, in Montreal’s gay village and our original members were all part of the LGBTQ+ community. The ethos of our business has been about inclusion from the very beginning, and we strive to provide a workplace where everyone belongs.

Who we are:
Lightspeed (TSX/NYSE: LSPD) powers the businesses that are the backbone of the global economy.

Our one-stop commerce platform transforms and unifies digital and physical operations by enabling multichannel sales, expansion to new locations, global payments, financial solutions and connection to supplier networks. With the Lightspeed commerce platform, merchants in retail and hospitality can build thriving businesses for the future.

Headquartered in Montréal, Canada, Lightspeed is trusted by favourite local businesses, where the community goes to shop and dine in over 100 countries. Lightspeed has offices in Canada, the USA, Europe, Russia and APAC.

We’re passionate about enabling people to do their best work. We dream big and we’re looking for people who do the same. With us, career milestones happen often and we celebrate every one. Come work with us and find out where your career will take you at Lightspeed!

Tags: AWS CI/CD Cloud Cryptography DevOps IAM IDS Incident response Monitoring NIST Python SDLC SOC 2 Vulnerabilities Vulnerability management

Perks/benefits: Career development Flex hours Flex vacation Health care Unlimited paid time off Wellness

Region: Asia/Pacific
Country: New Zealand
Job stats:  9  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.