At Canva, we’re on a mission to empower the world to design. We’re looking for an Engineering Manager to lead our Identity & Access team. You will be responsible for building and running the services that protect Canva's systems and customer data, owning the strategy for identity and access while balancing security, compliance, and developer experience.
What You'll Do
- Manage a team of software engineers designing and implementing authentication and authorization systems to protect customer PII and user-generated content.
- Own the strategy for identity and access at Canva, balancing security, compliance, and developer experience to enable teams to move quickly with secure guardrails.
- Coach and develop engineers by providing regular, practical feedback to help them reach their personal growth goals.
- Own the team’s development methodology, including sprint planning, stand-ups, and retrospectives.
- Work collaboratively with partner groups such as Infrastructure and IT to build systems that scale.
- Drive internal adoption of the team’s systems, championing their benefits.
What We're Looking For
- A solid understanding of authentication and authorization technologies like access proxies, SAML, OIDC, and OAuth.
- The ability to build an access strategy that balances usability, security, and compliance requirements.
- Ability to partner with the team to design and build platform features, owning the solution end-to-end.
- Experience with languages such as Golang, Python, Java, or similar.
- An understanding of attribute-based access control systems that utilize Zanzibar-style authorization.
Nice to Have
- An understanding of policy-as-code methodologies such as OPA and rego policies.
- Experience with infrastructure tools like Terraform, Helm, K8s, or similar.
- Experience working with CI/CD systems and defining integration pipelines.
- A solid understanding of audit and compliance frameworks such as ISO27001, SOC 2, SOX, or FedRAMP.
- An understanding of emerging AI access patterns and how they differ from human access.
- An understanding of corporate identity and IGA systems such as Okta, Lumos, or ConductorOne.
Technical Stack
- Languages: Golang, Python, Java
- Infrastructure: Terraform, Helm, K8s
Team & Environment
This role is part of Canva's Security Group, which runs programs across Application Security, Risk Management, Enterprise Security, and Threat Detection and Response domains.
Work Mode
This role is open to remote candidates across Australia and New Zealand (ANZ).
Canva is an equal opportunity employer.



