About the Role
Role details below.
Responsibilities
- Managing two small teams of software engineers who design and implement software to reduce risk.
- Owning the strategy and roadmap for both teams, balancing security and developer experience to build an experience that allows Canvanauts to move quickly, while having secure guardrails in place.
- Coach and develop engineers by providing regular, practical feedback to help them reach their personal growth goals.
- Own the team’s development methodology including sprint planning, stand-ups and retrospectives resulting in a high-performing team.
- Driving adoption of our systems internally across Canva engineering teams, championing the benefits of what we build.
Requirements
- Experience in directly managing a high-performing team, guided by company or specialty missions, and goals.
- Strong software engineering fundamentals; be able to hold court with principal-level engineers and significantly contribute to design documents and complex software architecture.
- Experience partnering cross-functionally with software engineering, SRE/DevOps, and compliance teams to embed security into developer workflows.
- You’re experienced with languages such as Golang, Java, Rust or similar.
- Experience in building and operating cloud-based services.
Nice to Have
- Experience in a security domain (application sandboxing, encryption, vulnerability scanning, etc) is a strong plus.
- An understanding of the security products industry, and security risk. You know the security market, and can evaluate needs against existing security tools and products that meet product needs & identify areas where we should challenge the status quo.
- Experience with infrastructure tools like Terraform, Helm, K8s, or similar.
- Experience working with CI/CD systems and defining integration pipelines.
Additional Information
- The Security Group runs programs across Application Security, Risk Management, Enterprise Security, and Threat Detection and Response domains.
- The Security Platform Engineering team is currently focused on building sandbox capabilities, workload isolation, BYOK and more.
- The Security Development team builds net-new capabilities including vulnerability scanning and incident response tooling.