Remote
Staff Security Engineer
About this role
Staff Enterprise Security Engineer Join the team redefining how the world experiences design. Hey, gday, mabuhay, kia ora, 你好, hallo, vítejte! Thanks for stopping by. We know job hunting can be a little time-consuming, and you're probably keen to find out what's on offer, so we'll get straight to the point. About the team The Security Group protects Canva's systems and data from information security threats, across Application Security, Risk Management, Enterprise Security, and Threat Detection and Response.
Internal Systems Security is the team inside that focused on Canva's own environment. What you'd be doing in this role The Internal Systems Security team secures the environment Canvanauts work in every day. Laptops, networks, identities, the SaaS tools everyone relies on, and now the AI agents doing real work alongside us. Most of this work used to follow a playbook. That's no longer true. Canvanauts now run AI agents that act on their behalf, which is a very different security problem to a person at a laptop.
One of the questions on our plate right now: where does the policy layer sit for MCP tool calls, when we want decisions made per action rather than per application, and evaluated fast enough that nobody notices them? This is a Staff level individual contributor role. You'd set technical direction without managing anyone. At the moment, that means: Going out to teams across the business, working out where their real risks sit, and building the roadmap with them rather than handing them one.
Helping those teams turn on AI workflows safely, instead of being the reason they can't. Reviewing new tools and agents before they land. We're the team that says yes, no, or yes with these settings. Threat modelling newer patterns like MCP, agentic workflows and SaaS to SaaS integrations, then turning what you find into controls people adopt. Setting the standards other teams build against, and automating the work so a multiplying workload doesn't need a bigger team.
You're probably a match if: You go looking for problems. You can point to something you found yourself, got other people to care about, and saw through to a fix. You can bring people with you. You've convinced an IT or engineering lead to take on something that wasn't on their roadmap, without a mandate. You've done hands-on enterprise, corporate or internal security engineering, and built and run security services in production.