Senior Engineer, Security

Sydney or Melbourne. Foundation team. Build an enterprise level AI solution from the ground up.

About the role

Senior Engineer, Security
Sydney or Melbourne. Permanent, full time. $180,000 to $210,000 plus superannuation.

About Spikewerks

Spikewerks is an enterprise AI company building spikeOS, a governed knowledge and intelligence platform for large regulated organisations. It ingests from market data, documents, operational systems and spreadsheets, extracts structured facts, and holds them as typed records where every field traces back to the page it came from.

The company is commercially active in two sectors: energy, working with generators, asset owners and retailers, and lending, through a partnership with a lending management platform. Both carry signed customers and revenue.

The role

This is the first dedicated security appointment in the company, reporting to the CTO.

Identity and isolation carry the weight of this product. Every caller into spikeOS authenticates through the customer's own identity provider and inherits the access rights and directory groups the customer already manages. Entitlements are enforced inside the query at four levels: domain, record type, row and field.

The customer base is enterprise and regulated, so a security team assesses the platform before any deal closes. The CTO currently owns the identity and isolation design and carries that assessment response. You come in alongside it, learn the framework, and take it over.

Very little is locked. The identity provider approach, the tenant isolation model, and the AWS account structure are all open to better ideas. The CTO wants a strong second opinion on the direction, so forming a view and defending it is part of the seat.

What you would own

From day one: security tooling in the development pipeline, the roadmap to harden the platform, and adversarial row-level security tests that prove tenant isolation holds when a layer is removed.

Through the first year: single sign-on against customer identity providers including just-in-time provisioning and group to role mapping, per-tenant database role isolation and row-level security policies, certificate infrastructure between components, tenant onboarding and offboarding to a demonstrable standard, and audit records for all human access to customer data.

After that: PKI, threat models suitable for external review, and evidence preparation for SOC 2 or ISO 27001.

What we are looking for

An engineer first. Someone who has spent their career building software in which security was a major part of what they built. This is not a full-time security role, so expect ordinary product engineering alongside the identity and isolation surface.

On arrival, you will need hands-on experience with OIDC and SAML, PostgreSQL row-level security, including adversarial tests that prove isolation holds, and production-grade AWS IAM.

Useful but not required: WorkOS, Entra ID or Okta; operational X.509 and PKI; SOC 2 or ISO 27001 evidence preparation as the implementing engineer; and vendor-side experience with a regulated customer's security assessment.

How the team builds

Development runs through an internal harness built by the CTO. Engineers plan features and produce decision documents; the harness generates code under test-driven development, and human code review is mandatory. You will spend more time planning, deciding and reviewing than writing code. 

The stack is Python on PostgreSQL, containerised, on AWS.

Learn about Spikewerks

https://spikewerks.com/

Intro video: https://drive.google.com/file/d/1cRwaYIqe6NbyOyVlotOPgo03mPcRz0cb/view