Resume and JobRESUME AND JOB
Canva logo

Senior Security Engineer - Incident Response

Canva

Software and Technology Jobs

Senior Security Engineer - Incident Response

full-timePosted: Dec 16, 2025

Job Description

Senior Security Engineer - Incident Response

Location: Team Engineering

Team: Country London / United Kingdom

About the Role

Join the team redefining how the world experiences design at Canva! We're looking for a Senior Security Engineer - Incident Response to safeguard our innovative, design-focused platform used by millions of creators worldwide. Based in our buzzing London campus in Shoreditch – Europe's HQ with leafy Hoxton Square vibes, home-cooked meals, and collaborative spaces – you'll enjoy a hybrid model that empowers you to balance office magic with focused work. As part of our Detection and Response team within the Security Group, you'll protect Canva's cloud-native infrastructure (AWS, GCP) while collaborating with engineering squads to embed security into our creative tools, ensuring users can design without worry. In this role, you'll lead incident response efforts, hunt threats proactively, build detection automation, and champion best practices in a fast-scaling environment where change is exciting DNA. Expect to coordinate escalations, craft response playbooks, conduct post-mortems, and develop tools that prevent recurrence – all while fostering a culture of security awareness across our design-loving teams. Your investigative prowess and risk-based mindset will shine as you tackle ambiguous problems with elegant, scalable solutions. Canva's collaborative culture thrives on diverse skills and passion – even if you don't match every bullet, we want to hear from you! You'll join a team passionate about threat detection, working with modern tooling on Linux/macOS/EDR, and contributing to our global mission. With equity, inclusive leave, Vibe & Thrive perks, and moments of connectivity, you'll thrive while helping protect the world's creativity. Apply now and help us keep Canva secure for creators everywhere.

Key Responsibilities

  • Lead incident response coordination and act as escalation point for security incidents across Canva's cloud-native infrastructure, including on-call roster participation
  • Monitor and investigate security threats across AWS, GCP, and hybrid environments, proactively hunting for anomalous behavior and potential intrusions
  • Build and maintain detection rules, automation workflows, and response playbooks using detection-as-code methodologies
  • Develop tools and solutions for security incident alerting, management, and communication to prevent recurrence
  • Maintain comprehensive incident response documentation, lead post-incident reviews, and produce detailed incident reports
  • Champion security best practices across secure development, network security, and security operations
  • Collaborate with engineering teams to integrate security into Canva's innovative design-focused products
  • Apply risk-based decision making to protect Canva's global user base and creative ecosystem
  • Contribute to threat intelligence sharing and continuous improvement of detection capabilities
  • Mentor junior team members on incident response techniques and best practices

Required Qualifications

  • Demonstrable experience in incident response, security operations, and coordinating security events from detection through resolution
  • Strong knowledge of cloud security architectures, attack techniques, and hands-on experience with cloud providers (AWS, GCP, or Azure)
  • Extensive experience with endpoint detection and response (EDR) platforms for investigations, analysis, and response actions
  • Investigative mindset with ability to leverage OSINT techniques and solve ambiguous security problems with elegant solutions
  • Excellent documentation, communication, and stakeholder management skills while prioritizing multiple tasks in a dynamic environment
  • Understanding of security's organizational role with risk-based decision making in security operations
  • Comfortable working with Linux, macOS, and modern security tooling

Preferred Qualifications

  • Background in forensic acquisition and analysis, including maintaining chain of custody
  • Incident response experience in containerized and Kubernetes environments
  • Proficiency in scripting and programming languages (Python, Go, or similar)
  • Experience with security automation platforms and SOAR tools
  • Familiarity with detection-as-code practices and version control workflows

Required Skills

  • Incident response coordination and escalation
  • Cloud security (AWS, GCP, hybrid environments)
  • EDR platforms for threat investigation
  • OSINT techniques and threat hunting
  • Detection-as-code and automation workflows
  • Linux and macOS proficiency
  • Risk-based security decision making
  • Stakeholder communication and documentation
  • Post-incident review leadership
  • Scripting (Python, Go)
  • Kubernetes/container security
  • MITRE ATT&CK framework knowledge
  • Collaborative problem-solving
  • Fast-paced environment adaptability
  • Investigative mindset

Benefits

  • Equity packages to share in Canva's success
  • Inclusive parental leave policy supporting all parents and carers
  • Annual Vibe & Thrive allowance for wellbeing, social connection, office setup, and more
  • Flexible leave options to recharge and support personal needs
  • Hybrid work model from Canva's vibrant London campus in Shoreditch
  • Delicious home-cooked meals from our Head Chef and collaborative workspaces
  • Opportunities for global impact in a design-first, innovative culture
  • Virtual interviews and inclusive hiring process with reasonable adjustments

Canva is an equal opportunity employer.

Locations

  • Team Engineering, Global

Salary

Estimated Salary Rangehigh confidence

140,000 - 220,000 USD / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • Incident response coordination and escalationintermediate
  • Cloud security (AWS, GCP, hybrid environments)intermediate
  • EDR platforms for threat investigationintermediate
  • OSINT techniques and threat huntingintermediate
  • Detection-as-code and automation workflowsintermediate
  • Linux and macOS proficiencyintermediate
  • Risk-based security decision makingintermediate
  • Stakeholder communication and documentationintermediate
  • Post-incident review leadershipintermediate
  • Scripting (Python, Go)intermediate
  • Kubernetes/container securityintermediate
  • MITRE ATT&CK framework knowledgeintermediate
  • Collaborative problem-solvingintermediate
  • Fast-paced environment adaptabilityintermediate
  • Investigative mindsetintermediate

Required Qualifications

  • Demonstrable experience in incident response, security operations, and coordinating security events from detection through resolution (experience)
  • Strong knowledge of cloud security architectures, attack techniques, and hands-on experience with cloud providers (AWS, GCP, or Azure) (experience)
  • Extensive experience with endpoint detection and response (EDR) platforms for investigations, analysis, and response actions (experience)
  • Investigative mindset with ability to leverage OSINT techniques and solve ambiguous security problems with elegant solutions (experience)
  • Excellent documentation, communication, and stakeholder management skills while prioritizing multiple tasks in a dynamic environment (experience)
  • Understanding of security's organizational role with risk-based decision making in security operations (experience)
  • Comfortable working with Linux, macOS, and modern security tooling (experience)

Preferred Qualifications

  • Background in forensic acquisition and analysis, including maintaining chain of custody (experience)
  • Incident response experience in containerized and Kubernetes environments (experience)
  • Proficiency in scripting and programming languages (Python, Go, or similar) (experience)
  • Experience with security automation platforms and SOAR tools (experience)
  • Familiarity with detection-as-code practices and version control workflows (experience)

Responsibilities

  • Lead incident response coordination and act as escalation point for security incidents across Canva's cloud-native infrastructure, including on-call roster participation
  • Monitor and investigate security threats across AWS, GCP, and hybrid environments, proactively hunting for anomalous behavior and potential intrusions
  • Build and maintain detection rules, automation workflows, and response playbooks using detection-as-code methodologies
  • Develop tools and solutions for security incident alerting, management, and communication to prevent recurrence
  • Maintain comprehensive incident response documentation, lead post-incident reviews, and produce detailed incident reports
  • Champion security best practices across secure development, network security, and security operations
  • Collaborate with engineering teams to integrate security into Canva's innovative design-focused products
  • Apply risk-based decision making to protect Canva's global user base and creative ecosystem
  • Contribute to threat intelligence sharing and continuous improvement of detection capabilities
  • Mentor junior team members on incident response techniques and best practices

Benefits

  • general: Equity packages to share in Canva's success
  • general: Inclusive parental leave policy supporting all parents and carers
  • general: Annual Vibe & Thrive allowance for wellbeing, social connection, office setup, and more
  • general: Flexible leave options to recharge and support personal needs
  • general: Hybrid work model from Canva's vibrant London campus in Shoreditch
  • general: Delicious home-cooked meals from our Head Chef and collaborative workspaces
  • general: Opportunities for global impact in a design-first, innovative culture
  • general: Virtual interviews and inclusive hiring process with reasonable adjustments

Target Your Resume for "Senior Security Engineer - Incident Response" , Canva

Get personalized recommendations to optimize your resume specifically for Senior Security Engineer - Incident Response. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Senior Security Engineer - Incident Response" , Canva

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

CanvaDesignCountry London / United KingdomTeam EngineeringGlobalCountry London / United Kingdom

Answer 10 quick questions to check your fit for Senior Security Engineer - Incident Response @ Canva.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.

Canva logo

Senior Security Engineer - Incident Response

Canva

Software and Technology Jobs

Senior Security Engineer - Incident Response

full-timePosted: Dec 16, 2025

Job Description

Senior Security Engineer - Incident Response

Location: Team Engineering

Team: Country London / United Kingdom

About the Role

Join the team redefining how the world experiences design at Canva! We're looking for a Senior Security Engineer - Incident Response to safeguard our innovative, design-focused platform used by millions of creators worldwide. Based in our buzzing London campus in Shoreditch – Europe's HQ with leafy Hoxton Square vibes, home-cooked meals, and collaborative spaces – you'll enjoy a hybrid model that empowers you to balance office magic with focused work. As part of our Detection and Response team within the Security Group, you'll protect Canva's cloud-native infrastructure (AWS, GCP) while collaborating with engineering squads to embed security into our creative tools, ensuring users can design without worry. In this role, you'll lead incident response efforts, hunt threats proactively, build detection automation, and champion best practices in a fast-scaling environment where change is exciting DNA. Expect to coordinate escalations, craft response playbooks, conduct post-mortems, and develop tools that prevent recurrence – all while fostering a culture of security awareness across our design-loving teams. Your investigative prowess and risk-based mindset will shine as you tackle ambiguous problems with elegant, scalable solutions. Canva's collaborative culture thrives on diverse skills and passion – even if you don't match every bullet, we want to hear from you! You'll join a team passionate about threat detection, working with modern tooling on Linux/macOS/EDR, and contributing to our global mission. With equity, inclusive leave, Vibe & Thrive perks, and moments of connectivity, you'll thrive while helping protect the world's creativity. Apply now and help us keep Canva secure for creators everywhere.

Key Responsibilities

  • Lead incident response coordination and act as escalation point for security incidents across Canva's cloud-native infrastructure, including on-call roster participation
  • Monitor and investigate security threats across AWS, GCP, and hybrid environments, proactively hunting for anomalous behavior and potential intrusions
  • Build and maintain detection rules, automation workflows, and response playbooks using detection-as-code methodologies
  • Develop tools and solutions for security incident alerting, management, and communication to prevent recurrence
  • Maintain comprehensive incident response documentation, lead post-incident reviews, and produce detailed incident reports
  • Champion security best practices across secure development, network security, and security operations
  • Collaborate with engineering teams to integrate security into Canva's innovative design-focused products
  • Apply risk-based decision making to protect Canva's global user base and creative ecosystem
  • Contribute to threat intelligence sharing and continuous improvement of detection capabilities
  • Mentor junior team members on incident response techniques and best practices

Required Qualifications

  • Demonstrable experience in incident response, security operations, and coordinating security events from detection through resolution
  • Strong knowledge of cloud security architectures, attack techniques, and hands-on experience with cloud providers (AWS, GCP, or Azure)
  • Extensive experience with endpoint detection and response (EDR) platforms for investigations, analysis, and response actions
  • Investigative mindset with ability to leverage OSINT techniques and solve ambiguous security problems with elegant solutions
  • Excellent documentation, communication, and stakeholder management skills while prioritizing multiple tasks in a dynamic environment
  • Understanding of security's organizational role with risk-based decision making in security operations
  • Comfortable working with Linux, macOS, and modern security tooling

Preferred Qualifications

  • Background in forensic acquisition and analysis, including maintaining chain of custody
  • Incident response experience in containerized and Kubernetes environments
  • Proficiency in scripting and programming languages (Python, Go, or similar)
  • Experience with security automation platforms and SOAR tools
  • Familiarity with detection-as-code practices and version control workflows

Required Skills

  • Incident response coordination and escalation
  • Cloud security (AWS, GCP, hybrid environments)
  • EDR platforms for threat investigation
  • OSINT techniques and threat hunting
  • Detection-as-code and automation workflows
  • Linux and macOS proficiency
  • Risk-based security decision making
  • Stakeholder communication and documentation
  • Post-incident review leadership
  • Scripting (Python, Go)
  • Kubernetes/container security
  • MITRE ATT&CK framework knowledge
  • Collaborative problem-solving
  • Fast-paced environment adaptability
  • Investigative mindset

Benefits

  • Equity packages to share in Canva's success
  • Inclusive parental leave policy supporting all parents and carers
  • Annual Vibe & Thrive allowance for wellbeing, social connection, office setup, and more
  • Flexible leave options to recharge and support personal needs
  • Hybrid work model from Canva's vibrant London campus in Shoreditch
  • Delicious home-cooked meals from our Head Chef and collaborative workspaces
  • Opportunities for global impact in a design-first, innovative culture
  • Virtual interviews and inclusive hiring process with reasonable adjustments

Canva is an equal opportunity employer.

Locations

  • Team Engineering, Global

Salary

Estimated Salary Rangehigh confidence

140,000 - 220,000 USD / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • Incident response coordination and escalationintermediate
  • Cloud security (AWS, GCP, hybrid environments)intermediate
  • EDR platforms for threat investigationintermediate
  • OSINT techniques and threat huntingintermediate
  • Detection-as-code and automation workflowsintermediate
  • Linux and macOS proficiencyintermediate
  • Risk-based security decision makingintermediate
  • Stakeholder communication and documentationintermediate
  • Post-incident review leadershipintermediate
  • Scripting (Python, Go)intermediate
  • Kubernetes/container securityintermediate
  • MITRE ATT&CK framework knowledgeintermediate
  • Collaborative problem-solvingintermediate
  • Fast-paced environment adaptabilityintermediate
  • Investigative mindsetintermediate

Required Qualifications

  • Demonstrable experience in incident response, security operations, and coordinating security events from detection through resolution (experience)
  • Strong knowledge of cloud security architectures, attack techniques, and hands-on experience with cloud providers (AWS, GCP, or Azure) (experience)
  • Extensive experience with endpoint detection and response (EDR) platforms for investigations, analysis, and response actions (experience)
  • Investigative mindset with ability to leverage OSINT techniques and solve ambiguous security problems with elegant solutions (experience)
  • Excellent documentation, communication, and stakeholder management skills while prioritizing multiple tasks in a dynamic environment (experience)
  • Understanding of security's organizational role with risk-based decision making in security operations (experience)
  • Comfortable working with Linux, macOS, and modern security tooling (experience)

Preferred Qualifications

  • Background in forensic acquisition and analysis, including maintaining chain of custody (experience)
  • Incident response experience in containerized and Kubernetes environments (experience)
  • Proficiency in scripting and programming languages (Python, Go, or similar) (experience)
  • Experience with security automation platforms and SOAR tools (experience)
  • Familiarity with detection-as-code practices and version control workflows (experience)

Responsibilities

  • Lead incident response coordination and act as escalation point for security incidents across Canva's cloud-native infrastructure, including on-call roster participation
  • Monitor and investigate security threats across AWS, GCP, and hybrid environments, proactively hunting for anomalous behavior and potential intrusions
  • Build and maintain detection rules, automation workflows, and response playbooks using detection-as-code methodologies
  • Develop tools and solutions for security incident alerting, management, and communication to prevent recurrence
  • Maintain comprehensive incident response documentation, lead post-incident reviews, and produce detailed incident reports
  • Champion security best practices across secure development, network security, and security operations
  • Collaborate with engineering teams to integrate security into Canva's innovative design-focused products
  • Apply risk-based decision making to protect Canva's global user base and creative ecosystem
  • Contribute to threat intelligence sharing and continuous improvement of detection capabilities
  • Mentor junior team members on incident response techniques and best practices

Benefits

  • general: Equity packages to share in Canva's success
  • general: Inclusive parental leave policy supporting all parents and carers
  • general: Annual Vibe & Thrive allowance for wellbeing, social connection, office setup, and more
  • general: Flexible leave options to recharge and support personal needs
  • general: Hybrid work model from Canva's vibrant London campus in Shoreditch
  • general: Delicious home-cooked meals from our Head Chef and collaborative workspaces
  • general: Opportunities for global impact in a design-first, innovative culture
  • general: Virtual interviews and inclusive hiring process with reasonable adjustments

Target Your Resume for "Senior Security Engineer - Incident Response" , Canva

Get personalized recommendations to optimize your resume specifically for Senior Security Engineer - Incident Response. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Senior Security Engineer - Incident Response" , Canva

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

CanvaDesignCountry London / United KingdomTeam EngineeringGlobalCountry London / United Kingdom

Answer 10 quick questions to check your fit for Senior Security Engineer - Incident Response @ Canva.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.