Cyber Security Engineer
rushdigital
Auckland, Parnell, New Zealand
Posted Jun 4, 2026
- Full-time
- Remote
- Engineering
Job description
CYBER SECURITY ENGINEER At RUSH, we design, build, and manage purposeful digital experiences that improve people's lives. We're a team that takes pride in doing meaningful work, doing it well, and enjoying the ride, if that sounds like your kind of place, we'd love to hear from you. This Cyber Security Engineer role is RUSH's dedicated security resource for an exciting new project, responsible for both the build-time security posture of the solution and the ongoing operational security of the delivered system. Security Architecture and Design Contribute to threat modelling for the NAIT system at design and sprint planning stages, identifying security risks and defining mitigations aligned to OWASP and NIST SSDF frameworks. Design and configure the security layer of the RUSH Azure stack: Azure WAF (Application Gateway integrated), Azure Front Door, Microsoft Defender for Cloud, Azure Monitor SIEM, and Azure Key Vault for secrets and certificate management. Define and implement identity and access management patterns using Microsoft Entra ID B2C, AuthSignal MFA flows, SCIM provisioning, and OpenID Connect integration Specify RBAC and field-level permission models aligned to NAIT business roles, ensuring granular access control across all system domains. Ensure session management, token handling, and authentication flows meet NAIT NFR requirements including HTTP-only cookies, HTTPS-only transmission, idle timeout and server-side revocation. Security in the Delivery Pipeline Integrate and operate SAST and DAST tooling within the Azure DevOps CI/CD pipeline, ensuring automated security scanning on every build and immediate alerting on high-severity findings. Configure Wiz Cyber for continuous cloud security posture management across all NAIT Azure environments (development, staging, UAT, production), including misconfiguration detection, vulnerability scanning, and compliance drift alerting. Operate Vanta for continuous ISO 27001 and SOC 2 Type II compliance monitoring, automating evidence collection and maintaining real-time audit readiness dashboards Conduct or coordinate regular penetration testing and configuration reviews of the NAIT solution, producing evidence reports Manage file upload scanning for malicious content, ensuring all upload pathways are protected per NFR-059. Ensure all input validation controls are implemented and tested, covering SQL injection, XSS, and other OWASP Top 10 attack vectors across both client and server-side handling. Compliance, Audit and GRC Maintain RUSH's ISO 27001:2022 obligations as they apply to the NAIT programme, including information security controls, asset management and risk treatment for NAIT data assets. Ensure non-production environments holding NAIT data are protected with equivalent controls to production, or that data is appropriately anonymised Manage comprehensive audit logging requirements: infrastructure event logs (NFR-054), CRUD audit trails with user, timestamp, previous and new state (NFR-065), log export and long-term retention (NFR-055 to NFR-057). Support compliance statement obligations including and any applicable security architecture standards. Respond to vendor security questionnaires and coordinate evidence submissions for annual independent cybersecurity audits. Participate in regular security incident response exercises to maintain readiness Security Incident Management and Operations Operate RUSH's 24/7 security monitoring function for the NAIT system via Azure Monitor, Microsoft Defender for Cloud, and Wiz, ensuring real-time threat detection and alerting. Lead RUSH's response to NAIT security incidents and suspected or actual information security incidents within the timeframes and processes. Maintain and test the NAIT incident response runbook, ensuring the RUSH team can respond to P1 security incidents within the 15-minute SLA for critical issues. Manage privileged access controls including bastion host access, VPN, segregation of duties, and privileged device baseline standards Ensure DDoS and DoS protection is active and correctly configured across Azure Application Gateway and Azure Front Door Secure Development Advisory Provide secure development advisory to the RUSH engineering team throughout the programme, including code review guidance for security-sensitive components. Conduct regular security awareness touch points with the delivery team, ensuring OWASP and NIST SSDF principles are embedded in day-to-day engineering practice. Review and approve security-relevant architectural decisions before implementation, particularly around API authentication, authorisation flows, and integration points with external systems. Contribute to the Azure DevOps backlog with security-specific stories and acceptance criteria, ensuring security requirements are treated as first-class delivery items in every sprint. Skills & Competencies 5+ years of hands-on cyber security engineering experience in enterprise environments, with a strong focus on cloud security. Deep practical experience with Microsoft Azure security services: Microsoft Defender for Cloud, Azure Monitor and Log Analytics, Azure WAF, Azure Key Vault, Azure Front Door, and Microsoft Entra ID. Hands-on experience with Wiz or a comparable cloud security posture management platform (Prisma Cloud, Orca, etc.). Experience operating SAST and DAST tooling within CI/CD pipelines (e.g. SonarQube, Checkmarx, Burp Suite Enterprise, OWASP ZAP). Strong understanding of identity and access management: OAuth 2.0, OpenID Connect, SAML, SCIM, RBAC, and MFA flows. Demonstrated experience with ISO 27001, SOC 2, or equivalent compliance frameworks including evidence collection and audit preparation. Familiarity with OWASP Top 10, NIST SSDF, and their practical application in secure software development. Experience coordinating or conducting penetration testing engagements and managing findings through remediation. Demonstrated ability to lead or contribute to security incident response in a production environment. Why RUSH? You'll be working on meaningful, complex security challenges for collaborative work that makes a real difference. We're a team that takes pride in doing meaningful work, doing it well, and enjoying the ride, if that sounds like your kind of place, we'd love to hear from you.