- Location
- Perth, Australia · Brisbane
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Closing date
- Today
- Source
- Workday
Description
- Own and shape Application Security architecture, standards and services across Rio Tinto
- Lead our Secure SDLC standards and manage the Snyk application security capability
- Permanent full-time opportunity based in Perth or Brisbane, working with a practical and collaborative Cyber Architecture team
We're Finding Better Ways™ to provide materials the world needs, now and in the future. Our values - care, courage and curiosity - guide how we work and how we treat each other.
About the role
We are looking for a Principal Adviser - Cyber Security Architecture (AppSec) to lead the Application Security domain within Cyber Security. This role owns the strategy, standards, architecture and roadmap for secure software development and application security services across Rio Tinto.
You will work closely with Enterprise Architecture, software engineering, platform teams and business stakeholders to make security a practical part of how applications are designed, built, deployed and supported.
The role combines enterprise security architecture with hands-on ownership of key Application Security capabilities. It suits someone who can set direction, work directly with development teams, and turn security requirements into standards, patterns, tooling and practical guidance.
What you'll be doing
Reporting to the Manager of Cyber Security Architecture and working within the Cyber Architecture team, you will:
- Own the enterprise Application Security strategy, standards, reference architectures and service roadmap
- Lead and continually improve Secure SDLC, DevSecOps, threat modelling and secure application development practices.
- Work with development, architecture and platform teams to embed practical security requirements into engineering standards, delivery processes and CI/CD pipelines
- Own and support Application Security tooling and services, including Snyk and integrations with GitHub, Azure DevOps and Artifactory, working with vendors and internal teams to improve adoption and value
- Guide teams in identifying, prioritising and remediating application and dependency vulnerabilities, and improve the processes used to manage them
- Define reusable security patterns and requirements for applications, APIs, cloud-native workloads, containers, secrets and AI-enabled solutions
- Review solution designs for higher-risk initiatives, and provide clear security advice to projects and development teams
- Build strong relationships across Cyber, IS&T and the development community, mentor other architects and help lift Application Security capability across the organisation
About you
We're looking for someone with strong Application Security experience who can operate at an enterprise scale while remaining practical and approachable. You do not need to meet every 'helpful for success' item to apply. If you bring relevant experience and are interested in the opportunity, we encourage you to submit an application.
Required for Success
- A commitment to the safety of yourself and your team
- Strong experience in Application Security architecture, Secure SDLC, DevSecOps, threat modelling, vulnerability management and security-by-design
- Experience creating and embedding security standards, patterns and guidance across development teams in a large, complex organisation
- Proven experience owning or supporting Application Security platforms such as Snyk, including developer onboarding, platform integrations, service improvement and vulnerability remediation
- A practical communication style and the ability to build strong working relationships across Cyber, architecture, engineering, platform and business teams
- Relevant qualifications or certifications in cyber security, information security, software engineering or a related discipline, or equivalent practical experience
Helpful for Success
- Experience with GitHub, Azure DevOps, Artifactory, CI/CD security, API security, secrets management, container security or software supply chain security
- Experience supporting cloud-native and AI-enabled software development, including the security risks introduced by AI coding tools and AI-enabled applications
- Familiarity with frameworks and guidance such as OWASP, NIST, ISO 27001, CIISec or OFIA, and exposure to security architecture across identity, cloud, OT or infrastructure domains
What we offer
Be recognised for your contribution, your thinking and your hard work, and go home knowing you’ve helped the world progress.
- A work environment where safety is always the number one priority
- A permanent position working directly for Rio Tinto
- A competitive base salary reflective of your skills and experience with annual incentive program
- Comprehensive medical benefits including subsidised private health insurance for employees and immediate family
- Attractive share ownership plan
- Company provided insurance cover
- Extensive salary sacrifice & salary packaging options
- Career development & education assistance to further your technical or leadership ambitions
- Ongoing access to family-friendly health and medical wellbeing support
- Leave for all of life’s reasons (vacation/annual, paid parental, sick & cultural leave)
- Exclusive employee discounts (banking, accommodation, cars, retail and more)
Where you'll be working
IS&T
Information Systems and Technology (IS&T) is a global function delivering integrated and critical IT services and support to Rio Tinto’s mines, refineries, smelters, remote operations centres and corporate offices. IS&T’s mission is to power Rio Tinto’s pioneers with data and technology, enhancing safety, productivity, and value for the business. Through our collaborative partnerships and a deep understanding of our mining and metals business, IS&T carefully balances the implementation of ‘here and now’ solutions with emerging technologies that will help to create the digitally-optimised Rio Tinto of tomorrow.
About Rio Tinto
Rio Tinto is a leading global mining and materials company. We operate in 35 countries where we produce iron ore, copper, aluminium, critical minerals, and other materials needed for the global energy transition and for people, communities, and nations to thrive.
We have been mining for 150 years and operate with knowledge built up across generations and continents. Our purpose is finding better ways to provide the materials the world needs – striving for innovation and continuous improvement to produce materials with low emissions and to the right environmental, social and governance standards. But we can’t do it on our own, so we’re focused on creating partnerships to solve problems, create win-win situations and meet opportunities.
Respect and Inclusion
At Rio Tinto, we particularly welcome and encourage applications from Aboriginal and Torres Strait Islander people, women, the LGBTQ+ community, mature workers, people with disabilities and people from different cultural backgrounds.
We are committed to an inclusive environment where people feel comfortable to be themselves. We want our people to feel that all voices are heard, all cultures respected and that a variety of perspectives are not only welcome – they are essential to our success. We treat each other fairly and with dignity regardless of race, gender, nationality, ethnic origin, religion, age, sexual orientation or anything else that makes us different.