Senior Security Engineer
Software Engineering
Sydney, NSW, Australia
This is a full-time role, with hybrid working 3 days per week in-office in Sydney (Surry Hills).
Everlab is an Australian healthtech startup building the platform to look after people’s health for their entire lives. It’s not just an app, it’s the infrastructure connecting every available healthcare service to give you comprehensive data on your health and provide personalised care.
We hold some of the most sensitive data there is: diagnostic radiology, pathology, and health records flowing through our ecosystem of partners and operational systems.
As we scale locally and globally, keeping that data safe, and being able to prove we keep it safe, is becoming one of our most important capabilities.
We’ve had a 23x increase in revenue since June 2025 & recently closed our $65m Series A round, making this an exciting time to join Everlab as we scale globally.
About the Role
This is a hands-on role for a Senior Security Engineer who will own Everlab’s security & compliance end to end to keep us & our data secure, and be able to prove it. You are the single owner of security here, so you will set the direction and then do the work yourself or alongside our Platform and IT teams.
Here are some examples of the types of projects you would work on:
Own the risk register: make it the single source of truth. Identify risks across the whole business and operational surface, assess and prioritise them by real business impact, and drive them to closure. For each material risk you recommend a path with clear trade-offs, favouring automation, process change and structural, preventative controls over adding headcount.
Do the hands-on security work: access reviews and least-privilege, SaaS, SSO and MFA configuration, cloud (GCP) and identity hardening, plus the tooling and lightweight automation that holds it together.
Drive cross-team fixes to completion: where a fix sits with engineering, platform or IT, you unblock it and verify it rather than handing it off and hoping.
Own compliance: drive our ISO 27001 and GDPR programs through Vanta, keep controls and evidence current, and get us audit-ready and certified.
Own the reactive surface: B2B vendor security questionnaires, procurement and third-party reviews, incident response, and security monitoring and alerting.
Scale the function without scaling headcount: direct AI tooling on real security work and automate the repeatable parts for things like annual audits.
What We're Looking For
Hands-on security engineer: around 5+ years of security experience as an individual contributor with a broad remit across internal IT security i.e. Google workplace through to Product security. Ideally in startup environments where you have built or scaled from earlier stages rather than inherit well established infrastructure and process
Strong risk judgment: you spot the risks that actually matter, prioritise by real business impact, and make defensible trade-off calls independently.
Compliance: Make sure we're GDPR, ISO 27001 and SOC 2 compliant and set up the automations to make documentation faster each time we need it
Experience securing a regulated, sensitive-data environment, ideally healthcare (PHI or health data) or another regulated domain such as finance.
Technical depth: exposure to cloud security (AWS/GCP), identity and access management, SaaS security, and application security fundamentals.
Structural thinker: a bias toward automation and preventative controls over throwing more people at the problem. You fix the shape of the system, not just the symptom.
Autonomous operator: you work independently and drive outcomes across teams. You own the chasing and the follow-through, and you enjoy that part of the job rather than tolerating it.
Works with AI: you use AI across your work to move faster, pointing tools at real problems and improving what comes back.
Incredible teammate: you communicate with kindness and enjoy the growth that comes from giving and receiving direct, honest feedback. You acknowledge your mistakes, know when to disagree and commit, and care more about the team being successful than you being right.
Owner: you take the responsibility of building in regulated healthcare seriously. Privacy and safety are not boxes to tick, they are the reason people trust us with their health data, and you are motivated by what's best for our customers long term.
Why It’s Great to Work at Everlab
Do work that matters: We're building the future of preventive health. Use your skills to prevent disease, improve access to personalised care, and reduce pressure on the health system.
Work-life flexibility: Hybrid working with 3 days in the office, plus flexibility to manage life beyond the 9 to 5 when it matters.
Experience Everlab as a customer: Full access to the Everlab health program, provided after successfully passing probation.
Share in our success: Employee Share Option Plan included as part of your total remuneration. We grow together.
People you'll love working with: A welcoming, mission-driven team of smart, thoughtful people doing meaningful work.