Job description
Job Description
Join the team redefining how the world experiences design.
Hey, hello, hiya, g’day, mabuhay, kia ora, 你好, hallo, vítejte!
Thanks for stopping by. We know job hunting can be a little time consuming and you’re probably keen to find out what’s on offer, so we’ll get straight to the point.
Where and how you can work
Our flagship campus is in Sydney. We also have a campus in Melbourne and co-working spaces in Brisbane, Perth and Adelaide. But you have choice in where and how you work. That means if you want to do your thing in the office (if you’re near one), at home or a bit of both, it’s up to you.
What you’d be doing in this role
As Canva scales change continues to be part of our DNA. But we like to think that’s all part of the fun. So this will give you the flavour of the type of things you’ll be working on when you start, but this will likely evolve.
At the moment, this role is focused on:
You’ll partner with teams across Canva to drive improvements to Canva’s technology control environment.
You’ll drive multi-team projects to meet Canva’s new technology and information security compliance obligations.
You’ll organise and facilitate Canva’s internal and external technology audits and control testing processes.
You’ll empower business decisions by clearly articulating technology and security risks.
You’ll drive efficiency improvements that reduce the manual effort involved in risk management and compliance activities.
You’ll build a culture of risk and compliance literacy across diverse stakeholders.
You’ll actively contribute to team responsibilities and other parts of Canva’s technology risk and information security management system.
You’re probably a match if
You bring at least 5 years of experience in technology risk and compliance, including hands-on controls testing, audit facilitation, and control design discussions.
You have practical knowledge of key industry standards such as ISO 27001, SOC 2, and PCI DSS, and ideally exposure to SOX or FedRAMP frameworks.
You understand the technical foundations of SaaS - cloud infrastructure, CI/CD, and identity systems- well enough to engage meaningfully with engineering teams.
You thrive in cross-functional environments, working effectively with diverse stakeholders at all levels.
You’re a strong communicator with sharp attention to detail and a mindset for continuous improvement.
You’re comfortable leveraging tools like Jira, Confluence, and ideally, continuous control monitoring platforms like Anecdotes.
You have hands-on experience using AI in your work to drive greater impact
About the Group/Team
The Security Group is responsible for protecting Canva’s systems and data from information security threats. Our teams work together, and with other groups, to deliver preventive and detective controls and processes that reduce security risk. The group runs programs across Identity and Access Management, Application Security, Risk Management, and Threat Detection and Response domains.
The Technology Risk & Compliance team oversees the identification and management of technology risks across Canva while maintaining compliance with applicable laws and industry frameworks. We work with stakeholders at all levels and from all corners of Canva to identify and assess risks to Canva’s technology operations, information assets and the information that our customers have entrusted to us.
About the Role/Specialty
As a Senior Technology Risk & Compliance Analyst, you’ll be involved in a range of risk management and compliance activities, including driving new certification / attestation projects, organising and facilitating internal and external audits, disseminating risk information to stakeholders across Canva, and contributing in general across all aspects of Canva’s technology risk management.
What’s in it for you?
Achieving our crazy big goals motivates us to work hard - and we do - but you’ll experience lots of moments of magic, connectivity and fun woven throughout life at Canva, too. We also offer a stack of benefits to set you up for every success in and outside of work.
Here’s a taste of what’s on offer:
Equity packages - we want our success to be yours too
Inclusive parental leave policy that supports all parents & carers
An annual Vibe & Thrive allowance to support your wellbeing, social connection, office setup & more
Flexible leave options that empower you to be a force for good, take time to recharge and supports you personally
Check out lifeatcanva.com for more info.
Other stuff to know
We see AI as a powerful amplifier of creativity and technology at Canva.We’re evolving how we assess AI skills in our Technology hiring experience - you’ll tackle interactive, real-time challenges that reflect the kind of work we do. In some interviews, you may also be asked to solve a problem using an AI tool to show how you approach challenges with tech by your side. Your recruitment partner will walk you through what to expect.We make hiring decisions based on your experience, skills and passion, as well as how you can enhance Canva and our culture.
When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.
We celebrate all types of skills and backgrounds at Canva so even if you don’t feel like your skills quite match what’s listed above - we still want to hear from you!
Please note that interviews are conducted virtually.