AppSec Jobs
← Back to all jobs

Australia Post

Senior Manager, Enterprise Security Architect

Cremorne, Victoria, AustraliaWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About Australia Post

Australia Post, officially known as the Australian Postal Corporation, is a government-owned enterprise that provides postal and parcel services across Australia and internationally. Established in 1809, it has evolved from colonial postal systems to a modern logistics provider, operating over 4,342 post offices and more than 77,500 Parcel Locker compartments nationwide. The company processes over 2.2 billion mail items annually and handles record volumes of parcels, including 40 million in December 2024 alone. Australia Post supports 256,000 small businesses through its MyPost Business service and offers international delivery to 214 countries. It has embraced digital innovations such as online postage and parcel tracking, with significant customer engagement reflected in 918 million digital visits in FY25. With a workforce of over 64,000, Australia Post is committed to serving individuals, businesses, and government bodies throughout Australia.

Industry

consumer services

Employees

63,000

297 engineers

Revenue

$6.2B

Website

Visit →

Security at Australia Post

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Australia Post's Application Security philosophy centers on enabling development teams to deliver solutions 'quickly and securely' by embedding controls directly into the software development lifecycle.
  • The mission is to partner with squads to perform threat modeling and operate security tooling within CI/CD pipelines.
  • Their risk philosophy is evidenced by recommending specific security protocols like TLS 1.2+ for API integrations to ensure data integrity.

Security Team

  • The Application Security team sits within the broader Cyber Defence team.
  • The leadership emphasizes a people-centric approach, with CISO Adam Cartwright noting that staff are highly engaged and aware of community obligations.
  • As of March 2026, there is at least one active recruitment effort for an Application Security Specialist.

Key Initiatives

  • Active initiatives include a Responsible Disclosure Program where security issues are reported via a dedicated email address.
  • The team is focused on 'shifting left' by implementing and operating AppSec tooling within CI/CD pipelines and partnering with development squads for threat modeling.
  • They commit to addressing reported issues in a 'timely fashion'.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.