About the Role
You are a problem solver with deep expertise in cyber security engineering, security design, and technical risk. You bring a strong ability to translate complex threats into practical, scalable security controls embedded directly into engineering delivery. Commonwealth Bank's Cyber Security team is one of the most advanced in Australia, operating at scale across cloud, payments, and digital banking platforms, protecting the Group, its customers, and the broader community.
Responsibilities
- Provide security architecture and design guidance across the full SDLC, ensuring secure outcomes by design
- Lead threat modelling, security design reviews, and technical risk assessments, identifying threats, controls, and mitigation strategies
- Embed security into Devsecops and CI/CD pipelines, enabling teams to build and run secure services end-to-end
- Develop and promote security patterns, guardrails, and reusable controls to scale security across domains
- Partner with engineering, architecture, and product teams to uplift security maturity and influence design decisions
- Ensure solutions align with Group policies, security standards, and regulatory obligations, including control design and effectiveness
Requirements
- Strong experience across security engineering and architecture in large-scale, distributed environments
- Ability to influence and deliver secure solutions in modern engineering ecosystems
Skills
- Security architecture
- Threat modelling
- Secure design
- AI security
- Devsecops
- CI/CD security
- Modern engineering practices
- Scalable security controls
- Guardrails
- Cloud security (AWS and/or Azure)
Experience Level
- Senior
About the Company
- Commonwealth Bank's Cyber Security team is one of the most advanced in Australia, operating at scale across cloud, payments, and digital banking platforms.
- Cyber Security plays a critical role in protecting the Group from evolving cyber threats by embedding security into the design, build, and operation of all technology services.
- This is achieved by integrating security engineering into the full software development lifecycle and aligning to Group policies, standards, and regulatory obligations.
