About the Role
You are a highly skilled security engineer with deep expertise across cyber security engineering, security design, and secure software delivery. You will solve complex security challenges, influence technical direction, and build practical security solutions that scale across large, distributed environments. You will be part of the Security Engineering team, operating within a Secure by Design and DevSecOps model where security is embedded early and continuously across delivery.
Responsibilities
- Lead complex cyber risk assessments, evaluate control effectiveness, and provide risk-informed recommendations.
- Define and drive risk assessment approaches, security control standards, and decision frameworks.
- Lead the design and implementation of scalable security controls, guardrails, and automation.
- Solve complex security engineering challenges spanning application security, cloud security, DevSecOps, and secure platform design.
- Define and evolve reusable security patterns, standards, and engineering practices.
- Partner with engineers, architects, and technology leaders to influence technical decisions and deliver secure customer outcomes.
- Lead threat modelling, security design reviews, and technical risk assessments for complex initiatives.
- Champion Secure by Design principles by embedding security across the software development lifecycle.
- Act as a technical leader within the engineering community, mentoring engineers and uplifting security engineering capability.
- Balance security, customer outcomes, resilience, and delivery velocity when solving challenging engineering problems.
- Drive continuous improvement of security engineering practices, controls, and automation capabilities.
Requirements
- Deep expertise across security engineering, secure design, and technical risk management within large-scale distributed environments.
- Strong experience designing, implementing, and operating security controls embedded within modern engineering ecosystems.
- Advanced understanding of AI security, application security, DevSecOps, CI/CD security, and secure software delivery practices.
- Strong knowledge of cloud security across AWS and/or Azure environments.
- Experience defining and evolving security standards, patterns, guardrails, and reusable controls at scale.
- Proven ability to solve complex and ambiguous security engineering challenges through pragmatic, risk-informed decision making.
- Strong stakeholder engagement skills with the ability to influence engineers, architects, and technology leaders.
- A track record of driving engineering excellence and uplifting capability through technical leadership, mentoring, and coaching.
- Strong judgement and risk-based decision making in complex and ambiguous environments.
- Ability to articulate technical risk and control effectiveness to both technical and non-technical audiences.
- Strong system design, security architecture, and threat modelling expertise.
- End-to-end ownership of security outcomes.
- Deep technical problem-solving capability.
- Focus on secure software delivery, resilience, and engineering excellence.
- A passion for mentoring others and raising engineering standards.
- The ability to influence through expertise, collaboration, and technical leadership.
Skills
- Cyber security engineering
- Security design
- Secure software delivery
- AI security
- Application security
- Cloud security (AWS, Azure)
- DevSecOps
- CI/CD security
- Threat modelling
- Security architecture
- System design
- Risk management
- Stakeholder engagement
- Mentoring
- Coaching
Location
- Australia
Work Type
- Full-time
Experience Level
- Staff
About the Company
- Commonwealth Bank's Cyber Security team is one of the most advanced in Australia, operating at scale across cloud, payments, and digital banking platforms.
- Group Security is part of Technology and brings together security and resilience capabilities spanning cyber security, cyber defence, fraud technology, protective security, and business resilience.
- Our purpose is safeguarding a brighter future for all by securing the Bank, protecting customers, and delivering best-in-class security outcomes through governance, protection, detection, response, and recovery.
