Senior Security Engineer, x15ventures at Commonwealth Bank | Sydney | Rezi

Senior Security Engineer, x15ventures at Commonwealth Bank

Senior Security Engineer, x15ventures

Commonwealth Bank · Sydney

Today

Senior Security Engineer, x15ventures

Commonwealth Bank · Sydney

4 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

As a Senior Security Engineer, you will help design, build, and improve security capabilities across x15 and its ventures. This is a hands-on engineering role with a strong focus on DevSecOps, cloud security, identity, and automation. You will work closely with software engineers, platform teams, and venture leaders to embed security into delivery pipelines, cloud environments, and day-to-day engineering practices. You will independently lead complex security engineering work, make sound technical decisions, and take ownership of outcomes through to implementation. You will also mentor other engineers, contribute to technical standards, and help lift security capability across the broader x15 community.

Responsibilities

  • Partner with engineering teams to embed security controls throughout the software development lifecycle.
  • Design and implement security capabilities within CI/CD pipelines, including code, dependency, secrets, container, and infrastructure-as-code scanning.
  • Help teams interpret security findings, prioritize material issues, and remediate vulnerabilities without creating unnecessary delivery friction.
  • Develop reusable pipeline components, guardrails, and secure engineering patterns that can be adopted across multiple ventures.
  • Implement policy-as-code and automated compliance checks where these provide a practical and reliable alternative to manual review.
  • Contribute to secure coding practices, threat modeling, and technical security reviews for new products, services, and material changes.
  • Design, implement, and improve security controls across AWS and Azure environments.
  • Review cloud architectures and configurations, identifying risks relating to identity, networking, data protection, logging, workload security, and resilience.
  • Help ventures implement secure cloud foundations and preventative guardrails using infrastructure as code and native cloud capabilities.
  • Improve visibility of cloud security posture, vulnerabilities, misconfigurations, and emerging threats.
  • Work with engineering teams to secure containers, serverless workloads, APIs, data platforms, and other cloud-native services.
  • Support the implementation and tuning of capabilities such as AWS CloudTrail, GuardDuty, Security Hub, Config, and Azure Policy, Defender for Cloud, and related services.
  • Help design and improve identity and access controls using Microsoft Entra ID and associated identity governance capabilities.
  • Implement and review controls including Conditional Access, Privileged Identity Management, access reviews, workload identities, application registrations, and enterprise application permissions.
  • Support the secure integration of cloud services, software-as-a-service platforms, and venture applications with x15’s identity environment.
  • Configure, integrate, and improve capabilities across the Microsoft Defender suite, including Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud.
  • Investigate security alerts and work with relevant teams to improve detection quality, coverage, and automated response.
  • Build automation that reduces repetitive security work and enables the small Security team to operate effectively across multiple ventures.
  • Develop scripts, integrations, and workflows using languages and tools such as Python, PowerShell, APIs, serverless functions, and workflow automation platforms.
  • Automate security monitoring, evidence collection, vulnerability management, control validation, and response activities where appropriate.
  • Contribute to detection engineering, security monitoring, and incident response across cloud, identity, endpoint, and application environments.
  • Support the investigation of security incidents and help identify root causes and longer-term control improvements.
  • Ensure security automation is reliable, observable, maintainable, and supported by appropriate documentation and operational ownership.
  • Provide practical security advice to venture product, engineering, and leadership teams.
  • Translate technical vulnerabilities and security risks into clear business and customer impacts.
  • Recommend proportionate controls that consider the nature of the risk, venture maturity, customer experience, and delivery constraints.
  • Conduct technical security assessments and support ventures to develop prioritized remediation plans.
  • Constructively challenge designs or decisions where material security risks have not been adequately addressed.
  • Work with CommBank security and technology teams where ventures rely on Group platforms, services, or security capabilities.
  • Mentor security engineers and other technical team members through pairing, design reviews, technical discussions, and constructive feedback.
  • Help software and platform engineers build their security knowledge and take greater ownership of security within their teams.
  • Contribute to security engineering standards, patterns, playbooks, and technical roadmaps.
  • Share lessons, tools, and reusable solutions across the venture portfolio.
  • Model strong engineering practices, including testing, documentation, peer review, observability, and maintainable design.
  • Contribute to a collaborative team environment where people are comfortable asking questions, challenging assumptions, and learning from mistakes.

Requirements

  • Strong hands-on experience in security engineering, cloud security, DevSecOps, or a closely related discipline.
  • Experience designing and implementing security controls within modern software delivery pipelines.
  • Strong cloud security experience across AWS and Azure, with deep technical capability in at least one of these platforms.
  • Practical experience securing cloud identity and access management, networking, workloads, data, logging, and monitoring.
  • Experience using infrastructure-as-code technologies such as Terraform, CloudFormation, or Bicep.
  • Experience with CI/CD platforms such as GitHub Actions, Azure DevOps, GitLab CI, or similar technologies.
  • Experience implementing security testing within delivery pipelines, such as static analysis, software composition analysis, secrets scanning, container scanning, and infrastructure-as-code scanning.
  • Practical knowledge of Microsoft Entra ID, including Conditional Access, privileged access, workload identities, and application integrations.
  • Experience with Microsoft Defender products, particularly Defender XDR, Defender for Endpoint, or Defender for Cloud.
  • Strong automation and scripting capability using Python, PowerShell, or another suitable language.
  • The ability to review technical designs, identify material security risks, and propose realistic solutions.
  • Experience supporting vulnerability management, security monitoring, or incident response activities.
  • Strong written and verbal communication skills, including the ability to explain technical issues clearly to both engineering and non-technical audiences.
  • Experience mentoring engineers and supporting the technical development of others.
  • The ability to work independently, manage competing priorities, and operate effectively in a small team supporting several businesses.
  • A practical mindset and the judgment to distinguish between controls that materially reduce risk and controls that primarily add process.

Skills

  • DevSecOps
  • Cloud Security
  • Identity and Access Management
  • Automation
  • AWS
  • Azure
  • Infrastructure as Code (Terraform, CloudFormation, Bicep)
  • CI/CD (GitHub Actions, Azure DevOps, GitLab CI)
  • Security Testing (SAST, SCA, Secrets Scanning, Container Scanning, IaC Scanning)
  • Microsoft Entra ID
  • Microsoft Defender Suite (XDR, Endpoint, Cloud)
  • Python
  • PowerShell
  • Vulnerability Management
  • Security Monitoring
  • Incident Response
  • Technical Mentoring

Location

  • Remote

Work Type

  • Full-time

Experience Level

  • Senior

About the Company

  • x15ventures operates in the space between corporate and startup, helping build and scale digital ventures by giving teams the freedom to move quickly while maintaining the security, safety, and resilience expected of businesses connected to CommBank.
  • Our Security team is small, agile, and cross-functional, working across x15 and its portfolio of ventures to partner with product and engineering teams, understand risks, and build practical security controls into their technology and ways of working.