Staff Security Engineer

Bangalore - Manyata Tech Park Road, India

Commonwealth Bank

CommBank offers personal banking, business solutions, institutional banking, company information, and more

View all jobs at Commonwealth Bank

Apply now Apply later

Organization: At CommBank, we never lose sight of the role we play in other people’s financial wellbeing. Our focus is to help people and businesses move forward to progress. To make the right financial decisions and achieve their dreams, targets, and aspirations. Regardless of where you work within our organisation, your initiative, talent, ideas, and energy all contribute to the impact that we can make with our work. Together we can achieve great things.

Job Title: : Staff Security Engineer

Location: Bangalore

Business & Team:

We're building tomorrow’s bank today, which means we need creative and diverse engineers to help us redefine what customers expect from a bank. Envisioning new technologies that are still waiting to be invented and reimagining products that support our customers and help build Australia’s future economy.

CommBank is recognised as leading the industry in IT and operations with its world-class platforms and processes, agile IT infrastructure, and innovation in everything from payments to internet banking and mobile apps. Cyber Security protects the bank and our customers from theft, losses and risk events, through effective and proactive management of cyber security, privacy and operational risk.

The CBA technology unit delivers the best digital banking services to Commonwealth Bank customers and to do so is responsible for digital delivery, group data and analytics, technology and technology infrastructure, cyber, fraud, physical security and business resilience for all divisions across CBA. It is also dedicated to delivering the best workplace technology experience for our over 53.000 people across CBA and focused on providing the latest tools, technology, and resources to enhance the way we work together and empower our people to achieve more for our customers.

The Security Engineering team protects the group and our customers from theft, loss and risk events, through effective and proactive management of cyber security, privacy and operational risk.

Impact & Contribution:

  • Designing and implementing secure solutions that align with group security policies, standards, and reference architecture.
  • Work on threat modelling and can interpret and understand key cyber controls across the Group.
  • Identify security requirements, qualify threats to design the IT systems and build countermeasures to minimise cyber risks.
  • Collaborating with cross-functional teams to drive security outcomes throughout the design, build, and run phases of product development
  • Supporting the adoption of modern scalable and high-velocity security practices, including Secure By Design, DevSecOps, and Automation
  • Contributing to the continuous innovation and re-engineering of existing security engineering practices, including the development of practice strategies, patterns, and processes
  • Staying up-to-date with the evolving technology landscape and providing expert guidance on security engineering best practices
  • Supporting the response to high-profile security incidents, technology strategy and selection, and automation of security services

Roles & Responsibilities:

  • Provide deep technical hands-on Experience in security engineering, with a focus on design, strategy and implementation of secure solutions.
  • Have strong understanding of security policies, standards, and reference architecture, and expertise in threat modelling, threat detection, control mapping, vulnerability analysis and control engineering risk identification.
  • Are experienced in designing and building reusable security patterns and or solutions.

Essential Skills:

  • 12+ years of experience in security engineering
  • Hold extensive experience in security implementation e.g IAM, Network and cryptography controls etc.
  • Have experience with secure by design, DevSecOps, and automation practices.
  • Are experienced in designing and implementing modern deployment initiatives such as microservices, web applications, APIs, containerisation, event driven, mobile applications and integration platforms.
  • Have a bachelor's degree in Computer Science, Information Security, or a related field.
  • Experience with Secure by Design, DevSecOps, and Automation practices
  • Familiarity with Australian financial industry regulations and standards, such as the Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC)
  • Familiarity with containerization and orchestration tools, such as Docker and Kubernetes
  • Experience with security testing and vulnerability assessment tools, such as OWASP ZAP or Burp Suite
  • Familiarity with compliance frameworks, such as PCI-DSS or HIPAA

Education Qualification:

  • Bachelor’s degree or master’s degree in engineering in Computer Science/Information Technology

If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 30/01/2025
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Agile Analytics APIs Automation Banking Burp Suite Compliance Computer Science Cryptography DevSecOps Docker HIPAA IAM IT infrastructure Kubernetes Microservices OWASP Privacy Strategy Threat detection

Perks/benefits: Career development Team events

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.