Staff Security Engineer
Bangalore - Manyata Tech Park Road, India
Commonwealth Bank
CommBank offers personal banking, business solutions, institutional banking, company information, and moreOrganization: At CommBank, we never lose sight of the role we play in other people’s financial wellbeing. Our focus is to help people and businesses move forward to progress. To make the right financial decisions and achieve their dreams, targets, and aspirations. Regardless of where you work within our organisation, your initiative, talent, ideas, and energy all contribute to the impact that we can make with our work. Together we can achieve great things.
Job Title: : Staff Security Engineer
Location: Bangalore
Business & Team:
We're building tomorrow’s bank today, which means we need creative and diverse engineers to help us redefine what customers expect from a bank. Envisioning new technologies that are still waiting to be invented and reimagining products that support our customers and help build Australia’s future economy.
CommBank is recognised as leading the industry in IT and operations with its world-class platforms and processes, agile IT infrastructure, and innovation in everything from payments to internet banking and mobile apps. Cyber Security protects the bank and our customers from theft, losses and risk events, through effective and proactive management of cyber security, privacy and operational risk.
The CBA technology unit delivers the best digital banking services to Commonwealth Bank customers and to do so is responsible for digital delivery, group data and analytics, technology and technology infrastructure, cyber, fraud, physical security and business resilience for all divisions across CBA. It is also dedicated to delivering the best workplace technology experience for our over 53.000 people across CBA and focused on providing the latest tools, technology, and resources to enhance the way we work together and empower our people to achieve more for our customers.
The Security Engineering team protects the group and our customers from theft, loss and risk events, through effective and proactive management of cyber security, privacy and operational risk.
Impact & Contribution:
- Designing and implementing secure solutions that align with group security policies, standards, and reference architecture.
- Work on threat modelling and can interpret and understand key cyber controls across the Group.
- Identify security requirements, qualify threats to design the IT systems and build countermeasures to minimise cyber risks.
- Collaborating with cross-functional teams to drive security outcomes throughout the design, build, and run phases of product development
- Supporting the adoption of modern scalable and high-velocity security practices, including Secure By Design, DevSecOps, and Automation
- Contributing to the continuous innovation and re-engineering of existing security engineering practices, including the development of practice strategies, patterns, and processes
- Staying up-to-date with the evolving technology landscape and providing expert guidance on security engineering best practices
- Supporting the response to high-profile security incidents, technology strategy and selection, and automation of security services
Roles & Responsibilities:
- Provide deep technical hands-on Experience in security engineering, with a focus on design, strategy and implementation of secure solutions.
- Have strong understanding of security policies, standards, and reference architecture, and expertise in threat modelling, threat detection, control mapping, vulnerability analysis and control engineering risk identification.
- Are experienced in designing and building reusable security patterns and or solutions.
Essential Skills:
- 12+ years of experience in security engineering.
- Have experience with secure by design, DevSecOps, and Security automation (SAST, DAST, IAST) practices.
- Are experienced in designing and implementing enterprise Security Guidelines and Practices
- should have hands on experience in developing code , doing secure code Review , Threat modelling.
- Should have hands on experience securing Docker , Container and kubernitess.
- Experience with penetration testing and vulnerability assessment , and tool like OWASP ZAP or Burp Suite
- Familiarity with compliance frameworks, such as PCI-DSS or HIPAA
- Experience with AI/ML frameworks, libraries, and tools, such as TensorFlow, PyTorch, or Keras .
- Familiarity with Australian financial industry regulations and standards, such as the Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC)
Education Qualification:
- Bachelor’s degree or master’s degree in engineering in Computer Science/Information Technology
If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.
We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.
Advertising End Date: 29/05/2025* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Analytics Automation Banking Burp Suite Compliance Computer Science DAST DevSecOps Docker HIPAA IAST IT infrastructure OWASP Pentesting Privacy SAST Strategy Threat detection
Perks/benefits: Career development Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.