Senior Security Engineer
Organization: At CommBank, we never lose sight of the role we play in other people’s financial wellbeing. Our focus is to help people and businesses move forward to progress. To make the right financial decisions and achieve their dreams, targets, and aspirations. Regardless of where you work within our organisation, your initiative, talent, ideas, and energy all contribute to the impact
Job Title: Senior Security Engineer
Location: Bangalore
Business & Team:
The Technology division delivers the group’s information technology and banking operation functions to ensure the highest levels of customer service through world-class process excellence and technology innovation. Group Security protects the bank and our customers from theft, loss, and risk events through effective and proactive management of cyber security, privacy and operational risk.
At CommBank we believe in working somewhere that works for you. We have many flexible working options available so talk to us about which arrangements could work best for you.
The Secure Build & Deploy team, a part of the wider Cyber Security team, partners closely with our wider engineering teams to govern and build DevSecOps automated security controls and capabilities. This includes:
- Application Security: Code scanning capabilities (e.g. GitHub Advanced Security, Snyk), including related policies and procedures, reporting and support, to allow developers to self-identify security issues in the SDLC.
- Tooling & Automation: Develop and embed security tooling and capabilities into pipelines and the SDLC.
Impact & Contribution:
As a Security Engineer, you will work with our software engineering teams, control owners and security tooling teams to:
- Improve the design and operating effectiveness of the Application Security control
- Design and develop secure coding resources and guidelines
- Maintain strategies and roadmaps for DevSecOps automated security tooling and capabilities (e.g. SAST, DAST, pipeline security)
- Liaise with Security Champions in software delivery teams to increase adoption of and support them in utilising secure coding practices and tooling.
- This role reports directly to the Secure Build & Deploy COE Team Lea
Roles & Responsibilities:
- Work with software development teams to ensure application security requirements are addressed and understood throughout the SDLC.
- Develop policies, guidelines, procedures and control documentation
- Develop and/or support DevSecOps automated secure code tooling:
- Embed application security tools into CI/CD pipelines
- Use or operate static, dynamic analysis and other software security tools
- Identify and triage false positives and false negatives from automated tools
- Work with development teams to resolve issues identified by application security tools
- Report results of application security initiatives to our stakeholders, including leadership, product management, risk and engineering colleagues
- Work within a team environment and across business units to complete associated tasks with exceptional results
Undertake any other tasks assigned by your manager that you have the capability to perform safely. (NOTE: All tasks assigned and carried out must be performed in accordance with all relevant internal Bank policies and external regulatory requirements).
Essential Skills:
- 8-12 years of experience in Security Engineering with strong expertise in Secure Software Development.
- Expert knowledge of application security and software security concepts and frameworks (e.g. OWASP & NIST SSDF)
- Experience with CI/CD and DevSecOps practices – essential
- Experience in using or application security tools (e.g. Snyk, GitHub Advanced Security) – desirable
- Coding/programming (e.g. Python) - desirable
- Ability to consult with business and technical representatives and to balance security and business requirements
- Strong written communication skills
- Risk mindset and understanding of risk management principles
- Your experience is ideally supported by one or more of the following qualifications:
- Relevant industry certifications, such as CSSLP
- Tertiary qualifications in Software Engineering, Computer Science, Cyber Security or another related discipline
- Participation and membership of relevant industry associations
Education Qualification:
Bachelor’s degree or master’s degree in engineering in Computer Science/Information Technology
If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.
We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.