Control Lead Cloud Security

1 week ago


Sydney, New South Wales, Australia Commonwealth Bank – Technology Full time $150,000 - $200,000 per year

Control Lead Cloud Security (Senior Manager)

  • Are you a cybersecurity risk and control professional with a background in cloud security control design and implementation?

  • We are one of the best and most advanced Cyber Security teams in Australia.

  • Together we can build the Cyber Controls Chapter Area and contribute to protecting the Group, its customers and community.

See yourself in our team:

The Cyber Controls Chapter Area plays an important function within the Group Security division being responsible for designing and deploying effective cyber control capabilities and overseeing continuous improvement of the Group's cyber risk profile.

As an organisation with a large IT estate servicing millions of customers everyday, we need to ensure effective mitigations are in place to defend our assets against an ever-evolving cyber threat environment. The Control Lead Cloud Security is tasked with ensuring control capabilities are in place to identify security weaknesses and mitigate cyber threats to cloud-based asset classes (IaaS, PaaS, SaaS, containers) across the Group.

We support our people with the flexibility to balance where work is done with at least half your time each month connecting in office. We also have many other flexible working options available including changing start and finish times, part-time arrangements and job share to name a few. Talk to us about how these arrangements might work for you.

Do work that matters

Working with the Cyber Controls Chapter Area Lead and collaborating with peer Control Leads, the Control Lead Cloud Security will focus on:

Supporting Technology Crew Leads, Product Owners and Enterprise Architects in setting the control capability roadmap for cloud security, overseeing control operation, and delivery of control remediation to achieve target risk outcomes.

Establishing and maintaining cloud security standards and guidelines to align with changes in industry standards, technology strategy and threat intelligence.

Governing the Group's compliance with Cloud Security control requirements and supporting the business in tracking remediation of critical security weaknesses and improvement of overall risk posture.

Carry out control effectiveness assessments, identify control weaknesses and drive appropriate risk remediation across business-owned cloud-based assets.

Establish automated control performance monitoring capabilities to support cloud security assurance over business-aligned technology services.

We are interested in hearing from people who:

  • Embody the leadership principle of 'Curious and Humble' by being willing to speak up and challenge the status quo, and continually expand their skills and knowledge.
  • Have experience in GRC with knowledge related to Cloud Security

  • Are knowledgeable about cyber threats and vulnerabilities relevant to cloud-based technologies.

  • Can analyse threat intelligence, identify potential risks, prioritise vulnerabilities, and recommend appropriate mitigations (Identity & Access Management, Cryptography, Secure Configuration, Data Security, Vulnerability Management, CIEM, CNAPP, CSPM, SSPM).

  • Have experience working with cloud security enterprise solutions and implementing security tools in large and complex IT environments.

  • Can operate effectively in an agile working environment exemplifying high degrees of autonomy and self-initiative to achieve target outcomes.

  • Have demonstrated ability to engage and influence stakeholders to build rapport, obtain buy-in and achieve target outcomes.

Desirable technical Skills :

  • Understanding of hybrid and cloud-native environments (e.g. AWS, Azure) and how security controls apply to them.

  • Applied knowledge of ASD ISM, NIST CSF, CIS and ACSC Essential Eight cyber mitigation strategies.

  • Proficiency in SSPM, CSPM, CNAPP, CIEM.

  • Experience with vulnerability prioritisation frameworks (e.g., CVSS, EPSS).

  • Understanding of web application vulnerabilities (e.g., OWASP Top Ten).

  • Security certifications: AWS/Azure security; CISSP, CISM.

Whether you're passionate about customer service, driven by data, or called by creativity, a career here is for you.

Our people bring their diverse backgrounds and unique perspectives to build a respectful, inclusive and flexible workplace. We are working hard to build a team of people who represent the rich diversity of our customers and communities. If you're excited about this opportunity but you don't meet every single requirement, or your experience doesn't align perfectly, we still want to encourage you to apply. You may just be the perfect candidate for this opportunity or another within CommBank.

At CommBank we will inspire you with work that makes a difference, surround you with talented people that respect and value each other, and empower you to grow professionally and personally. Most of all, making a positive impact for customers, communities and each other is part of our every day.

We're determined to make a real difference for Australia's first peoples. We encourage all interested applicants to apply. If you're already part of the Commonwealth Bank Group (including Bankwest), you'll need to apply through Sidekick to submit a valid application. We're keen to support you with the next step in your career.



  • Sydney, New South Wales, Australia Commonwealth Bank Full time

    This is a Control Lead Cloud Security role with Commonwealth Bank based in Sydney, NSW, AU == Commonwealth Bank ==Role Seniority - seniorMore about the Control Lead Cloud Security role at Commonwealth BankControl Lead Cloud Security (Senior Manager) Are you a cybersecurity risk and control professional with a background in cloud security control design and...


  • Sydney, New South Wales, Australia Commonwealth Bank Full time

    Cloud Security Control lead ( Senior Manager) Are you a cyber security risk and control professional with a background in cloud security control design and implementation ? We are one of the best and most advanced Cyber Security teams in Australia. Together we can build the Cyber Controls Chapter Area and contribute to protecting the Group, its customers and...


  • Sydney, New South Wales, Australia Commonwealth Bank Full time

    Cloud Security Control lead ( Senior Manager) Are you a cyber security risk and control professional with a background in cloud security control design and implementation ? We are one of the best and most advanced Cyber Security teams in Australia. Together we can build the Cyber Controls Chapter Area and contribute to protecting the Group, its customers and...

  • Cloud Security Lead

    5 days ago


    Sydney, New South Wales, Australia beBeeCloudSecurity Full time $190,000 - $230,000

    Our organisation is seeking a highly skilled Cyber Security professional to lead our cloud security team.The ideal candidate will have expertise in cloud security control design and implementation, as well as strong background in cloud governance and cyber threats relevant to cloud-based technologies.The successful candidate will support Technology Crew...


  • Sydney, New South Wales, Australia beBeeSecurity Full time $150,000 - $180,000

    Job Title: Lead Cloud Security Strategist">Job Description:">">Develop and implement cloud security strategies to protect company resources.">Conduct risk assessments, threat modelling, and vulnerability analysis across cloud platforms.">Implement and manage cloud-native security tools, particularly Prisma Cloud CNAPP.">Design and deploy automated security...


  • Sydney, New South Wales, Australia beBeeCybersecurity Full time $140,000 - $180,000

    Cloud Security Control Lead Job DescriptionThe Cloud Security Control Lead plays a critical role in designing and deploying effective cyber control capabilities across the organization. With a focus on protecting cloud-based assets, this role is responsible for ensuring that security weaknesses are identified and mitigated.Main Responsibilities:Support...


  • Sydney, New South Wales, Australia beBeeCloud Full time $180,000 - $250,000

    Cloud Security Lead PositionThe role of the Cloud Security Lead is to ensure effective security controls are implemented and maintained across cloud-based asset classes.About the JobAs a Cloud Security Lead, you will be responsible for identifying and mitigating cyber threats to cloud-based assets. This includes:Collaborating with technology teams to...


  • Sydney, New South Wales, Australia Bebeesecurity Full time

    Senior IAM and Cloud Security ExpertThis is an exciting opportunity to join a dynamic team shaping the future of cloud-native security.You will lead the design, implementation, and ongoing management of complex security solutions at scale while partnering closely with cross-functional teams to strengthen our security posture and streamline secure access...


  • Sydney, New South Wales, Australia beBeeCloudSecurity Full time $160,000 - $200,000

    Job Summary We are seeking a Senior Cloud Security Architect to lead the development and implementation of secure cloud solutions. This strategic role entails championing DevSecOps best practices, including CI/CD and Infrastructure as Code.Key ResponsibilitiesDevelop and implement secure cloud architecturesMaintain and enhance existing security controls and...


  • Sydney, New South Wales, Australia Cloud Careers At Mantel Group Full time

    **About us**Mantel Group is an Australian-owned technology consulting business with capabilities across Cloud, Digital, Data & Security. Since our inception in November 2017, we have experienced remarkable growth across Australia & New Zealand and are honoured to be recognised as a Great Place to Work for 4 years in a rowWe hire smart and talented people and...