Cloud Security Control Lead
5 days ago
Cloud Security Control lead (Senior Manager)
See yourself in our team:
The Cyber Controls Chapter Area plays an important function within the Group Security division being responsible for designing and deploying effective cyber control capabilities and overseeing continuous improvement of the Group's cyber risk profile.
As an organisation with a large IT estate servicing millions of customers everyday, we need to ensure effective mitigations are in place to defend our assets against an ever-evolving cyber threat environment. The Control Lead Cloud Security is tasked with ensuring control capabilities are in place to identify security weaknesses and mitigate cyber threats to cloud-based asset classes (IaaS, PaaS, SaaS, containers) across the Group.
We support our people with the flexibility to balance where work is done with at least half your time each month connecting in office. We also have many other flexible working options available including changing start and finish times, part-time arrangements and job share to name a few. Talk to us about how these arrangements might work for you.
Do work that matters
- Working with the Cyber Controls Chapter Area Lead and collaborating with peer Control Leads, the Control Lead Cloud Security will focus on:
- Supporting Technology Crew Leads, Product Owners and Enterprise Architects in setting the control capability roadmap for cloud security, overseeing control operation, and delivery of control remediation to achieve target risk outcomes.
- Establishing and maintaining cloud security standards and guidelines to align with changes in industry standards, technology strategy and threat intelligence.
- Governing the Group's compliance with Cloud Security control requirements and supporting the business in tracking remediation of critical security weaknesses and improvement of overall risk posture.
- Carry out control effectiveness assessments, identify control weaknesses and drive appropriate risk remediation across business-owned cloud-based assets.
- Establish automated control performance monitoring capabilities to support cloud security assurance over business-aligned technology services.
We are interested in hearing from people who:
- Embody the leadership principle of 'Curious and Humble' by being willing to speak up and challenge the status quo, and continually expand their skills and knowledge.
- Have expertise in in Cloud governance
- Are knowledgeable about cyber threats and vulnerabilities relevant to cloud-based technologies.
- Can analyse threat intelligence, identify potential risks, prioritise vulnerabilities, and recommend appropriate mitigations (Identity & Access Management, Cryptography, Secure Configuration, Data Security, Vulnerability Management, CIEM, CNAPP, CSPM, SSPM).
- Have experience working with cloud security enterprise solutions and implementing security tools in large and complex IT environments.
- Can operate effectively in an agile working environment exemplifying high degrees of autonomy and self-initiative to achieve target outcomes.
- Have demonstrated ability to engage and influence stakeholders to build rapport, obtain buy-in and achieve target outcomes.
Desirable technical Skills :
- Understanding of hybrid and cloud-native environments (e.g. AWS, Azure) and how security controls apply to them.
- Applied knowledge of ASD ISM, NIST CSF, CIS and ACSC Essential Eight cyber mitigation strategies.
- Proficiency in SSPM, CSPM, CNAPP, CIEM.
- Experience with vulnerability prioritisation frameworks (e.g., CVSS, EPSS).
- Understanding of web application vulnerabilities (e.g., OWASP Top Ten).
- Security certifications: AWS/Azure security; CISSP, CISM.
Whether you're passionate about customer service, driven by data, or called by creativity, a career here is for you.
Our people bring their diverse backgrounds and unique perspectives to build a respectful, inclusive and flexible workplace. We are working hard to build a team of people who represent the rich diversity of our customers and communities. If you're excited about this opportunity but you don't meet every single requirement, or your experience doesn't align perfectly, we still want to encourage you to apply. You may just be the perfect candidate for this opportunity or another within CommBank.
At CommBank we will inspire you with work that makes a difference, surround you with talented people that respect and value each other, and empower you to grow professionally and personally. Most of all, making a positive impact for customers, communities and each other is part of our every day.
We're determined to make a real difference for Australia's first peoples. We encourage all interested applicants to apply. If you're already part of the Commonwealth Bank Group (including Bankwest), you'll need to apply through Sidekick to submit a valid application. We're keen to support you with the next step in your career.
-
Control Lead Security Posture Management
1 week ago
Eveleigh, New South Wales, Australia Commonwealth Bank – Technology Full time $120,000 - $180,000 per yearControl Lead Security Posture Management (Senior Manager) You are a cybersecurity risk and control professional with a background in Security Posture Management control design and implementation.We are one of the best and most advanced Cyber Security teams in AustraliaTogether we can build the Cyber Controls Chapter Area and contribute to protecting the...
-
Technology Product Owner
1 week ago
Eveleigh, New South Wales, Australia Commonwealth Bank – Technology Full time $90,000 - $120,000 per yearTechnology Product Owner - AI Operations & Resilience EngineeringAbout the Team The CIO for Technology team ensures CommBank has world-class engineering capability and is at the forefront of technology, using innovative and emerging technologies to help our customers and support our Group Strategy. Focused on innovation, best practices, and collaboration,...
-
Principal Site Reliability Engineer
21 hours ago
Eveleigh, New South Wales, Australia Commonwealth Bank Full time $120,000 - $180,000 per yearYou are passionate about SRE and systems engineeringWe are undergoing one of Australia's largest digital transformationsTogether we can reimagine banking for millions of customersDo work that mattersWe're accelerating our digital strategy with an ambition to provide customers with one of the best digital experiences of any company globally. Site Reliability...
-
Eveleigh, New South Wales, Australia Commonwealth Bank – Technology Full time $120,000 - $180,000 per yearSenior Manager Group Cyber Governance and ComplianceYou are a passionate cybersecurity risk professional with strong expertise in governance, risk and complianceWe are one of the best and most advanced Cyber Security teams in AustraliaTogether we can contribute to protecting the Group, its customers and community from current and evolving cyber threats.See...
-
Senior Software Engineer
1 week ago
Eveleigh, New South Wales, Australia Commonwealth Bank – Technology Full time $120,000 - $180,000 per yearSenior Software EngineerWe're embarking on an engineering transformation with a key focus in building robust, secure, and highly scalable services to our customers.You have knowledge that spans both development and operations, including coding, infrastructure management, system admin/engineering, and DevOps Toolchains.Together we will build tomorrow's bank...
-
Product Manager – Platform Migration
1 week ago
Eveleigh, New South Wales, Australia Bluefin Resources Pty Limited Full time $208,000 per yearContract Product Manager – Platform Migration12-month contract (strong likelyhood of extension) | $800/day + super | Sydney (hybrid) This role is ideal for a product manager who enjoys ambiguity early in the build lifecycle. The team is scoping a large-scale infrastructure migration to support a healthcare payments platform used by thousands of...
-
Senior Data Scientist
2 weeks ago
Eveleigh, New South Wales, Australia Commonwealth Bank - Retail Banking Services Full time $120,000 - $180,000 per yearDo work that mattersAs a Data Scientist within Home Buying, you will assist in the development, monitoring, implementation and management of AI and Machine Learning models supporting one of the largest Retail Banking divisions in Australia. From applying models and analytical techniques to better support decision management functions, to activating...
-
Manager - Technology Strategy
3 days ago
Eveleigh, New South Wales, Australia Commonwealth Bank - Group Strategic Development Full time $120,000 - $180,000 per yearDo work that matters: We are seeking a Manager, Technology Strategy to craft Board and ELT strategy papers, research emerging technology trends, frame strategic options, and influence senior decision‑making across the Group. The role reports to the Executive Manager, Technology Strategy, and partners closely with Group Strategy and strategy teams across...
-
Senior Product Manager, Digital Experiences
19 hours ago
Eveleigh, New South Wales, Australia Commonwealth Bank - Retail Banking Services Full time $120,000 - $180,000 per yearSenior Product Manager, Personalise and Controls, Digital ExperiencesYou are passionate about creating seamless, personalised digital experiences that customers love - giving them confidence, choice, control.You are curious and bring strong analytical and problem-solving skills, helping your squad successfully deliver new and innovative propositions to...
-
Research Leaders
3 days ago
Eveleigh, New South Wales, Australia Department of Defence Full time $120,000 - $180,000 per yearThe RoleWe are seeking highly motivated Innovation, Science and Technology (IS&T) leaders with a passion for delivering advanced and valued outcomes to Defence, and in accordance with the intent of the Defence Strategic Review. There are a number of positions available if you are looking for a new, exciting and challenging role. Each IS&T Leader is...