Senior Secure Configuration Specialist

Posted:
7/29/2026, 2:20:52 PM

Location(s):
Victoria, Australia ⋅ Sydney, New South Wales, Australia ⋅ New South Wales, Australia ⋅ Melbourne, Victoria, Australia

Experience Level(s):
Senior

Field(s):
IT & Security

Workplace Type:
On-site

Senior Secure Configuration Specialist

  • Strengthen cyber security outcomes across SaaS, API, cloud and on-premises technology environments

  • Influence risk reduction and remediation activities across one of Australia’s largest technology ecosystems

  • Join a team investing in emerging security capabilities and security posture technologies

 

Do work that matters

As a Senior Secure Configuration Specialist, you'll play a key role in maturing secure configuration management capabilities across the Group. You'll partner with engineering, platform, technology and cyber security teams to strengthen security controls, improve configuration compliance and reduce cyber risk.

You'll help maintain and evolve secure configuration standards, drive remediation outcomes, and provide expertise across a growing suite of security posture technologies covering servers, workstations, cloud platforms, containers, SaaS applications and APIs.

See yourself in our team

Group Security is part of Technology and brings together security and resilience capabilities spanning cyber security, protective security and business resilience, fraud technology and operations, and cyber defence.

Within Group Security Technology, you'll join a team focused on secure configuration management, vulnerability management and security engineering outcomes. Working across a complex technology landscape, you'll collaborate with stakeholders to uplift security posture, strengthen governance practices and reduce cyber risk at scale.

In this role you will:

  • Maintain and continuously improve the Secure Configuration Management Standard, ensuring alignment with organisational security policies, regulatory obligations and industry best practice.

  • Assess and monitor secure configuration controls, identifying opportunities to strengthen control effectiveness and support remediation activities.

  • Provide subject matter expertise across security posture management technologies, supporting configuration governance across servers, workstations, APIs, SaaS platforms, containers and cloud environments.

  • Drive risk reduction initiatives by identifying configuration-related security exposures, assessing impact and partnering with stakeholders to prioritise remediation activities.

  • Develop and maintain reporting, metrics and insights that provide visibility of configuration compliance, control health and security posture.

  • Partner with technology, engineering, platform and cyber security teams to promote secure-by-default configuration practices and improve security outcomes.

  • Build and maintain strong stakeholder relationships across technology, risk, audit and business teams.

  • Support assurance, audit and regulatory activities through evidence gathering, control validation and continuous improvement initiatives.

We're interested in hearing from people who:

  • Have experience in cyber security, secure configuration management, vulnerability management or a related security discipline.

  • Have worked with security scanning, posture management or exposure management technologies such as Qualys, Wiz, Obsidian, NoName, or similar platforms.

  • Possess strong knowledge of cloud, SaaS, API, infrastructure or container technologies and the application of security controls within these environments.

  • Have demonstrated success influencing stakeholders and driving remediation outcomes across complex technology environments.

  • Understand security controls, governance frameworks, risk management and assurance practices.

  • Can analyse security findings, assess risk and translate technical issues into practical remediation actions.

  • Have experience using workflow and ticketing platforms such as ServiceNow.

  • Bring strong communication, stakeholder engagement and relationship management capabilities.

Working with us:

At CommBank, we're committed to creating an accessible, inclusive and respectful workplace. If you require support or adjustments, please let us know. We welcome applications from people of all backgrounds and we're particularly committed to making a positive difference for Aboriginal and/or Torres Strait Islander Peoples.

For support please contact 1800 989 696.

If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 12/08/2026

Commonwealth Bank Australia

Website: https://commbank.com.au/

Headquarter Location: Sydney, New South Wales, Australia

Employee Count: 10001+

Year Founded: 1911

IPO Status: Public

Last Funding Type: Post-IPO Debt

Industries: Banking ⋅ Finance ⋅ Financial Services ⋅ Wealth Management