Senior Product Security Engineer

Posted:
3/18/2025, 5:00:00 PM

Location(s):
Victoria, Australia ⋅ Sydney, New South Wales, Australia ⋅ New South Wales, Australia ⋅ Melbourne, Victoria, Australia

Experience Level(s):
Senior

Field(s):
IT & Security ⋅ Software Engineering

  • Work in one of the most advanced Cyber Security teams in Australia
  • Work across an extremely broad range of technologies, and many innovative projects and systems.
  • Supportive team environment, with a real focus on staff development and progression

 

Your role:

The Cyber Security Team (protects the bank and our customers from theft, losses and risk events, through effective and proactive management of cyber security, privacy and operational risk.

 

The Product Security Centre of Excellence (CoE) conducts simulated cyber-attacks to ensure systems are safe, sound, and secure.

 

The Product Security team performs security assessments of the Groups technology to ensure our applications and infrastructure are adequately robust to resist cyber-attacks. Our work seeks to identify security weaknesses in technology using real-world attack scenarios and provide recommendations to assist the remediation effort.

 

Do Work that Matters:

You will be responsible for technical penetration testing activities designed to ensure that the bank maintains its risk and security posture at desired levels. You will be responsible for communicating security issues to both technical and non-technical stakeholders. This role reports directly to a Penetration Testing Manager within the Penetration Testing team.

Your responsibilities:

  • Assist with performance of security assessments including (but not limited to) web application security testing, penetration testing & mobile security testing.
  • Assess and validate the security posture of bank systems, under the mentorship of senior team members.
  • Carry out scoping activities to identify what components of a given system require testing and to provide a likely effort required to carry out the testing
  • Report results of testing to our customers, including project managers, service owners, developers and risk managers
  • Have the flexibility to work on multiple projects as needed
  • Work within a team environment and across business units to complete associated tasks with exceptional results

 

What you will need to succeed:

  • An understanding of vulnerability identification or penetration testing processes and methodologies
  • Working knowledge of application security review and threat modelling
  • Experience in using penetration testing tools such as Burp Suite and Metasploit
  • Experience in programming across a variety of platforms

Your experience is ideally supported by one or more of the following qualifications:

  • Tertiary qualifications in Software Engineering, Computer Science, Cyber Security or another related discipline
  • Participation and membership of relevant industry associations

If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 05/04/2025

Commonwealth Bank Australia

Website: https://commbank.com.au/

Headquarter Location: Sydney, New South Wales, Australia

Employee Count: 10001+

Year Founded: 1911

Last Funding Type: Post-IPO Debt

Industries: Banking ⋅ Finance ⋅ Financial Services ⋅ Wealth Management