Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Cloud security control lead

Sydney
Commonwealth Bank
Posted: 24 August
Offer description

Cloud Security Control lead ( Senior Manager)

1. Are you a cyber security risk and control professional with a background in cloud security control design and implementation ?

2. We are one of the best and most advanced Cyber Security teams in Australia.

* Together we can build the Cyber Controls Chapter Area and contribute to protecting the Group, its customers and community.

See yourself in our team:
The Cyber Controls Chapter Area plays an important function within the Group Security division being responsible for designing and deploying effective cyber control capabilities and overseeing continuous improvement of the Group's cyber risk p rofile .

As an organisation with a large IT estate servicing millions of customers everyday, we need to ensure effective mitigations are in place to defend our assets against an ever- evolving cyber threat environment. The Control Lead Cloud Security is tasked with ensur ing control capabilities are in place to identify security weaknesses and mitigate cyber threats to cloud -based asset classes (IaaS, PaaS, SaaS, containers ) across the Group .

We support our people with the flexibility to balance where work is done with at least half your time each month connecting in office. We also have many other flexible working options available including changing start and finish times, part-time arrangements and job share to name a few. Talk to us about how these arrangements might work for you.

Do work that matters
Working with the Cyber Controls Chapter Area Lead and collaborat ing with peer Control Leads, t he Control Lead Cloud Security will focus on :

Supporting Technology Crew Leads, Product Owners and Enterprise Architects in setting the control capability roadmap for c loud s ecurity, oversee ing control operation, and delivery of control remediation to achieve target risk outcomes .

Establis hing and maintaining cloud security standards and guidelines to align with changes i n industry standards, technology strategy and threat intelligence .

Governing the Group's compliance with Cloud Security control requirements and supp orting the business in track ing remediation of critical security weaknesses and improvement of overall risk posture .

Carry out control effectiveness assessments, identify control weaknesses and drive appropriate risk remediation across business-owned cloud-based assets .

Establish automated control performance monitoring capabilit ies to support cloud security assurance over business-aligned technology services .

We are interested in hearing from people who :

3. Embody the leadership principle of 'Curious and Humble' by being willing to speak up and challeng e the status quo, and continually expand their skills and knowledge.

4. Have expertise in in Cloud governance

5. Are knowledgeable about cyber threats and vulnerabilities relevant to cloud-based technologies .

6. Can analyse threat intelligence, identify potential risks, prioritis e vulnerabilities, and recommend appropriate mitigations ( Identity & Access Management, Cryptography, Secure Configuration, Data Security, Vulnerability Management, CIEM, CNAPP, CSPM, SSPM ) .

7. Have experience working with c loud s ecurity enterprise solutions and implementing security tools in large and complex IT environments.

8. Can operat e effectively in an agile working environment exemplifying high degrees of autonomy and self-initiative to achieve target outcomes.

* Have demonstrated ability to engage and influence stakeholders to build rapport, obtain buy- in and achieve target outcomes.

Desirable technical Skills :

9. Understanding of hybrid and cloud-native environments (e.g. AWS, Azure ) and how security controls apply to them.

10. Applied knowledge of ASD ISM, NIST CSF, CIS and ACSC Essential Eight cyber mitigation strategies.

11. Proficiency in SSPM, CSPM, CNAPP, CIEM .

12. Experience with vulnerability prioritisation frameworks (e.g., CVSS, EPSS).

13. Understanding of web application vulnerabilities (e.g., OWASP Top Ten).

* Security certifications: AWS/Azure security; CISSP, CISM .

If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We're keen to support you with the next step in your career.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 03/09/2025
#J-18808-Ljbffr

Send an application
Create a job alert
Alert activated
Saved
Save
Similar job
Senior product manager, everyday accounts (chapter lead)
Sydney
Commonwealth Bank
Product Manager
Similar job
Senior data scientist - gen ai & agentic ai
Sydney
Commonwealth Bank
Data Scientist
Similar job
Analyst/manager – group mergers and acquisitions
Sydney
Commonwealth Bank
Similar jobs
Commonwealth Bank recruitment
Commonwealth Bank jobs in Sydney
jobs Sydney
jobs New South Wales
Home > Jobs > Cloud Security Control Lead

About Jobstralia

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by job title
  • Jobs by sector
  • Jobs by company
  • Jobs by location

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2025 Jobstralia - All Rights Reserved

Send an application
Create a job alert
Alert activated
Saved
Save