Principal Product Security Engineer (Melbourne)

Principal Product Security Engineer (Melbourne)

17 Sep
|
Commonwealth Bank
|
Melbourne

17 Sep

Commonwealth Bank

Melbourne

Principal Product Security Engineer Influence security outcomes across Retail Banking technology at enterprise scale Drive innovation through AI, automation and secure-by-design engineering practices Mentor engineers and uplift application security capability across multiple technology domains Do work that matters: At CommBank, we're building tomorrow's bank today.
Technology is at the heart of everything we do and security is fundamental to providing safe, secure and trusted experiences for millions of customers.
We are seeking a Principal Product Security Engineer to join Group Security.
This is a highly influential role focused on improving how security is embedded across our software engineering practices, helping teams build secure products at speed while continuously uplifting security capability across the organisation.
You'll work across a broad range of Retail Banking portfolios, partnering with engineering teams, technology leaders and security specialists to drive practical security outcomes.
This is an prospect to shape the future direction of application security through innovation, automation and modern engineering practices.
See yourself in our team: Group Security safeguards a brighter future for all by securing the bank, protecting our customers and enabling technology teams to deliver safely at speed.
We partner across the organisation to embed security earlier in the development lifecycle and help teams build secure, resilient and trusted experiences for millions of customers.
As part of our Product Security capability, you will play a key role in strengthening secure engineering practices, reducing risk and driving the evolution of product security across Retail Banking technology portfolios.
On any given day, you will: Lead complex application security engagements across a diverse portfolio of products, platforms and engineering teams.
Perform advanced web application penetration testing and security assessments to identify and validate security vulnerabilities, attack paths and business risks.
Conduct in-depth secure code reviews across modern technology stacks, identifying vulnerabilities,



insecure design patterns and opportunities to strengthen security controls.
Partner with engineers, architects and product teams to embed secure-by-design principles throughout the software development lifecycle.
Provide expert guidance on application security risks, remediation strategies and security architecture decisions.
Drive threat modelling activities and help teams proactively identify and mitigate security risks during design and development.
Influence security outcomes across large-scale and complex engineering environments through strong technical leadership and stakeholder engagement.
Develop and enhance security tooling, automation and AI-driven capabilities to improve assessment coverage, efficiency and scalability.
Mentor engineers and security practitioners, helping uplift offensive security, application security and secure development capabilities across the organisation.
Contribute to the evolution of product security standards, testing methodologies, secure coding practices and security assurance processes.
Work closely with stakeholders to balance security risk, customer experience, operational resilience and delivery objectives.
We are interested in hearing from people who have: Extensive experience in Application Security, Product Security or Offensive Security, with a strong focus on web application security.
Deep hands-on expertise in web application penetration testing, including identification and exploitation of common and complex vulnerabilities such as authentication, authorization, business logic, API and cloud-native security weaknesses.
Strong secure code review capabilities across modern programming languages and frameworks,



with the ability to identify security vulnerabilities directly from source code.
Deep understanding of modern authentication and authorization mechanisms, web protocols, APIs, cloud-native architectures and common application security attack vectors.
Proven experience conducting threat modelling, architecture reviews, penetration testing and security assessments throughout the software development lifecycle.
Strong understanding of secure software engineering principles, OWASP methodologies and modern application security practices.
Demonstrated ability to communicate complex technical risks clearly and influence engineering teams to achieve effective security outcomes.
Experience working within modern engineering environments leveraging cloud platforms, CI/CD pipelines, DevSecOps practices and infrastructure-as-code.
A passion for mentoring others and driving a strong security culture across engineering organisations.
Experience leveraging automation, scripting, AI or security tooling to improve security effectiveness and scale security assurance activities.
Excellent stakeholder management skills with the ability to engage effectively with engineers, architects, product owners and senior leaders.
Nice to have Experience securing modern web frameworks such as Next.js, React, Node.js, Java, .
NET or Go based applications.
Experience assessing GraphQL, REST APIs, microservices and cloud-native applications.
Relevant industry certifications such as OSWE, OSEP, OSCP, GWAPT, GWEB, CISSP or equivalent.
Experience building or leading application security or product security programs within large organisations If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through to submit a valid application.
We're keen to support you with the next step in your career.
We're aware of some accessibility issues on this site, particularly for screen reader users.
We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on ************.
Advertising End Date: 01/10/2026

📌 Principal Product Security Engineer (Melbourne)
🏢 Commonwealth Bank
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: principal product security engineer (melbourne) / melbourne