- Location
- Eveleigh, NSW - 5-7 Central Ave, Australia · Melbourne, VIC - 435 Bourke Street
- Workplace
- Onsite
- Type
- Full-time
- Department
- Management
- Seniority
- Manager
- Closing date
- Today
- Source
- Workday
Description
Control Manager, Vulnerability Management
Do you thrive at the intersection of cyber security, technology, and stakeholder engagement? Help drive vulnerability remediation, shape governance practices, and make a real impact across the organisation.
You are a cyber security, technology risk or controls professional with experience in vulnerability management, remediation governance and stakeholder engagement.
We are one of Australia’s leading cyber security teams, helping protect the Group, our customers and the community.
Together we can strengthen vulnerability management controls and improve remediation outcomes across a large, complex technology environment.
See yourself in our team:
The Cyber Controls Chapter Area sits within Group Security and is responsible for governing and continuously improving cyber control capabilities across the organisation.
As the Control Manager, Vulnerability Management, you will support the Control Lead in strengthening how vulnerability remediation is governed, measured and improved across the Group. You will work closely with technology teams, IT service owners and business stakeholders to help them understand their vulnerability posture, meet remediation expectations and address control gaps.
This is a governance and control-focused role. While familiarity with vulnerability scanning tools is useful, the primary focus is on remediation governance, control effectiveness, reporting, stakeholder engagement and continuous improvement.
We support our people with flexibility to balance where work is done, with at least half your time each month connecting in office. We also have flexible working options available, including changing start and finish times, part-time arrangements and job share. Talk to us about how these arrangements might work for you.
Do work that matters:
Working with the Control Lead Vulnerability Management, you will:
Support the ongoing management and continuous improvement of the Vulnerability Management Standard and related control requirements.
Govern vulnerability remediation activities by helping technology teams understand their vulnerability posture, remediation obligations and control compliance requirements.
Engage with IT service owners, technology domains and business units to support timely, risk-based remediation of vulnerabilities.
Assess and monitor control effectiveness, identify areas outside tolerance and work with stakeholders to understand root causes and improvement actions.
Develop and use dashboards, reporting and metrics to provide visibility of remediation compliance, control performance and security posture.
Assess and respond to ServiceNow (SNOW) requests relating to vulnerability management, including requests to exclude assets from scanning or defer vulnerabilities in line with policy requirements.
Support process improvement, assurance and audit activities through evidence gathering, control validation and continuous improvement initiatives.
We are interested in hearing from people who:
Have experience in cyber security, technology risk, vulnerability management, security operations, infrastructure, cloud, engineering or technology controls.
Understand vulnerability management concepts, including vulnerability identification, prioritisation, remediation governance and risk-based decision making.
Can confidently engage with technical stakeholders and constructively challenge assumptions around remediation timelines, risk acceptance and control compliance.
Are comfortable working with data, dashboards and reporting to identify trends, insights and areas requiring attention.
Bring a continuous improvement mindset and can help build practical, stable and scalable processes.
Are curious, humble and confident enough to speak up, challenge constructively and keep building their knowledge.
Technical skills that will benefit you in the role
Understanding of cyber security risk frameworks and guidance, including ASD Essential Eight, ASD ISM, NIST and related control frameworks.
Experience with vulnerability prioritisation and risk assessment, including frameworks such as CVSS and EPSS.
Familiarity with vulnerability scanning or exposure management tools such as Qualys, Wiz or Microsoft Defender.
Familiarity with patch management tools or processes, including Tanium or similar enterprise technologies.
Understanding of vulnerabilities across servers, endpoints, cloud environments, web applications and related technology platforms.
Experience in technology controls, cyber controls or risk governance will be highly regarded, but we are also open to candidates with strong technical cyber or technology backgrounds who can confidently engage with stakeholders.
Security certifications such as CISSP, CISM or CRISC are advantageous, but not mandatory.
If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.
We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.