- Location
- Bangalore - Manyata Tech Park Road, India
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Education
- Master
- Closing date
- Today
- Source
- Workday
Description
Organization- At CommBank, we never lose sight of the role we play in delivering a brighter future for our customers and supporting our communities. Our focus is to help customers and communities move forward to progress. To make the right financial decisions and achieve their dreams, targets and aspirations. Regardless of where you work within our organization, your initiative, talent, ideas and energy all contribute to the impact that we can make with our work. Together we can build tomorrow’s bank today.
Job Title: Senior Platform Engineer
Location: Bangalore
Business & Team: Corporate Technology
Impact & Contribution
As a Senior Platform Engineer within the Perimeter Posture Management squad, you will help maintain visibility and understanding of the organisation's external attack surface across cloud, datacentre and internet-facing environments.
You will use attack surface management capabilities to identify and investigate externally visible assets, services, vulnerabilities and security exposures.
The role has a strong focus on security analysis and operational threat assessment determining what an exposure means, validating its security significance, assessing potential risk and providing clear security context to support appropriate action.
Your responsibilities
Use Assetnote or similar attack surface management technologies to discover, monitor and analyse internet-facing assets and exposures.
Investigate security findings to determine their validity, exploitability, exposure and potential security impact.
Apply security judgement and contextual analysis to distinguish meaningful risks from false positives, expected behaviour or low-value findings.
Analyse externally observable risks across domains, applications, services, network infrastructure and cloud-hosted assets.
Assess findings using available technical, asset and business context to support effective risk prioritisation.
Maintain and improve the accuracy of asset visibility, ownership information and external attack-surface data.
Provide clear security analysis and recommended actions to relevant technology and asset owners, and support findings through to appropriate closure where required.
Identify recurring exposure patterns, control gaps and changes in the external threat surface and provide insights to improve perimeter security posture.
Contribute to improvements in security monitoring, reporting, platform configuration and analytical workflows.
Your skills and experience
We are interested in hearing from candidates with strong cybersecurity analysis experience and a solid understanding of external attack surfaces. The role places particular emphasis on security analysis and threat assessment, supported by platform engineering and automation capabilities.
Essential – Security and attack-surface experience
Security analysis: Demonstrated experience investigating security exposures, vulnerabilities or externally observable risks and forming defensible security conclusions from technical evidence.
Attack surface management: Hands-on experience with external attack surface management, exposure management, vulnerability management or comparable security capabilities.
Security tooling: Experience using Assetnote or similar vulnerability or exposure-management platforms.
External exposure analysis: Strong understanding of internet-facing assets, services, ports, protocols, domains, subdomains, certificates and externally exposed applications.
Threat assessment: Ability to assess whether an identified exposure represents a credible security risk by considering exploitability, reachability, severity and available context.
Security inference: Ability to correlate information from multiple data sources and infer potential security risks where a finding may not provide the complete picture.
Vulnerability knowledge: Understanding of common web, infrastructure, network and cloud security vulnerabilities and misconfigurations.
Risk prioritisation: Ability to distinguish high-value security findings from noise and prioritise analysis based on likely security impact.
Cloud security understanding: Working knowledge of security concepts and common exposure patterns across AWS, Azure and GCP.
Stakeholder communication: Ability to clearly explain technical security findings, supporting evidence and recommended actions to engineering and technology teams.
Supporting engineering skills
Experience with the following technologies or equivalent tools and platforms would be beneficial:
Scripting and automation: Python, Bash or PowerShell
Cloud platforms: AWS, Azure or GCP
Infrastructure as Code: Terraform or CloudFormation
CI/CD: GitHub and GitHub Actions
Operating systems: Linux and Windows
Observability: Logs, dashboards, monitoring and alerting
Security integrations: APIs and automated security workflows
Education
Bachelor's or Master's degree in Computer Science, Engineering, Information Technology, Cybersecurity or a related discipline, or equivalent practical experience
If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.
We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.