← Back to Jobs
Full time
Technology
Senior Security Engineer
GetcheddarAustralia🇦🇺AustraliaPosted 7 Aug 2026
Quick Overview
Work Type
Hybrid
Schedule
Full Time
Level
Mid Senior
Job Description
x15ventures operates in the space between corporate and startup. We help build and scale digital ventures, giving teams the freedom to move quickly while maintaining the security, safety and resilience expected of businesses connected to CommBank.
Our Security team is small, agile and cross-functional. We work across x15 and its portfolio of ventures, partnering with product and engineering teams to understand their risks and build practical security controls into their technology and ways of working.
Where do you fit?
As a Senior Security Engineer, you will help design, build and improve security capabilities across x15 and its ventures.
This is a hands-on engineering role with a strong focus on DevSecOps, cloud security, identity and automation. You will work closely with software engineers, platform teams and venture leaders to embed security into delivery pipelines, cloud environments and day-to-day engineering practices.
You will independently lead complex security engineering work, make sound technical decisions and take ownership of outcomes through to implementation. You will also mentor other engineers, contribute to technical standards and help lift security capability across the broader x15 community.
We are looking for someone who can move comfortably between building technical solutions and providing practical advice. You will need to understand the risk, explain why it matters and then help teams implement a solution that works in their environment.
In this role, you will
DevSecOps and secure delivery
Partner with engineering teams to embed security controls throughout the software development lifecycle.
Design and implement security capabilities within CI/CD pipelines, including code, dependency, secrets, container and infrastructure-as-code scanning.
Help teams interpret security findings, prioritise material issues and remediate vulnerabilities without creating unnecessary delivery friction.
Develop reusable pipeline components, guardrails and secure engineering patterns that can be adopted across multiple ventures.
Implement policy-as-code and automated compliance checks where these provide a practical and reliable alternative to manual review.
Contribute to secure coding practices, threat modelling and technical security reviews for new products, services and material changes.
Design, implement and improve security controls across AWS and Azure environments.
Review cloud architectures and configurations, identifying risks relating to identity, networking, data protection, logging, workload security and resilience.
Help ventures implement secure cloud foundations and preventative guardrails using infrastructure as code and native cloud capabilities.
Improve visibility of cloud security posture, vulnerabilities, misconfigurations and emerging threats.
Work with engineering teams to secure containers, serverless workloads, APIs, data platforms and other cloud-native services.
Support the implementation and tuning of capabilities such as AWS CloudTrail, GuardDuty, Security Hub, Config and Azure Policy, Defender for Cloud and related services.
Identity and Microsoft security
Help design and improve identity and access controls using Microsoft Entra ID and associated identity governance capabilities.
Implement and review controls including Conditional Access, Privileged Identity Management, access reviews, workload identities, application registrations and enterprise application permissions.
Support the secure integration of cloud services, software-as-a-service platforms and venture applications with x15's identity environment.
Configure, integrate and improve capabilities across the Microsoft Defender suite, including Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud.
Investigate security alerts and work with relevant teams to improve detection quality, coverage and automated response.
Automation and security operations
Build automation that reduces repetitive security work and enables the small Security team to operate effectively across multiple ventures.
Develop scripts, integrations and workflows using languages and tools such as Python, PowerShell, APIs, serverless functions and workflow automation platforms.
Automate security monitoring, evidence collection, vulnerability management, control validation and response activities where appropriate.
Contribute to detection engineering, security monitoring and incident response across cloud, identity, endpoint and application environments.
Support the investigation of security incidents and help identify root causes and longer-term control improvements.
Ensure security automation is reliable, observable, maintainable and supported by appropriate documentation and operational ownership.
Advisory and venture partnership
Provide practical security advice to venture product, engineering and leadership teams.
Translate technical vulnerabilities and security risks into clear business and customer impacts.
Recommend proportionate controls that consider the nature of the risk, venture maturity, customer experience and delivery constraints.
Conduct technical security assessments and support ventures to develop prioritised remediation plans.
Constructively challenge designs or decisions where material security risks have not been adequately addressed.
Work with CommBank security and technology teams where ventures rely on Group platforms, services or security capabilities.
Technical leadership and mentoring
Mentor security engineers and other technical team members through pairing, design reviews, technical discussions and constructive feedback.
Help software and platform engineers build their security knowledge and take greater ownership of security within their teams.
Contribute to security engineering standards, patterns, playbooks and technical roadmaps.
Share lessons, tools and reusable solutions across the venture portfolio.
Model strong engineering practices, including testing, documentation, peer review, observability and maintainable design.
Contribute to a collaborative team environment where people are comfortable asking questions, challenging assumptions and learning from mistakes.
We are interested in hearing from people who have
Strong hands-on experience in security engineering, cloud security, DevSecOps or a closely related discipline.
Experience designing and implementing security controls within modern software delivery pipelines.
Strong cloud security experience across AWS and Azure, with deep technical capability in at least one of these platforms.
Practical experience securing cloud identity and access management, networking, workloads, data, logging and monitoring.
Experience using infrastructure-as-code technologies such as Terraform, CloudFormation or Bicep.
Experience with CI/CD platforms such as GitHub Actions, Azure DevOps, GitLab CI or similar technologies.
Experience implementing security testing within delivery pipelines, such as static analysis, software composition analysis, secrets scanning, container scanning and infrastructure-as-code scanning.
Practical knowledge of Microsoft Entra ID, including Conditional Access, privileged access, workload identities and application integrations.
Experience with Microsoft Defender products, particularly Defender XDR, Defender for Endpoint or Defender for Cloud.
Strong automation and scripting capability using Python, PowerShell or another suitable language.
The ability to review technical designs, identify material security risks and propose realistic solutions.
Experience supporting vulnerability management, security monitoring or incident response activities.
Strong written and verbal communication skills, including the ability to explain technical issues clearly to both engineering and non-technical audiences.
Experience mentoring engineers and supporting the technical development of others.
The ability to work independently, manage competing priorities and operate effectively in a small team supporting several businesses.
A practical mindset and the judgement to distinguish between controls that materially reduce risk and controls that primarily add process.
Useful, but not essential
Experience with Microsoft Sentinel, security orchestration and automated response.
Experience building custom detections using Kusto Query Language or similar query languages.
Experience with cloud security posture management, cloud workload protection or application security posture management platforms.
Experience securing Kubernetes, container platforms, serverless applications and API-based architectures.
Familiarity with identity protocols such as OAuth 2.0, OpenID Connect and SAML.
Experience with GitHub Advanced Security, Microsoft Defender for DevOps or similar developer security tooling.
Knowledge of secure software development frameworks and standards such as the NIST Secure Software Development Framework, OWASP and the ACSC Information Security Manual.
Familiarity with the ACSC Essential Eight, NIST Cybersecurity Framework or other commonly used security frameworks.
Experience working in financial services, fintech, regulated technology environments or businesses handling sensitive customer information.
Experience working in startup . click apply for full job details
Our Security team is small, agile and cross-functional. We work across x15 and its portfolio of ventures, partnering with product and engineering teams to understand their risks and build practical security controls into their technology and ways of working.
Where do you fit?
As a Senior Security Engineer, you will help design, build and improve security capabilities across x15 and its ventures.
This is a hands-on engineering role with a strong focus on DevSecOps, cloud security, identity and automation. You will work closely with software engineers, platform teams and venture leaders to embed security into delivery pipelines, cloud environments and day-to-day engineering practices.
You will independently lead complex security engineering work, make sound technical decisions and take ownership of outcomes through to implementation. You will also mentor other engineers, contribute to technical standards and help lift security capability across the broader x15 community.
We are looking for someone who can move comfortably between building technical solutions and providing practical advice. You will need to understand the risk, explain why it matters and then help teams implement a solution that works in their environment.
In this role, you will
DevSecOps and secure delivery
Partner with engineering teams to embed security controls throughout the software development lifecycle.
Design and implement security capabilities within CI/CD pipelines, including code, dependency, secrets, container and infrastructure-as-code scanning.
Help teams interpret security findings, prioritise material issues and remediate vulnerabilities without creating unnecessary delivery friction.
Develop reusable pipeline components, guardrails and secure engineering patterns that can be adopted across multiple ventures.
Implement policy-as-code and automated compliance checks where these provide a practical and reliable alternative to manual review.
Contribute to secure coding practices, threat modelling and technical security reviews for new products, services and material changes.
Design, implement and improve security controls across AWS and Azure environments.
Review cloud architectures and configurations, identifying risks relating to identity, networking, data protection, logging, workload security and resilience.
Help ventures implement secure cloud foundations and preventative guardrails using infrastructure as code and native cloud capabilities.
Improve visibility of cloud security posture, vulnerabilities, misconfigurations and emerging threats.
Work with engineering teams to secure containers, serverless workloads, APIs, data platforms and other cloud-native services.
Support the implementation and tuning of capabilities such as AWS CloudTrail, GuardDuty, Security Hub, Config and Azure Policy, Defender for Cloud and related services.
Identity and Microsoft security
Help design and improve identity and access controls using Microsoft Entra ID and associated identity governance capabilities.
Implement and review controls including Conditional Access, Privileged Identity Management, access reviews, workload identities, application registrations and enterprise application permissions.
Support the secure integration of cloud services, software-as-a-service platforms and venture applications with x15's identity environment.
Configure, integrate and improve capabilities across the Microsoft Defender suite, including Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud.
Investigate security alerts and work with relevant teams to improve detection quality, coverage and automated response.
Automation and security operations
Build automation that reduces repetitive security work and enables the small Security team to operate effectively across multiple ventures.
Develop scripts, integrations and workflows using languages and tools such as Python, PowerShell, APIs, serverless functions and workflow automation platforms.
Automate security monitoring, evidence collection, vulnerability management, control validation and response activities where appropriate.
Contribute to detection engineering, security monitoring and incident response across cloud, identity, endpoint and application environments.
Support the investigation of security incidents and help identify root causes and longer-term control improvements.
Ensure security automation is reliable, observable, maintainable and supported by appropriate documentation and operational ownership.
Advisory and venture partnership
Provide practical security advice to venture product, engineering and leadership teams.
Translate technical vulnerabilities and security risks into clear business and customer impacts.
Recommend proportionate controls that consider the nature of the risk, venture maturity, customer experience and delivery constraints.
Conduct technical security assessments and support ventures to develop prioritised remediation plans.
Constructively challenge designs or decisions where material security risks have not been adequately addressed.
Work with CommBank security and technology teams where ventures rely on Group platforms, services or security capabilities.
Technical leadership and mentoring
Mentor security engineers and other technical team members through pairing, design reviews, technical discussions and constructive feedback.
Help software and platform engineers build their security knowledge and take greater ownership of security within their teams.
Contribute to security engineering standards, patterns, playbooks and technical roadmaps.
Share lessons, tools and reusable solutions across the venture portfolio.
Model strong engineering practices, including testing, documentation, peer review, observability and maintainable design.
Contribute to a collaborative team environment where people are comfortable asking questions, challenging assumptions and learning from mistakes.
We are interested in hearing from people who have
Strong hands-on experience in security engineering, cloud security, DevSecOps or a closely related discipline.
Experience designing and implementing security controls within modern software delivery pipelines.
Strong cloud security experience across AWS and Azure, with deep technical capability in at least one of these platforms.
Practical experience securing cloud identity and access management, networking, workloads, data, logging and monitoring.
Experience using infrastructure-as-code technologies such as Terraform, CloudFormation or Bicep.
Experience with CI/CD platforms such as GitHub Actions, Azure DevOps, GitLab CI or similar technologies.
Experience implementing security testing within delivery pipelines, such as static analysis, software composition analysis, secrets scanning, container scanning and infrastructure-as-code scanning.
Practical knowledge of Microsoft Entra ID, including Conditional Access, privileged access, workload identities and application integrations.
Experience with Microsoft Defender products, particularly Defender XDR, Defender for Endpoint or Defender for Cloud.
Strong automation and scripting capability using Python, PowerShell or another suitable language.
The ability to review technical designs, identify material security risks and propose realistic solutions.
Experience supporting vulnerability management, security monitoring or incident response activities.
Strong written and verbal communication skills, including the ability to explain technical issues clearly to both engineering and non-technical audiences.
Experience mentoring engineers and supporting the technical development of others.
The ability to work independently, manage competing priorities and operate effectively in a small team supporting several businesses.
A practical mindset and the judgement to distinguish between controls that materially reduce risk and controls that primarily add process.
Useful, but not essential
Experience with Microsoft Sentinel, security orchestration and automated response.
Experience building custom detections using Kusto Query Language or similar query languages.
Experience with cloud security posture management, cloud workload protection or application security posture management platforms.
Experience securing Kubernetes, container platforms, serverless applications and API-based architectures.
Familiarity with identity protocols such as OAuth 2.0, OpenID Connect and SAML.
Experience with GitHub Advanced Security, Microsoft Defender for DevOps or similar developer security tooling.
Knowledge of secure software development frameworks and standards such as the NIST Secure Software Development Framework, OWASP and the ACSC Information Security Manual.
Familiarity with the ACSC Essential Eight, NIST Cybersecurity Framework or other commonly used security frameworks.
Experience working in financial services, fintech, regulated technology environments or businesses handling sensitive customer information.
Experience working in startup . click apply for full job details
Skills
AWS
OAuth
OWASP
SAML
Agile
Azure
CloudFormation
GitHub Actions
GitLab CI
Kubernetes
PowerShell
Python
Terraform
Similar jobs
Senior Cyber Security Engineer (Splunk/TS) - USSOCOM EDAT Zero T with Security Clearance
Kentro · Tampa, United States
24 minutes agoCyber Security Specialist (Apprentice) - 302939 with Security Clearance
DNI Delaware Nation Industries · Aiken, United States
24 minutes agoCyber Engineer II with Security Clearance
Everfox · Herndon, United States
24 minutes agoSECURITY STRATEGY ANALYST with Security Clearance
Department of Defense · pentagon arlington, United States
24 minutes agoISSO/Information Assurance Security Specialist with Security Clearance
Agile Defense, Inc. · Quantico, United States
24 minutes ago$120k - $125k/yr(Technical Targeter - General) Cyber Technical Analyst Principal with Security Clearance
GCI · Chantilly, United States
24 minutes ago$124.1k/yr