remote
Executive Manager - Product Security - Commonwealth Bank of Australia
Software Engineer
Lead the Product Security function, embedding security across the product lifecycle with a federated model, driving strategy, governance, and culture to deliver secure, innovative products at scale.
About the role
Key Responsibilities
- Define and execute the Product Security strategy, ensuring security is integrated from ideation to retirement across all product lines.
- Lead a federated operating model, coordinating Product Security Centres of Excellence and embedded chapters within business divisions.
- Establish and maintain security standards, governance frameworks, and risk management processes that align with industry best practices.
- Drive threat modeling, security architecture reviews, and secure design workshops to mitigate risks early in the development cycle.
- Collaborate with engineering, product, and operations teams to embed DevSecOps practices and automate security controls.
- Report on security posture, metrics, and continuous improvement initiatives to executive leadership.
Requirements
- 10+ years of experience in product security, secure software development, or related fields.
- Deep knowledge of secure SDLC, threat modeling, and security architecture principles.
- Proven ability to build and lead cross‑functional security teams in a federated environment.
- Strong understanding of governance, risk management, and compliance frameworks.
- Excellent communication skills, capable of influencing senior stakeholders and driving cultural change.
Skills
penetration testing