Senior Platform Engineer

Summary

Senior Platform Engineer in CommBank's Perimeter Posture Management squad (Corporate Technology, Bangalore) focused on external attack surface management — using Assetnote to discover, investigate and triage internet-facing exposures across cloud, datacentre and web assets, with scripting, IaC and cloud-platform engineering to support security workflows.

Organization- At CommBank, we never lose sight of the role we play in delivering a brighter future for our customers and supporting our communities. Our focus is to help customers and communities move forward to progress. To make the right financial decisions and achieve their dreams, targets and aspirations. Regardless of where you work within our organization, your initiative, talent, ideas and energy all contribute to the impact that we can make with our work. Together we can build tomorrow’s bank today.

Job Title: Senior Platform Engineer

Location: Bangalore

Business & Team: Corporate Technology

Impact & Contribution

As a Senior Platform Engineer within the Perimeter Posture Management squad, you will help maintain visibility and understanding of the organisation's external attack surface across cloud, datacentre and internet-facing environments.

You will use attack surface management capabilities to identify and investigate externally visible assets, services, vulnerabilities and security exposures.

The role has a strong focus on security analysis and operational threat assessment determining what an exposure means, validating its security significance, assessing potential risk and providing clear security context to support appropriate action.

Your responsibilities

  • Use Assetnote or similar attack surface management technologies to discover, monitor and analyse internet-facing assets and exposures.

  • Investigate security findings to determine their validity, exploitability, exposure and potential security impact.

  • Apply security judgement and contextual analysis to distinguish meaningful risks from false positives, expected behaviour or low-value findings.

  • Analyse externally observable risks across domains, applications, services, network infrastructure and cloud-hosted assets.

  • Assess findings using available technical, asset and business context to support effective risk prioritisation.

  • Maintain and improve the accuracy of asset visibility, ownership information and external attack-surface data.

  • Provide clear security analysis and recommended actions to relevant technology and asset owners, and support findings through to appropriate closure where required.

  • Identify recurring exposure patterns, control gaps and changes in the external threat surface and provide insights to improve perimeter security posture.

  • Contribute to improvements in security monitoring, reporting, platform configuration and analytical workflows.

Your skills and experience

We are interested in hearing from candidates with strong cybersecurity analysis experience and a solid understanding of external attack surfaces. The role places particular emphasis on security analysis and threat assessment, supported by platform engineering and automation capabilities.

Essential – Security and attack-surface experience

  • Security analysis: Demonstrated experience investigating security exposures, vulnerabilities or externally observable risks and forming defensible security conclusions from technical evidence.

  • Attack surface management: Hands-on experience with external attack surface management, exposure management, vulnerability management or comparable security capabilities.

  • Security tooling: Experience using Assetnote or similar vulnerability or exposure-management platforms.

  • External exposure analysis: Strong understanding of internet-facing assets, services, ports, protocols, domains, subdomains, certificates and externally exposed applications.

  • Threat assessment: Ability to assess whether an identified exposure represents a credible security risk by considering exploitability, reachability, severity and available context.

  • Security inference: Ability to correlate information from multiple data sources and infer potential security risks where a finding may not provide the complete picture.

  • Vulnerability knowledge: Understanding of common web, infrastructure, network and cloud security vulnerabilities and misconfigurations.

  • Risk prioritisation: Ability to distinguish high-value security findings from noise and prioritise analysis based on likely security impact.

  • Cloud security understanding: Working knowledge of security concepts and common exposure patterns across AWS, Azure and GCP.

  • Stakeholder communication: Ability to clearly explain technical security findings, supporting evidence and recommended actions to engineering and technology teams.

Supporting engineering skills

Experience with the following technologies or equivalent tools and platforms would be beneficial:

  • Scripting and automation: Python, Bash or PowerShell

  • Cloud platforms: AWS, Azure or GCP

  • Infrastructure as Code: Terraform or CloudFormation

  • CI/CD: GitHub and GitHub Actions

  • Operating systems: Linux and Windows

  • Observability: Logs, dashboards, monitoring and alerting

  • Security integrations: APIs and automated security workflows

Education

Bachelor's or Master's degree in Computer Science, Engineering, Information Technology, Cybersecurity or a related discipline, or equivalent practical experience

If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 29/10/2026

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available