
Cloud Security Incident Response Senior Analyst
Commonwealth Bank of Australia
- Melbourne, VIC
- Permanent
- Full-time
- You are a problem solver with experience in cloud security, specialising across AWS and Azure services and solutions.
- We are one of the largest Cyber Security teams in the southern hemisphere.
- Together we will build tomorrow’s bank today, using world-leading engineering, technology, and innovation.
- Use cyber security tools to gather information and perform investigations within the Group’s public cloud environment.
- Determine best practice approaches for monitoring, undertaking incident response, and managing cyber control hygiene in the cloud.
- Document appropriate ways to detect, prevent, and isolate suspicious activity in the cloud.
- Assist the CDO team with any incident response and remediation activities related to cloud workloads.
- Conduct proactive cyber defensive assessments by referencing adversary tactics and offensive techniques to identify control gaps and validate defensive effectiveness against emerging threats.
- Review security controls in affected cloud environment(s) to identify gaps and provide input into post incident reporting.
- Assist the CEE team with ongoing reviews/uplift of the security posture in the public cloud environment.
- Research and evaluate emerging security technologies and trends, recommending implementations to enhance our security posture.
- Stay informed about the latest cybersecurity threats and vulnerabilities, and provide tactical and strategic recommendations to mitigate risks
- Experience in cybersecurity, with a focus in Incident Response and cloud Security.
- Demonstrated experience in incident response is essential.
- Expertise in AWS and/or Azure cloud security controls.
- Proven ability to conduct proactive cyber defensive assessments by referencing adversary tactics and offensive techniques to identify control gaps and validate defensive effectiveness against emerging threats.
- Demonstrated experience translating assessment outcomes into actionable improvements aligned to enterprise risk frameworks and adversary tactics.
- Experience applying industry frameworks (e.g., NIST CSF, MITRE ATT&CK) to defensive assessments.
- Strong stakeholder engagement skills to communicate findings and drive remediation outcomes.
- Bachelor’s degree in information technology, Cybersecurity, or a related field is preferred.
- Professional certifications such as CISSP, information security, information technology, risk management or equivalent discipline is highly desirable.
- Cloud Security Certifications such as AWS Certified Security Speciality is desirable.