Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Principal Product Security Engineer

Home > Javascript/Typescript programming jobs

Principal Product Security Engineer in Australia new

  • Commonwealth Bank
  • Full time
  • Email
  • Melbourne

Responsibilities

  • Lead complex application security engagements across products, platforms, and engineering teams.
  • Perform advanced web application penetration testing and security assessments.
  • Conduct secure code reviews across modern technology stacks.
  • Partner with engineering, architecture, and product teams to embed secure-by-design principles.
  • Provide guidance on application security risks, remediation strategies, and security architecture decisions.
  • Lead threat modelling and proactive security risk mitigation during design and development.
  • Develop security tooling, automation, and AI-driven capabilities to improve assessment coverage and scalability.
  • Mentor engineers and security practitioners and uplift offensive security, application security, and secure development capabilities.
  • Contribute to product security standards, testing methodologies, secure coding practices, and security assurance processes.
  • Balance security risk, customer experience, operational resilience, and delivery objectives with stakeholders.

Requirements

  • Extensive experience in Application Security, Product Security, or Offensive Security focused on web application security.
  • Deep hands-on expertise in web application penetration testing, including authentication, authorization, business logic, API, and cloud-native vulnerabilities.
  • Strong secure code review capabilities across modern programming languages and frameworks.
  • Deep understanding of authentication and authorization mechanisms, web protocols, APIs, cloud-native architectures, and application security attack vectors.
  • Experience with threat modelling, architecture reviews, penetration testing, and security assessments throughout the software development lifecycle.
  • Strong understanding of secure software engineering principles, OWASP methodologies, and modern application security practices.
  • Ability to communicate complex technical risks clearly and influence engineering teams.
  • Experience with cloud platforms, CI/CD pipelines, DevSecOps practices, and infrastructure-as-code.
  • Experience using automation, scripting, AI, or security tooling to improve security effectiveness and scale assurance activities.
  • Strong stakeholder management skills across engineers, architects, product owners, and senior leaders.
  • Experience with Next.js, React, Node.js, Java, .NET, or Go applications is desirable.
  • Experience assessing GraphQL, REST APIs, microservices, and cloud-native applications is desirable.
  • Relevant certifications such as OSWE, OSEP, OSCP, GWAPT, GWEB, or CISSP are desirable.
  • Experience building or leading application security or product security programs within large organisations is desirable.

Commonwealth Bank

Commonwealth Bank of Australia is an ASX-listed bank headquartered in Sydney that provides retail, business, and institutional banking, payments, and wealth services across Australia. Its offerings include transaction and savings accounts, home and business lending, cards, merchant services, digi...

Similar positions

Founding Design Engineer

  • Clera
  • Full time
  • USA
  • 10/02/2026
  • Salary: $180k - $220k/yr
  • San Francisco, CA

Software Engineer

  • Smiths Group plc
  • Full time
  • Others
  • 10/02/2026
  • Bengaluru, India

Senior Software Engineer

  • Okta
  • Full time
  • Others
  • 10/02/2026
  • Bengaluru, India

Senior Software Engineer

  • Bellwood
  • Full time
  • USA
  • 10/02/2026
  • Salary: $105k-$125k
  • Remote

UX Engineering Intern (San Francisco)

  • Pinterest
  • Full time
  • USA
  • 10/02/2026
  • San Francisco, CA