Cyber Generalist Manager

Commonwealth Bank

Bengaluru

On-site

INR 1,800,000 - 3,000,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Commonwealth Bank in Bengaluru (Manyata Tech Park) is seeking a Cyber Generalist Manager to lead vulnerability management governance and remediation programs. You will collaborate with security technology teams, IT service owners, and business units to strengthen remediation practices, promote policy compliance, and drive continuous improvement across the cyber controls landscape.

The role emphasizes governance, reporting, and proactive risk-based decision making, with flexible work options and

Qualifications

  • Experience in cyber security risk governance and vulnerability management.
  • Familiarity with vulnerability remediation governance and risk-based decision making.
  • Ability to develop dashboards and metrics to monitor remediation posture.

Responsibilities

  • Support ongoing management and continuous improvement of the Vulnerability Management Standard and related controls.
  • Govern remediation activities and communicate risk posture to stakeholders.
  • Engage with IT service owners to ensure timely remediation and compliance.
  • Assess control effectiveness and drive improvement actions across teams.
  • Develop dashboards and metrics for visibility into remediation and security posture.
  • Handle ServiceNow requests related to vulnerability management and deferrals per policy.

Skills

ASD Essential Eight
ASD ISM
NIST
CVSS/EPSS
Vulnerability Scanning
Qualys
Wiz
Microsoft Defender
Tanium
Stakeholder Engagement
Security Governance

Education

Bachelor's or Master's in Computer Science/Engineering/IT/Cybersecurity

Tools

ServiceNow

Job description

Job Description:

Organization- At CommBank, we never lose sight of the role we play in delivering a brighter future for our customers and supporting our communities. Our focus is to help customers and communities move forward to progress. To make the right financial decisions and achieve their dreams, targets and aspirations. Regardless of where you work within our organization, your initiative, talent, ideas and energy all contribute to the impact that we can make with our work. Together we can build tomorrow’s bank today.

Role Title – Cyber Generalist Manager

Location- Bangalore- Manyata tech Park

Business and team:

Group Security Technology safeguards the organization through innovative cyber, identity and fraud technology. We design, build and run security products that improve security outcomes, enable secure technology adoption and protect the Group's platforms, systems, data and digital assets.

The API Security squad discovers, monitors and protects APIs across the organization. The squad operates enterprise API security capabilities, including Akamai Noname, to maintain visibility of the API estate, assess security posture, monitor runtime behavior and coordinate action on credible threats and security findings. We partner with application teams, API owners, platform engineering, cloud, architecture and security operations teams.

Impact and Contributions:

The Cyber Controls Chapter Area sits within Group Security and is responsible for governing and continuously improving cyber control capabilities across the organisation.

As the Control Manager, Vulnerability Management, you will support the Control Lead in strengthening how vulnerability remediation is governed, measured and improved across the Group. You will work closely with technology teams, IT service owners and business stakeholders to help them understand their vulnerability posture, meet remediation expectations and address control gaps.

This is a governance and control-focused role. While familiarity with vulnerability scanning tools is useful, the primary focus is on remediation governance, control effectiveness, reporting, stakeholder engagement and continuous improvement.

We support our people with flexibility to balance where work is done, with at least half your time each month connecting in office. We also have flexible working options available, including changing start and finish times, part‑time arrangements and job share. Talk to us about how these arrangements might work for you.

Roles & Responsibilities:

Working with the Control Lead Vulnerability Management, you will:

  • Support the ongoing management and continuous improvement of the Vulnerability Management Standard and related control requirements.
  • Govern vulnerability remediation activities by helping technology teams understand their vulnerability posture, remediation obligations and control compliance requirements.
  • Engage with IT service owners, technology domains and business units to support timely, risk-based remediation of vulnerabilities.
  • Assess and monitor control effectiveness, identify areas outside tolerance and work with stakeholders to understand root causes and improvement actions.
  • Develop and use dashboards, reporting and metrics to provide visibility of remediation compliance, control performance and security posture.
  • Assess and respond to ServiceNow (SNOW) requests relating to vulnerability management, including requests to exclude assets from scanning or defer vulnerabilities in line with policy requirements.
  • Support process improvement, assurance and audit activities through evidence gathering, control validation and continuous improvement initiatives.
We are interested in hearing from people who:
  • Have experience in cyber security, technology risk, vulnerability management, security operations, infrastructure, cloud, engineering or technology controls.
  • Understand vulnerability management concepts, including vulnerability identification, prioritisation, remediation governance and risk-based decision making.
  • Can confidently engage with technical stakeholders and constructively challenge assumptions around remediation timelines, risk acceptance and control compliance.
  • Are comfortable working with data, dashboards and reporting to identify trends, insights and areas requiring attention.
  • Bring a continuous improvement mindset and can help build practical, stable and scalable processes.
  • Are curious, humble and confident enough to speak up, challenge constructively and keep building their knowledge.
Essential Skills:
  • Understanding of cyber security risk frameworks and guidance, including ASD Essential Eight, ASD ISM, NIST and related control frameworks.
  • Experience with vulnerability prioritisation and risk assessment, including frameworks such as CVSS and EPSS.
  • Familiarity with vulnerability scanning or exposure management tools such as Qualys, Wiz or Microsoft Defender.
  • Familiarity with patch management tools or processes, including Tanium or similar enterprise technologies.
  • Understanding of vulnerabilities across servers, endpoints, cloud environments, web applications and related technology platforms.
  • Experience in technology controls, cyber controls or risk governance will be highly regarded, but we are also open to candidates with strong technical cyber or technology backgrounds who can confidently engage with stakeholders.
  • Security certifications such as CISSP, CISM or CRISC are advantageous, but not mandatory.

Education: Bachelor's or Master's degree in Computer Science, Engineering, Information Technology, Cybersecurity or a related discipline, or equivalent practical experience.

We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.

Advertising End Date: 29/09/2026

Requirements:
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Generalist Senior Manager
Cyber Generalist Senior Manager

Commonwealth Bank • Bengaluru

Hybrid
INR 4,000,000 - 7,500,000
Flexible working options
Part-time arrangements
Job share opportunities
Cyber Incident Responder
Cyber Incident Responder

Commonwealth Bank • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Senior Security Engineer
Senior Security Engineer

cba • Bengaluru

On-site
INR 2,400,000 - 4,000,000
Senior Security Engineer
Senior Security Engineer

Commonwealth Bank • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000
Cyber Assurance Controls Testing
Cyber Assurance Controls Testing

ACCA Careers • Maharashtra

On-site
INR 1,800,000 - 3,200,000
Cyber Assurance Controls Testing
Cyber Assurance Controls Testing

1203 Barclays Global Serv. Cent • Pune District

On-site
INR 1,200,000 - 2,000,000
Staff Security Engineer
Staff Security Engineer

Commonwealth Bank • Bengaluru

On-site
INR 3,000,000 - 6,000,000
AVP - Senior Cyber Operations Service Management Analyst
AVP - Senior Cyber Operations Service Management Analyst

Barclays • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Manager – Security Infrastructure & Applications
Manager – Security Infrastructure & Applications

inlogic Technologies Pvt. Ltd. • Chennai District

On-site
INR 1,800,000 - 2,400,000
Competitive compensation and benefits package
Flexible work arrangements
Professional development opportunities
Managed Services Analyst, MXDR
Managed Services Analyst, MXDR

Check Point Software • Bengaluru Urban

On-site
INR 1,200,000 - 1,500,000