AppSec Jobs
← Back to all jobs

ANZ

Application Security Engineer (AVP)

Hybrid
Bengaluru, Karnataka, IndiaPosted 3 weeks agoWebsite
Apply on LinkedIn →

At a Glance

AWSAzureGCPCI/CDCode ReviewSAST

About This Role

The mission of Application Security Engineering squad is to keep ANZ safe by ensuring that applications are coded securely via providing secure development training, secure code review and Software Composition Analysis services. As an Engineer in Application Security Engineering squad, you will support application security services to increase delivery speed in a secure manner. You will utilise various tools and practices to secure solutions in the most efficient ways, enhancing tech division capabilities and enabling DevSecOps across the enterprise. You will drive ANZ's information security efforts by providing Subject Matter Expertise and collaborate with engineering teams. Role Type: Permanent. Role Location: Bengaluru. Work Hours: Full-Time (Hybrid/Blended).

Responsibilities

  • Deliver application security services covering security code review, software composition analysis and security development training
  • Assess tools outputs, review code/configuration, and provide guidance on security vulnerabilities and remediation controls to application development teams
  • Integrate, manage, fine tune and automate application security tooling and practices to enable DevSecOps
  • Drive ANZ's information security efforts by providing Subject Matter Expertise and collaborate with engineering teams
  • Support application security services to increase delivery speed in a secure manner

Requirements

SASTSCADevSecOpsCI/CDAzureAWSGCPCISSP
  • 8+ years of relevant experience in security domain
  • Experience in performing end-to-end security code scanning/review and/or software composition analysis using automated and manual techniques, leveraging enterprise SAST and SCA toolsets
  • Ability to provide guidance to application teams on security vulnerabilities and remediation controls in various programming languages/frameworks
  • Experience with various application security tooling and its usage in an enterprise
  • Knowledge of APIs and integration patterns offered by application security toolsets (SAST, SCA) and its usage to facilitate DevSecOps
  • Hands-on experience with application security concepts (threats, vulnerabilities, and fixes) and proficiency in multiple programming languages
  • Experience in a consulting role with a background in security and/or application development
  • Knowledge of Risk Management Principles
  • Ability to drive optimal security outcomes and effectively navigate challenging situations
  • Knowledge of DevSecOps including CI/CD pipeline, Infrastructure as Code, testing automation, DevSecOps orchestration & configuration (preferred)
  • Experience of working with enterprise grade SaaS, PaaS and IaaS (MS Azure, AWS, GCP, Salesforce, etc.) security (preferred)
  • Knowledge of Regulatory Security Requirements (preferred)
  • Agile/Scaled Agile delivery experience; managing work under an Epic with defined stories (preferred)
  • Exceptional interpersonal skills, including the ability to inspire, mentor, coach and develop others (preferred)
  • Relevant cyber security certifications (CISSP, CEH, etc) (preferred)

Benefits & Perks

Flexible working options, including hybrid work (where the role allows it)
Access to health and wellbeing services
Range of flexible working options to support different needs

About ANZ

ANZ (Australia and New Zealand Banking Group Limited) is one of Australia's largest banking institutions, serving over 8.5 million retail and business customers across nearly 30 markets. Established in 1828, ANZ has a rich history that began with the Cornwall Bank in Tasmania. The modern bank was formed through significant mergers, including the creation of Australia and New Zealand Banking Group Limited in 1970. ANZ offers a wide range of banking and financial products and services. It has been a leader in banking innovation, launching digital banking solutions like the goMoney app and being the first major Australian bank to offer Apple Pay. The bank provides online banking, ATM services, private banking, wealth management, and investment services. ANZ caters to diverse customer segments, including individual consumers, businesses, and high-net-worth clients. Recognized as one of the world's safest banks, ANZ is headquartered in Melbourne and has shown resilience through various economic challenges.

Industry

banking

Employees

44,000

3938 engineers

Revenue

$45B

Website

Visit →

Security at ANZ

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • ANZ's stated mission is to look after customers and their money by helping them protect what matters.
  • Their security goals include identifying opportunities for improvement or automation and staying current with emerging vulnerabilities to escalate those of interest.

Security Team

  • ANZ's application security functions are situated within the Group Cyber Security Risk Domain, specifically within the Vulnerability Services Squad. Dr. Maria Milosavljevic serves as the Chief Information Security Officer.
  • As of June 2026, there is at least one active job posting for a Security Engineer within the Vulnerability Services Squad (Req ID: 118058).

Key Initiatives

  • ANZ implements 'shift left' practices through the integration of vulnerability scanning toolsets within the enterprise.
  • Their vulnerability management process involves using Bugcrowd for the intake of disclosures, ServiceNow's Vulnerability Response module for triage and remediation, and focused management of zero-day and critical vulnerabilities.
  • Enterprise reporting is achieved using a combination of ETL and CMDB resources.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn