Information Security Manager – Configuration Management
Listed on 2026-09-07
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer
Job Description
At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career.
Try new things, learn new skills and discover what you excel at—all from Day One.
This position is not eligible for visa sponsorship.
Location expectations:
This role requires working from a U.S. Bank location three (3) or more days per week.
- Lead and develop a team of security configuration analysts and implementation resources.
- Build and execute the strategy and roadmap for the Configuration Implementation function.
- Define and standardize secure configuration requirements across infrastructure, cloud services, operating systems, applications, and security platforms.
- Develop and maintain secure configuration standards, technical controls, and implementation guidance.
- Translate security and compliance requirements into actionable technical configuration controls.
- Oversee configuration monitoring and scanning capabilities used to identify configuration drift, control gaps, and compliance issues.
- Partner with cloud, infrastructure, platform, application, and security engineering teams to implement and maintain secure configurations.
- Influence engineering practices to embed security requirements earlier in development and deployment processes.
- Collaborate with technology subject matter experts to identify configuration risks and determine appropriate security controls.
- Establish processes, governance, performance measures, and success criteria for the secure configuration management program.
- Prioritize remediation efforts in partnership with security, engineering, business, risk, and compliance stakeholders.
- Support regulatory, compliance, and audit obligations through effective technical configuration management practices.
- Build strong relationships with engineering leaders, technology teams, security stakeholders, and business partners.
- Develop technical talent and create a culture of accountability, collaboration, urgency, and continuous improvement.
- Five or more years of progressive leadership experience within technical security, infrastructure security, cloud security, configuration engineering, security architecture, or security technology management.
- Experience leading technical security, infrastructure, cloud, or configuration management teams.
- Strong understanding of secure configuration management, security baselines, and technical security controls.
- Experience defining, implementing, or maintaining secure configuration standards across enterprise technology environments.
- Experience working across cloud, infrastructure, operating systems, applications, or security platforms.
- Demonstrated ability to partner with engineering teams and influence technical strategy and implementation.
- Experience building or maturing security programs, processes, operating models, or governance frameworks.
- Knowledge of security risk management, regulatory requirements, and compliance obligations.
- Strong stakeholder management, relationship-building, problem-solving, and communication skills.
- Ability to balance strategic program leadership with tactical execution.
- Relevant security, cloud, infrastructure, or service management certification, such as CISSP, ITIL 4, AWS Solutions Architect Professional, Azure Solutions Architect Expert, or a comparable certification.
- Enterprise secure configuration management program experience.
- Cloud security engineering or infrastructure security experience.
- Infrastructure automation or policy-as-code experience.
- CI/CD or Dev Sec Ops security integration experience.
- Experience with Terraform, Ansible, Git Lab, Checkov, Chef, or Artifactory.
- Experience with Azure Policy or AWS Service Control Policies.
- Experience with Tenable.io, Wiz, Microsoft Defender for Cloud, AWS security tooling, or comparable platforms.
- Experience establishing configuration monitoring, compliance scanning, or drift-detection capabilities.
- Experience leading a newly formed or rapidly growing technical security team.
If there’s anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants.
Benefits- Healthcare (medical, dental, vision)
- Basic term and optional term life insurance
- Short-term and long-term disability
- Pregnancy disability and parental leave
- 401(k) and employer-funded retirement plan
- Paid vacation (from two to five weeks depending on salary grade and tenure)
- Up to 11 paid holiday opportunities
- Adoption assistance
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).