Staff Engineer II - Cyber
Listed on 2026-09-11
-
IT/Tech
Cybersecurity
What you'll do:
As a Staff Engineer II - Cyber, you will serve as a technical leader responsible for end-to-end ownership of the bank’s cyber defense platforms, with a strong focus on Attack Surface Management (ASM) and Continuous Threat Exposure Management (CTEM). You will drive a proactive, risk-based security program that continuously discovers, prioritizes, and reduces cyber exposure across internal and external environments. This role combines deep engineering expertise, platform ownership, and strategic influence, leveraging tools such as CSPM, Vulnerability & Exposure Management, AV/EDR, Phishing, and DLP platforms to deliver integrated security outcomes across cloud, endpoint, network, and data layers.
Additionally, you'll lead the continuous review and improvement of the defense, auditing, access standards, tactics, and techniques to meet regulatory guidelines as well as owning the resiliency of cyber applications and platforms via routine disaster recovery exercises. You'll partner with vendors routinely to optimize cyber defense, auditing, and access products, as well as ensure costs/licenses do not exceed expectations, and that certificates do not expire while maintaining capacity planning to ensure quality end user experience.
Engineer and operationalize a Continuous Threat Exposure Management (CTEM) program, including:
- Asset discovery across cloud, on-prem, and internet-facing environments.
- Risk-based prioritization of vulnerabilities and exposures.
- Validation of findings through real-world context and exploitability.
- Coordination of remediation and risk reduction efforts across IT and Cyber teams.
- Identify and map internet-exposed assets (IPs, domains, cloud services).
- Validate exposures (open ports, public access, misconfigurations, weak controls).
- Provide continuous visibility into known and unknown attack surfaces.
- Wiz (CSPM + ASM) for cloud posture and exposure visibility.
- Microsoft Defender for Cloud compliance and posture management.
- Rapid7 for vulnerability scanning and prioritization.
- Crowd Strike for endpoint detection, response, and telemetry.
- Symantec Data Loss Prevention/CASB experience a plus.
- Engineer and operationalize a SaaS Security Posture Management (SSPM) technology.
- 6+ years of advanced cybersecurity experience.
- Bachelor’s degree in related field required.
- Advanced knowledge of general Financial Services or Banking is preferred.
- Working knowledge of Linux and Power Shell.
- Solid understanding of authentication protocols SAML, SSO, and LDAP.
- Solid understanding of concepts regarding ASM, CTEM, DLP, CASB, CSPM, Firewall, SSL/TLS, Vulnerability Scanners, and EDR.
- Solid understanding of OSI layers, DNS, SMTP, etc. for troubleshooting application functionality.
- Advanced experience of CIS, NIST, MITRE, and Administration of either or all within organizations.
- Advanced speaking and writing communication skills.
- Demonstrated leadership in security operations architecture or detection engineering.
- Proven ability to translate technical findings into executive-level risk context.
We offer all the important things you'd want - like competitive salaries, an ownership stake in the company, medical and dental insurance, time off, a great 401k matching program, tuition assistance program, an employee volunteer program, and a wellness program. In addition, you’ll have the opportunity to bolster your business knowledge, learning the ins and outs of how successful companies operate and manage their finances, giving you invaluable hands-on experience to help grow…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).