Information Security Engineer; On-Site
Listed on 2026-07-13
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, Data Security
HAPO Community Credit Union is an organization that believes in providing service that focuses on our members and giving back to the communities in which we do business - "Community" is our middle name. Our Standard of Service is to Defy Expectations. We promote individuality and encourage our employees to Defy Expectations®:
To treat every situation as a unique opportunity to be in the moment and go beyond what is expected. We value every member and appreciate the opportunity to serve you.
Come defy expectations with us!
- No cost premium health insurance for all employees, including medical, dental and vision
- Accidental death and dismemberment insurance
Long term and Short term disability
HAPO Professional Benefits
- Competitive pay
- Pension Plan
- 401K program with match
- Flexible spending account (medical and dependent care)
0% interest on select personal loans
HAPO Personal Benefits
- Employee Assistance Program (EAP)
- Paid time off
- 11 paid holidays per year
- Paid Birthday day off
- HAPO Anniversary day off
- Volunteer Opportunities (Both Paid and Volunteer)
- Employee Milestone Anniversary Bonus
Tuition Assistance Program
Information Security EngineerWe are seeking an individual who is ambitious, self‑motivated and who strives to represent HAPO’s core commitment “Be in the Moment” and standard of service “Defy Expectations” with our members, community as well as the team they are a part of. The Information Security Engineer is responsible for designing and reviewing security strategy and controls that safeguard and protect the organization’s computer networks, systems and sensitive information.
This position also serves as an expert resource for the Information Security Analyst role. Additional responsibility is assigned for ensuring information security best practices are implemented and enforced through cross‑department technologies under the direction of Information Security Management. The Info Sec Engineer is responsible for designing and scheduling vulnerability scans, conducting penetration testing, conducting risk assessment and recommending solutions to identified risks and vulnerabilities.
Job Functions
- Deploy and maintain security system configurations according to standards and best practices
- Develop system security standards
- Comply with process change control requirements for any additions and/or modification to systems
- Conduct Information Security based risk assessments
- Provide investigative support in information security incident response and forensics
- Design and implement vulnerability scanning processes and schedules
- Staying current with information security threats, trends and tactics
- Perform vendor information security assessments
- Process information security support requests
- Identify, design and deploy new security solutions and controls as required
- Develop and maintain information security procedures
- Serve as a source of knowledge and reference for the Information Security Analyst
- Become subject matter expert over the systems within the responsibility of the Information Security Engineer
- When needed and under the direction of Information Security Management, provide assistance in the following areas supporting the Information Security Analyst role:
- Assist in monitoring and analyzing information from logging and alerting systems
- Assist in investigating and escalating security alerts
- Assist in monitoring information security systems availability and performance
- Assist in performing threat hunting activities
- Assist in conducting vulnerability scans reviews
- Assist the Information Security Analyst conducting phishing campaigns
- Assist in processing information security support requests
- Assist Information Security Management with developing and maintaining information security policy
- Expertise in cyber security threat analysis, detection and prevention.
- Expert in Cyber security risks, threats and prevention technologies.
- Highly skilled in risk assessment and management approaches
- Advanced knowledge of IDS/IPS, SIEM, DLP, Attack Mitigation and Prevention
- Proficient in Security Frameworks (PCI-DSS, NIST 800-53, NIST CSF, CIS Top 20)
- Proficient in Third Party Risk reviews
- Exceptional communicator with both…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).