Senior Information Security Engineer
Listed on 2026-08-11
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
The Senior Information Security Engineer is a highly technical, hands-on engineering role responsible for designing, implementing, and owning enterprise-grade security solutions across the Bank’s infrastructure, cloud platforms, and identity environments. This role operates with significant autonomy and is expected to function as a technical leader within the Security Engineering team.
In addition to operational responsibilities, the Senior Information Security Engineer will drive security architecture patterns, detection engineering, and control strategy, partnering closely with the CISO, Information Security Architect, and IT leadership to influence enterprise security direction and risk posture.
This role is expected to act as a subject matter expert and technical escalation point, proactively identifying gaps, engineering scalable solutions, and improving the maturity of the Bank’s security program through automation, optimization, and innovation. This role may require after-hours support for critical incidents and production issues.
Key Responsibilities- Design, engineer, and own end-to-end security solutions across on-premises, hybrid, and cloud environments (Azure, M365, SaaS).
- Serve as a technical lead for security control design, translating architectural requirements into resilient, scalable, and auditable implementations.
- Function as a security engineering escalation point for complex incidents, investigations, and cross-domain issues.
- Lead configuration, tuning, and lifecycle management of enterprise security technologies (firewalls, WAF, IDS/IPS, EDR/XDR, SIEM, DLP, CASB, IAM solutions).
- Develop and maintain advanced detection logic and use cases (SIEM rules, correlation searches, behavioral analytics).
- Engineer and implement security automation and orchestration (Python, Power Shell, APIs, SOAR platforms) to reduce manual effort and improve response times.
- Lead or support incident response activities, including containment strategy, root cause analysis, and post-incident remediation plans.
- Perform threat modeling, risk assessments, and control gap analysis for systems and applications.
- Collaborate with architects to define and enforce secure design patterns and reference architectures.
- Evaluate emerging threats and technologies; recommend and implement security improvements aligned with evolving attack trends.
- Conduct advanced vulnerability analysis and prioritize risk based on exploitability and business impact.
- Analyze logs, network flows, and endpoint telemetry to identify and investigate sophisticated attack patterns and adversary behaviors.
- Provide technical mentoring, guidance, and peer review for junior engineers and analysts.
- Participate in security tool selection, evaluation, and proof-of-concept initiatives.
- Participate in on-call rotation and function as a primary escalation engineer for high-severity incidents.
- Lead or support major incident response efforts, including coordination across IT, vendors, and leadership.
- Drive incident postmortems (RCA) and ensure corrective actions are implemented and validated.
- Provide after-hours support for critical security events and production issues.
- Ensure adherence to incident response playbooks, SLAs, and regulatory reporting requirements.
- Ensure security engineering work aligns with regulatory frameworks and audit requirements (FFIEC, SOC 2, PCI DSS, etc.).
- Partner with GRC and audit teams to provide technical validation, evidence, and control effectiveness reporting.
- Support continuous control monitoring and compliance automation initiatives.
- Ensure all engineered solutions adhere to banking regulations (BSA, AML, OFAC, CIP, privacy laws).
Complies with all applicable state and federal banking laws, regulations, and internal policies related but not limited to lending, operations, and deposit requirements, including Bank Secrecy Act (BSA), Anti-Money Laundering (AML) requirements, Office of Foreign Assets Control (OFAC) regulations, Customer Identification Program (CIP) requirements, Financial Elder Abuse reporting laws, Sexual Harassment prevention policies,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).