Security Engineer
Listed on 2026-08-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About the Opportunity
Sierra Central Credit Union is a member‑owned financial institution that has served Northern California communities for more than 70 years. The Security Engineer is responsible for implementing and maintaining the Credit Union's cybersecurity infrastructure, controls, and security operations program. This role plays a key part in developing and operationalizing Sierra Central Credit Union’s cybersecurity program and ensuring the security of information systems, networks, applications, and data.
The Security Engineer partners with internal departments, third‑party security providers, and regulatory stakeholders to protect the organization from cyber threats while maintaining compliance with applicable regulatory and industry standards.
- Implement, administer, and optimize Microsoft 365 E5 security and compliance solutions, including Defender XDR, Entra , Intune, Purview, and Defender for Cloud Apps.
- Configure and maintain security controls for SharePoint Online, One Drive, Teams, and other cloud collaboration platforms, including data loss prevention (DLP), sensitivity labelling, information protection, sharing controls, and application governance.
- Administer enterprise email security technologies, including anti‑phishing, anti‑malware, impersonation protection, secure email gateway policies, and email authentication protocols such as SPF, DKIM, and DMARC.
- Manage and report on the organization’s phishing simulation and security awareness training program.
- Assist with cybersecurity incident investigations and response activities, including threat triage, containment, remediation, root‑cause analysis, and post‑incident reporting.
- Coordinate with managed detection and response (MDR) providers and other security partners to support ongoing monitoring and threat detection activities.
- Support vulnerability management efforts through asset scanning, risk assessment, remediation tracking, and penetration testing initiatives.
- Assist with enterprise risk management activities, including security control design, documentation, evidence collection, third‑party risk reviews, and regulatory examinations.
- Support compliance with applicable laws, regulations, and industry standards, including GLBA Safeguards Rule requirements and other financial industry security expectations.
- Participate in data protection and privacy initiatives, including data classification, data governance, insider risk monitoring, and information protection programs.
- Monitor, analyze, and respond to security events, alerts, and suspicious activity across network, endpoint, cloud, and identity platforms.
- Develop and maintain security documentation, standards, procedures, and operational guidelines.
- Collaborate with business units and IT teams to identify and mitigate cybersecurity risks.
- Provide technical guidance, mentoring, and cybersecurity training to junior staff and colleagues.
- Remain current on emerging security threats, vulnerabilities, technologies, and industry best practices.
- Perform other duties and projects as assigned.
Skills and Abilities
- Strong knowledge of cybersecurity principles, security architecture, threat detection, incident response, and risk management practices.
- Advanced knowledge of Microsoft 365 security and compliance technologies, including Defender, Entra , Intune, Purview, and cloud security controls.
- Proficiency in securing cloud collaboration platforms, including SharePoint Online, One Drive, and Teams.
- Knowledge of email security technologies and protocols, including anti‑phishing controls, SPF, DKIM, and DMARC.
- Experience with firewall administration, VPN technologies, network security practices, and related security tools.
- Ability to investigate and analyze security incidents using logs, endpoint telemetry, identity data, and forensic evidence.
- Understanding of vulnerability management processes and remediation practices.
- Knowledge of regulatory, audit, and compliance requirements within a regulated industry environment.
- Strong analytical, problem‑solving, and decision‑making skills.
- Excellent written, verbal, and interpersonal communication skills with the ability…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).