Senior IT Security Engineer

Job not on LinkedIn

🔥 8 hours ago

🇺🇸 United States – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 11%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cornerstone Capital Bank

Cornerstone Capital Bank

51 - 200 employees

🏦 Banking

💸 Finance

Banking • Finance

Cornerstone Capital Bank is a community-focused national bank formed by the merger of Cornerstone Home Lending and Roscoe Bank that provides mortgage origination and servicing, personal and commercial banking, and institutional treasury and liquidity services. The bank emphasizes customer service, stability, and digital convenience, offering fee-free deposit accounts, national ATM access, wire and ACH transfers, and integrated mobile banking alongside personalized, one-on-one financial support. It serves consumers, businesses, and other financial institutions with a broad suite of banking and home-lending products.

📋 Description

• Support and enhance the organization’s security program across security architecture, emerging technology and AI reviews, IAM governance, vulnerability management, and third-party security • Identify, assess, mitigate, and validate cybersecurity risks and security controls • Support security assurance, control effectiveness, remediation validation, security engineering, automation, and continuous improvement • Assess security controls, identify risks and gaps, and support remediation and validation activities • Leverage security technologies, engineering practices, and automation to strengthen controls and reduce manual processes • Support security metrics, reporting, and monitoring activities • Participate in cybersecurity incident response, investigations, exercises, and lessons learned • Contribute to security standards, procedures, and technical guidance • Collaborate with Technology, business, Risk, Compliance, Audit, and other stakeholders • Lead the enterprise phishing awareness program, including monthly simulations, metrics, risk trends, and continuous improvement • Conduct security architecture reviews for applications, infrastructure, cloud services, SaaS platforms, AI solutions, and third-party technologies • Assess AI and emerging-technology risks and participate in AI governance • Review authentication, authorization, encryption, data protection, logging, monitoring, resiliency, and recovery requirements • Validate security requirements and controls throughout implementation and operation • Participate in vendor evaluations, technology assessments, and project planning • Provide IAM oversight and independent verification of IAM, privileged access, authentication, vulnerability management, and third-party security controls • Administer and oversee identity lifecycle processes, RBAC, privileged access, segregation of duties, PAM, SSO, MFA, Conditional Access, and identity federation • Support Microsoft Entra ID, Active Directory, and related identity platforms • Conduct access reviews, control testing, audit support, regulatory examination support, and remediation validation • Develop cybersecurity metrics, KRIs, KPIs, and management-level reporting • Lead enterprise vulnerability management, including prioritization, remediation tracking, validation, and reporting • Review vulnerability assessments, penetration tests, red-team exercises, and technical security testing • Manage vulnerability exceptions, risk acceptances, and compensating controls • Participate in third-party security reviews, vendor risk assessments, due diligence, monitoring, and reassessment • Assess third-party controls, safeguards, resilience, incident response, data protection, and supply-chain risks • Partner with Vendor Management, Procurement, Legal, Privacy, Compliance, and business stakeholders

🎯 Requirements

• Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field preferred • Experience working within banking, financial services, mortgage lending, fintech, or other highly regulated industries • Working knowledge of FFIEC guidance, banking regulatory expectations, and cybersecurity requirements applicable to financial institutions • Familiarity with FDIC examinations, internal audits, external audits, and cybersecurity control assessments • Strong understanding of the NIST Cybersecurity Framework (CSF), CIS Controls, and risk-based cybersecurity programs • Familiarity with AI governance, AI risk management concepts, and secure adoption of emerging technologies • 5+ years of experience in cybersecurity, information security, or security engineering • Experience supporting Identity and Access Management programs, processes, and technologies • Experience conducting security architecture reviews and technical risk assessments • Experience managing or supporting enterprise vulnerability management programs • Experience conducting vendor security reviews and third-party security assessments • Experience with Microsoft Entra ID, Active Directory, Microsoft 365 security technologies, and cloud-based platforms • Preferred certifications: CISSP, CISA, CompTIA Security+, ISC2 Certified in Cybersecurity (CC), Microsoft SC-900, Microsoft AZ-900, Microsoft SC-300 • Additional cybersecurity, cloud security, or identity-focused certifications preferred • Ability to sit for extended periods • Dexterity to operate computer keyboards, mice, and other computer components • Ability to lift 30–40 lbs and move equipment • Ability to travel to other locations as needed • Ability to participate in training sessions, presentations, and meetings

🏖️ Benefits

• Fortune-certified Great Place to Work® recognition • Top Workplace recognition • Occasional evening and weekend work to meet deadlines • Reasonable accommodation for individuals with disabilities • Training sessions, presentations, and meetings • Opportunity to work remotely

Apply Now

Similar Jobs

🔥 8 hours ago

VIP (Vermont Information Processing)

501 - 1000

🍽️ Food & Beverage

📦 Logistics

☁️ SaaS

Senior Security Engineer hardening beverage-industry technology platforms across VIP’s U.S. operations. Leading segmentation, detection, vulnerability, identity, and incident-response engineering.

🔥 9 hours ago

Sky Betting & Gaming

1001 - 5000

🎲 Gambling

🎮 Gaming

👥 B2C

Senior Security Engineer protecting Fanatics’ global sports betting and gaming platform. Automating threat detection, maintaining cloud SIEM systems, and leading incident response.

🔥 9 hours ago

GE Vernova

10,000+ employees

💼 Consulting

📦 Logistics

🏭 Manufacturing

Product cybersecurity architect securing GE Vernova’s industrial energy products. Designing architectures, leading IEC 62443 threat modeling, and operationalizing AI-assisted security assessments.

🔥 9 hours ago

GE Vernova

10,000+ employees

💼 Consulting

📦 Logistics

🏭 Manufacturing

Product Cybersecurity Architect securing GE Vernova's industrial energy products through secure architectures and IEC 62443 threat modeling. Applying AI-assisted analysis and SDL guidance across Power, Wind, and Electrification teams.

🔥 10 hours ago

Peraton

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Information assurance engineer serving as ISSO for Peraton’s Azure-based federal systems. Managing RMF compliance, vulnerability assessments, security architecture, and incident response.