Information Security Engineer II

CardWorksWoodbury, MN
Hybrid

About The Position

CardWorks Financial Group is a diversified financial services platform building ethical solutions across credit, lending, and the full customer lifecycle. Through our family of companies, CardWorks Financial Group tackles the complex challenges that larger financial institutions leave behind. We’re embedded throughout the credit card ecosystem as a lender, servicer, and merchant acquirer. CardWorks Servicing, LLC provides end- to end operational servicing functions for credit cards, secured cards, and installment loans. We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees. Founded in 1997, Merrick Bank is an FDIC®-insured financial institution headquartered in South Jordan, Utah, with over $10 billion in assets. A wholly owned subsidiary of CardWorks Financial Group, Merrick Bank serves roughly five million cardmembers and more than 100,000 merchant customers, offering credit cards, recreational loans, deposit accounts, merchant services and bank sponsorships to consumers and businesses. Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management. This role implements, operates, monitors, and improves information security processes and systems that protect the Bank’s data, customers, and computer systems from business disruption, data/identity compromise, cyber fraud, and regulatory criticism. The Information Security Engineer II will perform security incident event management and network intrusion detection using security concepts, defense-in-depth strategies, security tools, and protocols. They will engage in the support of security-focused tools and services, conduct security event monitoring, investigation, detection, and incident response, including log analysis and documentation of investigations. This role will also perform incident response on escalated tickets and participate in major incident response engagements. The engineer will use a variety of tools to monitor system and application log alerts for indication of unauthorized activity and perform analysis on infected systems. They will engineer, tune, and operate log sources, alerts, rules, and monitors in the Security Information and Event Management (SIEM) platform, which collects, correlates, and analyzes security logs and events in real-time to detect threats and enable rapid incident response. The role involves working with IT Security Engineers and assisting with gathering information during penetration testing, incident handling/digital forensics, continuous monitoring, and intrusion detection/prevention. Additionally, the engineer will work with auditors to provide the required evidence of compliance with regulatory bodies, comply with all internal control policies and procedures, and understand and comply with all applicable laws and regulations. Communication of problems in operations, noncompliance with the code of conduct, noncompliance with laws and regulations, policy violations, or illegal acts is essential. The role requires communicating security issues and risks to individuals with both technical and non-technical backgrounds, and troubleshooting and problem-solving complex security, hardware, and network systems. Researching cybersecurity and technology trends, news, and hacking techniques is also a key part of the role. The engineer will use Kusto Query Language (KQL) to run advanced queries for threat hunting, anomaly detection, and security event investigations in the XDR platform. A work from home benefit is provided, and worksites are unanticipated. Travel to South Jordan, Utah is required one day per week.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology or a closely related field.
  • Three (3) years of experience as a Security Engineer, Security Analyst, Incident Responder or a closely related occupation.
  • Three (3) years of experience as a Security Engineer, Security Analyst, Incident Responder or a closely related occupation must be in the Credit Card Industry or Consumer Finance Industry.
  • Demonstrable knowledge and prior experience in: Advanced security event monitoring, investigation, and response capabilities.
  • Demonstrable knowledge and prior experience in: Engineering, tuning, and operating on the SIEM platform.
  • Demonstrable knowledge and prior experience in: Security concepts, defense-in-depth strategies, security tools, and protocols.
  • Demonstrable knowledge and prior experience in: Communicating security issues and risks to individuals with technical and non-technical backgrounds.
  • Demonstrable knowledge and prior experience in: Troubleshooting and problem-solving complex security, hardware, and network systems.
  • Demonstrable knowledge and prior experience in: Researching cybersecurity and technology trends, news, and hacking techniques.
  • Demonstrable knowledge and prior experience in: Kusto Query Language (KQL).

Responsibilities

  • Implement, operate, monitor, and improve information security processes and systems that protect the Bank’s data, customers, and computer systems from business disruption, data/identity compromise, cyber fraud, and regulatory criticism.
  • Perform security incident event management and network intrusion detection using security concepts, defense-in-depth strategies, security tools, and protocols.
  • Engage in the support of security-focused tools and services.
  • Conduct security event monitoring, investigation, detection, and incident response, including log analysis and documentation of investigations.
  • Perform incident response on escalated tickets.
  • Participate in major incident response engagements.
  • Use a variety of tools to monitor system and application log alerts for indication of unauthorized activity and perform analysis on infected systems.
  • Engineer, tune, and operate log sources, alerts, rules, and monitors in the Security Information and Event Management (SIEM) platform, that collects, correlates, and analyzes security logs and events in real-time to detect threats and enable rapid incident response.
  • Work with IT Security Engineers and assist with gathering information during penetration testing, incident handling/digital forensics, continuous monitoring, and intrusion detection/prevention.
  • Work with auditors to provide the required evidence of compliance with the regulatory bodies.
  • Comply with all the Bank’s internal control policies and procedures.
  • Understand and comply with all laws and regulations to which the Bank is subject.
  • Communicate problems in operations, noncompliance with the code of conduct, noncompliance with laws and regulations, policy violations, or illegal acts.
  • Communicate security issues and risks to individuals with technical and non-technical backgrounds.
  • Troubleshoot and problem-solve complex security, hardware, and network systems.
  • Research cybersecurity and technology trends, news, and hacking techniques.
  • Use Kusto Query Language (KQL) to run advanced queries for threat hunting, anomaly detection, and security event investigations in the XDR platform.

Benefits

  • Medical
  • Dental
  • Vision
  • 401(k) Plan with Company Match
  • Short- & Long-Term Disability
  • Wellness Programs
  • Group Life and AD&D Insurance
  • Paid Vacation
  • Sick Days
  • Bank Holidays
  • Competitive Pay, including a Bonus Target or Variable Pay Incentive Program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service