The InfoSec Senior Engineer – Security Engineering & Architecture is responsible for building security solutions that protect the business, but also allow the business to execute and innovate. The InfoSec Senior Engineer works closely with many diverse and dynamic teams, including, but not limited to, Security Engineering, IT Infrastructure, Application Development, Security Operations, Security Audit and End users. This position is also responsible for building solutions to secure business-to-business initiatives, third-party relationships, outsourced solutions, and vendors. The InfoSec Senior Engineer provides guidance for addressing current security issues but is expected to proactively deliver optimal secure solutions. The Engineer is expected to think like an adversary and identify how solutions should evolve as the threat landscape changes. The Engineer possesses strong communication and organizational skills, and the ability to guide less experienced coworkers. The Engineer provides technical leadership to delivery and solution engineering team members. Under the direction of the Information Security Director, develop strategies and plans to achieve security requirements and address identified risks. Assist in the development of security architecture and security policies, principles, and standards. Gather, analyze, and assess the current and future threat landscape, and assist in providing leadership with a realistic overview of risks and threats in the enterprise environment. Work with business units and with other risk functions to identify security requirements, using methods that may include risk and business impact assessments. Perform security testing and vulnerability assessments to identify security strengths and weaknesses, to assess the effectiveness of existing controls, and to recommend remediation action. Perform incident management and response activities as a member of the bank’s incident management team. As required, assist in triage, response and mitigation, postmortem analysis, and forensic analysis. Review audit trails, system logs and other monitoring data sources regularly and ensure they are in compliance with policies and audit requirements. Required to perform duties outside of normal work hours based on business needs. Assumes responsibility for other duties as required or assigned.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior