Security Engineer

Sierra Central Credit UnionYuba City, CA
$120,000 - $145,000Onsite

About The Position

Sierra Central Credit Union is a member-owned financial institution that has served Northern California communities for more than 70 years. This is a ground-floor security engineering seat: you will help design and operationalize the architecture rather than inherit someone else's, and your work will directly shape how a regulated financial institution protects its members for the next decade. You will report to the VP of Information and Cyber Security and work alongside an Information Security Specialist as part of the Information Systems and Information Technology (ISIT) department. We are a Microsoft shop, and this role sits at the center of operationalizing a Microsoft 365 E5 security stack that is licensed but not yet fully deployed. If you want to build rather than maintain, this is that job.

Requirements

  • Minimum 4 years of hands-on security engineering experience, including significant time in a Microsoft-centric enterprise environment.
  • Deep working knowledge of Microsoft 365 E5 security and compliance capabilities and cloud file sharing technologies (SharePoint Online, OneDrive, Teams governance, and DLP).
  • Knowledge and experience with firewalls, VPNs, and network security practices and tools.
  • Demonstrated incident investigation experience: log analysis, endpoint and identity forensics, and clear post-incident documentation.
  • Email security administration and phishing simulation program experience.
  • Working familiarity with risk management and audit practices in a regulated environment.
  • Strong written and verbal communication, comfortable explaining technical risk to both engineers and executives.
  • Ability to work onsite at our Yuba City headquarters.

Nice To Haves

  • Financial services or credit union experience; familiarity with NCUA and FFIEC regulatory expectations.
  • Certifications such as CISSP, CISM, GIAC, or Microsoft SC-200, SC-100, or SC-400.
  • SIEM engineering depth: KQL, analytics rule development, automation and SOAR workflows.
  • EDR operations experience and coordination with MSSP or MDR partners.
  • Privacy framework knowledge: GLBA, CCPA/CPRA.
  • A track record of mentoring, training, or developing junior staff.

Responsibilities

  • Engineer, deploy, and tune the Microsoft 365 E5 security stack: Microsoft Sentinel, Defender XDR, Entra ID, Intune, Microsoft Purview (DLP, sensitivity labels, information protection), and Defender for Cloud Apps.
  • Secure cloud file sharing and collaboration across SharePoint Online, OneDrive, and Teams: tenant sharing policies, sensitivity labeling, DLP policy design in monitor and enforce modes, and OAuth application consent governance.
  • Administer and tune enterprise email security: secure gateway policy, anti-phishing and impersonation controls, and SPF, DKIM, and DMARC posture.
  • Own the phishing simulation and testing program end to end: campaign design, execution, click-rate and reporting metrics, and targeted remediation training.
  • Lead incident investigation and response in partnership with our managed detection and response provider: triage, containment, root-cause analysis, and post-incident reporting aligned to NCUA cyber incident notification requirements.
  • Support vulnerability management: scan result analysis, remediation coordination with infrastructure and systems teams, and penetration test scoping and remediation tracking.
  • Contribute to risk management and audit readiness: control design and evidence, support for NCUA examinations and internal and external audits, and third-party risk reviews.
  • Support the privacy and data protection program: data classification, insider risk monitoring, and GLBA Safeguards Rule alignment.
  • Mentor junior security staff and act as a security resource for IT peers and business units across the credit union.

Benefits

  • Medical, Dental & Vision Insurance options
  • Voluntary Lines including hospital indemnity, accident, and critical illness policies
  • Company Paid HRA (with enrollment in certain health plans)
  • Company Paid Basic Term Life Insurance
  • Company Paid Long-Term Disability Insurance for Full-Time Employees
  • Company Paid Telehealth Services Membership (Teladoc)
  • Company Paid Employee Assistance Program (EAP)
  • 401(k) Retirement Plan
  • Flexible Spending Accounts
  • HSA
  • Paid Time Off
  • 11 paid holidays
  • Travel Expense Reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service