About The Position

At BNY, our culture allows us to run our company better and enables employees’ growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world’s investible assets. Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide. Recognized as a top destination for innovators, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance – and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary. We’re seeking a future team member for the role of Senior Director of Network Security – Engineering Lead to join our Network Security team. This role is located in New York City . In this role, you’ll make an impact in the following ways: Own Engineering delivery for the network security portfolio across the enterprise, including firewalls, IDS/IPS, secure web gateways, proxy, network access control (NAC), zero trust architectures, cloud security controls, and network threat detection solutions. Lead the end-to-end engineering lifecycle from architecture and design through build, integration, and production rollout, ensuring solutions are secure-by-design, resilient, and scalable. Ability to run formal lab validations for network security technologies (e.g., NGFW, SASE components, micro-segmentation), including design verification, performance testing, regression testing, and certification sign-off prior to production deployment. Drive & uphold Network Security & Cloud engineering governance, delivery management, and prioritization using Agile practices and Jira (roadmaps, epics, stories, sprint planning, dependencies, and delivery metrics). Build and lead a high-performing network security engineering organization with clear standards, reference architectures, reusable patterns, and strong collaboration across Network, Cloud, IAM, SOC, and application teams. Define and monitor engineering health metrics (availability, performance, change failure rate, MTTR, policy compliance, capacity), partnering with operations and the SOC to improve platform reliability and detection efficacy. Evaluate emerging technologies and vendor capabilities through proof-of-concepts and lab testing; provide recommendations that balance risk reduction, user experience, operational overhead, and total cost of ownership. Partner on budget planning and vendor management for the engineering portfolio (licensing, support, hardware/cloud consumption), ensuring investments are aligned to roadmap commitments and production support needs. Modernize network security engineering through automation and standardization, including policy-as-code, infrastructure-as-code, CI/CD for security changes, and repeatable deployment patterns across on-prem and cloud. Lead disciplined change management for engineering releases (implementation plans, test evidence, rollback procedures, stakeholder communications, and post-implementation validation) in partnership with operations and risk.

Requirements

  • Bachelor's degree in computer science or a related discipline, or equivalent work experience required; advanced degree preferred
  • 15+ years of experience in information security or related technology experience required; experience in the securities or financial services industry is a plus
  • 10+ years in network security engineering and/or platform engineering roles, including 5+ years leading teams and delivering enterprise-scale security platforms.
  • Deep hands-on expertise with network security technologies such as NGFWs, IDS/IPS, WAF/proxy/SWG, NAC, VPN/remote access, segmentation, SASE components, and cloud-native network security controls.
  • Proven ability to design, test, and certify solutions in a lab environment, producing implementation standards, test plans, evidence, and operational runbooks that support risk and regulatory expectations.
  • Strong stakeholder management and communication skills, able to translate engineering tradeoffs into clear decisions, timelines, and risk-based outcomes.
  • Proficiency with Jira for backlog management and delivery tracking (epics/stories, sprint planning, dashboards, and reporting); experience operating in Agile/DevOps delivery models.
  • Experience with automation and modern engineering practices (e.g., AI, scripting, APIs, infrastructure-as-code, CI/CD) to improve consistency, speed, and auditability of network security changes.

Responsibilities

  • Own Engineering delivery for the network security portfolio across the enterprise, including firewalls, IDS/IPS, secure web gateways, proxy, network access control (NAC), zero trust architectures, cloud security controls, and network threat detection solutions.
  • Lead the end-to-end engineering lifecycle from architecture and design through build, integration, and production rollout, ensuring solutions are secure-by-design, resilient, and scalable.
  • Ability to run formal lab validations for network security technologies (e.g., NGFW, SASE components, micro-segmentation), including design verification, performance testing, regression testing, and certification sign-off prior to production deployment.
  • Drive & uphold Network Security & Cloud engineering governance, delivery management, and prioritization using Agile practices and Jira (roadmaps, epics, stories, sprint planning, dependencies, and delivery metrics).
  • Build and lead a high-performing network security engineering organization with clear standards, reference architectures, reusable patterns, and strong collaboration across Network, Cloud, IAM, SOC, and application teams.
  • Define and monitor engineering health metrics (availability, performance, change failure rate, MTTR, policy compliance, capacity), partnering with operations and the SOC to improve platform reliability and detection efficacy.
  • Evaluate emerging technologies and vendor capabilities through proof-of-concepts and lab testing; provide recommendations that balance risk reduction, user experience, operational overhead, and total cost of ownership.
  • Partner on budget planning and vendor management for the engineering portfolio (licensing, support, hardware/cloud consumption), ensuring investments are aligned to roadmap commitments and production support needs.
  • Modernize network security engineering through automation and standardization, including policy-as-code, infrastructure-as-code, CI/CD for security changes, and repeatable deployment patterns across on-prem and cloud.
  • Lead disciplined change management for engineering releases (implementation plans, test evidence, rollback procedures, stakeholder communications, and post-implementation validation) in partnership with operations and risk.

Benefits

  • BNY offers highly competitive compensation, benefits, and wellbeing programs rooted in a strong culture of excellence and our pay-for-performance philosophy.
  • We provide access to flexible global resources and tools for your life’s journey.
  • Focus on your health, foster your personal resilience, and reach your financial goals as a valued member of our team, along with generous paid leaves, including paid volunteer time, that can support you and your family through moments that matter.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service