Senior Security Engineer, Information Technology

NISA Investment Advisors, LLC•Clayton, MO
•Onsite

About The Position

As Senior Security Engineer on NISA's Cybersecurity team within the Technology Operations Group, you are a senior individual contributor who engineers and operates security controls across identity and access management (IAM), privileged access management (PAM), cloud, artificial intelligence (AI), security operations and vulnerability management, partnering with the Deputy CISO and IT engineering.

Requirements

  • Bachelor's degree in computer science, cybersecurity or a related field, or equivalent experience
  • 7+ years of IT or security experience, including 5+ years of hands-on security engineering
  • Hands-on enterprise IAM and PAM engineering (e.g., Entra ID, Okta, CyberArk, BeyondTrust)
  • Hands-on experience securing AWS and/or Azure and engineering SIEM/SOAR and EDR platforms
  • Proficiency in security automation and IaC (e.g., Python, PowerShell, Terraform)
  • Strong command of core security concepts across all domains (least privilege, zero trust, cryptography, network security, risk management, secure development) and frameworks such as NIST CSF, SOC 2 and MITRE ATT&CK
  • Demonstrated mentorship and ability to explain technical risk to nontechnical stakeholders

Nice To Haves

  • AI security, financial services or Microsoft 365 security (Defender, Purview) experience
  • CISSP, CCSP, AWS Security – Specialty, AZ-500, SC-300 or GIAC certification

Responsibilities

  • Engineer and operate identity platforms (Entra ID, Active Directory, SSO), enforcing phishing-resistant multifactor authentication (MFA) and conditional access; automate joiner/mover/leaver and access reviews; govern non-human identities; respond to identity-based threats
  • Administer the PAM platform (vaulting, rotation, session recording); drive least privilege and just-in-time elevation across servers, databases, network, cloud and SaaS; implement tiered administration; centralize secrets management
  • Enforce AWS and Azure guardrails (landing zones, identity, segmentation, encryption and key management); operate cloud posture and workload protection tooling; embed policy-as-code in infrastructure as code (IaC) and CI/CD pipelines; secure Microsoft 365 and SaaS
  • Pilot and build guardrails for approved AI tooling and firmwide AI adoption; assess AI systems and vendors for prompt injection, data leakage and excessive agent permissions (NIST AI RMF, OWASP LLM Top 10); enforce least privilege and logging for AI agents; monitor unapproved AI use; use AI-assisted engineering with human review of production-bound output
  • Engineer and tune SIEM/SOAR, endpoint detection and response (EDR) and logging for detections mapped to MITRE ATT&CK; advance automation-first detection and response; lead incident response, forensics and root-cause analysis; maintain playbooks, run tabletop exercises and threat hunt
  • Operate scanning across network, container, cloud, application and endpoint environments; prioritize remediation by exploitability and asset criticality; conduct assessments and partner on penetration testing; maintain secure configuration and patch baselines
  • Apply zero trust, defense-in-depth and secure-by-design principles to new systems; engineer network and email security (segmentation, remote access, DNS filtering, DMARC); support data loss prevention, encryption and PKI; partner on secure development and threat modeling
  • Operate controls aligned with NIST CSF, SOC 2 and applicable regulations; support client and vendor due diligence; produce security metrics; maintain policies and standards
  • Support disaster recovery testing and security awareness; mentor junior engineers; maintain runbooks and architecture diagrams; participate in on-call rotation; perform other duties as assigned

Benefits

  • health, dental, vision and life insurance options
  • paid time off
  • a competitive retirement plan
  • onsite cafeteria
  • fitness center
  • a health and wellness program
  • an educational assistance program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service