
Senior IT Security Engineer
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in United States.
• Assist in the advancement and enhancement of the organization's security program, focusing on security architecture, emerging technologies, AI assessments, IAM governance, vulnerability management, and third-party security.
• Recognize, evaluate, mitigate, and verify cybersecurity risks and security measures.
• Aid in security assurance, control effectiveness, remediation validation, security engineering, automation, and ongoing enhancement.
• Evaluate security measures, pinpoint risks and gaps, and assist in remediation and validation efforts.
• Utilize security technologies, engineering methodologies, and automation to fortify controls and minimize manual tasks.
• Assist in the development of security metrics, reporting, and monitoring initiatives.
• Engage in cybersecurity incident response, investigations, drills, and post-incident evaluations.
• Contribute to the formulation of security standards, procedures, and technical recommendations.
• Collaborate with Technology, business units, Risk, Compliance, Audit, and other relevant parties.
• Oversee the enterprise phishing awareness initiative, which includes monthly simulations, metrics analysis, risk tracking, and ongoing enhancements.
• Perform security architecture assessments for applications, infrastructure, cloud services, SaaS platforms, AI solutions, and third-party technologies.
• Evaluate risks associated with AI and emerging technologies and engage in AI governance activities.
• Review requirements for authentication, authorization, encryption, data protection, logging, monitoring, resiliency, and recovery.
• Confirm security requirements and controls throughout the implementation and operational phases.
• Take part in vendor evaluations, technology assessments, and project planning activities.
• Provide oversight for IAM and conduct independent verification of IAM, privileged access, authentication, vulnerability management, and third-party security controls.
• Administer and supervise identity lifecycle processes, RBAC, privileged access, segregation of duties, PAM, SSO, MFA, Conditional Access, and identity federation.
• Support Microsoft Entra ID, Active Directory, and associated identity management platforms.
• Execute access reviews, control testing, audit support, regulatory examination assistance, and remediation validation.
• Develop cybersecurity metrics, KRIs, KPIs, and management-level reporting.
• Lead the enterprise vulnerability management efforts, including prioritization, remediation tracking, validation, and reporting.
• Review vulnerability assessments, penetration test results, red-team exercises, and technical security evaluations.
• Manage vulnerability exceptions, risk acceptances, and compensatory controls.
• Participate in third-party security reviews, vendor risk assessments, due diligence, monitoring, and reassessment activities.
• Evaluate third-party controls, safeguards, resilience, incident response, data protection, and supply-chain risks.
• Collaborate with Vendor Management, Procurement, Legal, Privacy, Compliance, and business stakeholders.
• Bachelor’s degree in information technology, Cybersecurity, Computer Science, or a related field is preferred.
• Experience in banking, financial services, mortgage lending, fintech, or other highly regulated sectors is essential.
• Proficient knowledge of FFIEC guidance, banking regulatory expectations, and cybersecurity obligations applicable to financial institutions.
• Familiarity with FDIC examinations, internal audits, external audits, and cybersecurity control evaluations.
• Strong comprehension of the NIST Cybersecurity Framework (CSF), CIS Controls, and risk-based cybersecurity approaches.
• Familiarity with AI governance, AI risk management concepts, and secure integration of emerging technologies.
• Over 5 years of experience in cybersecurity, information security, or security engineering is required.
• Experience in supporting Identity and Access Management programs, processes, and technologies.
• Experience in conducting security architecture assessments and technical risk evaluations.
• Experience in managing or supporting enterprise vulnerability management programs is advantageous.
• Experience in conducting vendor security assessments and third-party security evaluations.
• Proficiency with Microsoft Entra ID, Active Directory, Microsoft 365 security technologies, and cloud platforms.
• Preferred certifications include CISSP, CISA, CompTIA Security+, ISC2 Certified in Cybersecurity (CC), Microsoft SC-900, Microsoft AZ-900, Microsoft SC-300.
• Additional cybersecurity, cloud security, or identity-focused certifications are desirable.
• Ability to sit for extended periods.
• Dexterity to operate computer keyboards, mice, and other computing devices.
• Ability to lift 30–40 lbs and relocate equipment as necessary.
• Willingness to travel to various locations as required.
• Ability to participate in training sessions, presentations, and meetings.
• Recognized as a Fortune-certified Great Place to Work®.
• Acknowledged as a Top Workplace.
• Occasional evening and weekend work may be necessary to meet deadlines.
• Reasonable accommodations available for individuals with disabilities.
• Opportunities for training sessions, presentations, and meetings.
• Flexibility to work remotely.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.