Jobs · Information Technology

Lead, Security Engineer V&CM

U.S. Financial Technology · United States · 1 wk ago
RemoteRemoteInformation Technology$157k–$181k/yrFull-time

About the Company

U.S. Financial Technology (U.S. FinTech) operates the largest and most advanced mortgage securitization platform in the world, supporting the Uniform Mortgage-Backed Security (UMBS) of Fannie Mae and Freddie Mac. The company supports 70% of the mortgage-backed securities in the market, providing best-in-class single-family issuance, bond administration, disclosure, and tax services. U.S. FinTech manages a broad portfolio of products with full lifecycle management through its market-leading, cloud-based, end-to-end platform, which executes transactions at an extraordinary scale to bolster liquidity in the secondary mortgage market.

Responsibilities

  • Act as a Subject Matter Expert for all programs within the Vulnerability and Configuration Management (VCM) space, including conducting comprehensive vulnerability assessments using tools such as Wiz and Tenable.
  • Leverage analytical and problem-solving skills to identify weaknesses in U.S. FinTech’s IT infrastructure and communicate findings effectively to prioritize remediation.
  • Track, prioritize, and ensure remediation of vulnerabilities and compliance issues using established processes.
  • Continuously monitor U.S. FinTech’s infrastructure for vulnerability and compliance-related issues and improve monitoring, scanning, dashboards, and reporting.
  • Configure, tune, and maintain vulnerability management tools, and collaborate with Security Architecture on new build-outs, technologies, and environments to ensure VCM coverage.
  • Develop and implement new security baselines for CIS, DISA STIG, and custom baselines.
  • Correlate vulnerabilities with threat intelligence to assess exploitability and risk, and work with the Cyber Security Operations Center to ensure mitigations are in place during remediation.
  • Provide detailed risk assessments for discovered vulnerabilities and enforce remediation timelines in accordance with Standard Operating Procedures.
  • Collaborate with IT and DevOps teams to ensure timely remediation of vulnerabilities, conduct regular and ad-hoc vulnerability scans, and integrate tools with all cloud environments.
  • Ensure complete coverage of all IT environments and alignment with internal security policies, regulatory requirements (NIST/SOC), and industry best practices.
  • Support audits and assessments by providing evidence and documentation.
  • Act as a liaison between security, IT, development, and risk teams, providing clear, actionable recommendations to both technical and non-technical audiences.
  • Mentor junior analysts and provide guidance and training to junior members of the VCM team.
  • Identify gaps in vulnerability or compliance management programs and propose improvements.
  • Develop and maintain Standard Operating Procedures, frameworks, and job aids/how-tos.

Requirements

  • Bachelor’s degree or equivalent in Computer Science, Information Systems, Cyber Security, or a related technical field. A Master’s degree is a plus.
  • Minimum of 7 years of experience in security engineering and operations, including managing and supporting large, complex mission-critical systems.
  • Experience with vulnerability management tools, patching processes, VM operations/workflows, or configuration/baseline/file-integrity monitoring applications and processes.
  • Authorization to work in the U.S. without requiring employer sponsorship currently or in the future.

Skills

  • Subject matter expertise in cloud-based critical infrastructure systems and security threats (AWS Cloud experience required).
  • Deep knowledge of cybersecurity in vulnerability and compliance management.
  • Familiarity with the latest security vulnerabilities, advisories, incidents, penetration techniques, and countermeasures.
  • Strong understanding of AI models, technologies, attack paths, vulnerabilities, and securing AI tools or technologies, including experience leveraging AI models to identify, research, or remediate vulnerabilities.
  • Expertise in network and system vulnerabilities, malware, networking protocols, multi-tiered applications, and attack methods.
  • Experience in a senior technical security role, including network security, operating system security, internet/web security, and vulnerability testing.
  • Strong knowledge of networking fundamentals such as TCP/IP, packet analysis, network engineering, and LAN/WAN technologies and topologies.
  • Experience conducting comprehensive vulnerability assessments with tools like Wiz and Tenable.
  • General knowledge and experience in Windows/Linux operating systems, baseline security configurations, audits, forensics, and patch management.
  • Experience developing Standard Operating Procedures (SOPs), job aids, and hands-on training materials.
  • Ability to work in a fast-paced environment with occasional on-call activities.
  • Excellent interpersonal, presentation, and verbal/written communication skills.
  • Self-starter with adaptability to change, motivated to set and track personal and program goals.
  • Ability to manage multiple priorities, projects, deliverables, and stakeholders.
  • Strong influencing skills to collaborate cross-functionally and achieve objectives.
  • Active in the security industry with external networking relationships to maintain knowledge of best practices, tactics, strategies, and technologies.
  • AWS Security or AWS Architect certifications are desired.

Pay

$156,500 to $181,000. This range is a general guideline and not a guarantee of compensation. Additional factors such as qualifications, skills, competencies, experience, internal equity, market data, and applicable bargaining agreements may influence the final offer.

Benefits

  • Competitive total compensation package, including a performance bonus and 401k match.
  • Healthcare coverage.
  • Paid time off (PTO).
  • A broad range of other benefits.

Similar jobs

Lead Security Engineer

The ODP GroupAustin, TX· 2 days ago
Information Technologyapply on careers.theodpgroup.com

Lead Security Engineer

Thomson ReutersEagan, MN· 2 days ago
$118k/yrapply on thomsonreuters.wd5.myworkdayjobs.com

Lead Security Engineer

NTT DATA North AmericaWashington, PA· 2 mo ago
Information Technologyapply on careers.services.global.ntt