Lead, Security Engineer V&CM
About the Company
U.S. Financial Technology (U.S. FinTech) operates the largest and most advanced mortgage securitization platform in the world, supporting the Uniform Mortgage-Backed Security (UMBS) of Fannie Mae and Freddie Mac. The company supports 70% of the mortgage-backed securities in the market, providing best-in-class single-family issuance, bond administration, disclosure, and tax services. U.S. FinTech manages a broad portfolio of products with full lifecycle management through its market-leading, cloud-based, end-to-end platform, which executes transactions at an extraordinary scale to bolster liquidity in the secondary mortgage market.
Responsibilities
- Act as a Subject Matter Expert for all programs within the Vulnerability and Configuration Management (VCM) space, including conducting comprehensive vulnerability assessments using tools such as Wiz and Tenable.
- Leverage analytical and problem-solving skills to identify weaknesses in U.S. FinTech’s IT infrastructure and communicate findings effectively to prioritize remediation.
- Track, prioritize, and ensure remediation of vulnerabilities and compliance issues using established processes.
- Continuously monitor U.S. FinTech’s infrastructure for vulnerability and compliance-related issues and improve monitoring, scanning, dashboards, and reporting.
- Configure, tune, and maintain vulnerability management tools, and collaborate with Security Architecture on new build-outs, technologies, and environments to ensure VCM coverage.
- Develop and implement new security baselines for CIS, DISA STIG, and custom baselines.
- Correlate vulnerabilities with threat intelligence to assess exploitability and risk, and work with the Cyber Security Operations Center to ensure mitigations are in place during remediation.
- Provide detailed risk assessments for discovered vulnerabilities and enforce remediation timelines in accordance with Standard Operating Procedures.
- Collaborate with IT and DevOps teams to ensure timely remediation of vulnerabilities, conduct regular and ad-hoc vulnerability scans, and integrate tools with all cloud environments.
- Ensure complete coverage of all IT environments and alignment with internal security policies, regulatory requirements (NIST/SOC), and industry best practices.
- Support audits and assessments by providing evidence and documentation.
- Act as a liaison between security, IT, development, and risk teams, providing clear, actionable recommendations to both technical and non-technical audiences.
- Mentor junior analysts and provide guidance and training to junior members of the VCM team.
- Identify gaps in vulnerability or compliance management programs and propose improvements.
- Develop and maintain Standard Operating Procedures, frameworks, and job aids/how-tos.
Requirements
- Bachelor’s degree or equivalent in Computer Science, Information Systems, Cyber Security, or a related technical field. A Master’s degree is a plus.
- Minimum of 7 years of experience in security engineering and operations, including managing and supporting large, complex mission-critical systems.
- Experience with vulnerability management tools, patching processes, VM operations/workflows, or configuration/baseline/file-integrity monitoring applications and processes.
- Authorization to work in the U.S. without requiring employer sponsorship currently or in the future.
Skills
- Subject matter expertise in cloud-based critical infrastructure systems and security threats (AWS Cloud experience required).
- Deep knowledge of cybersecurity in vulnerability and compliance management.
- Familiarity with the latest security vulnerabilities, advisories, incidents, penetration techniques, and countermeasures.
- Strong understanding of AI models, technologies, attack paths, vulnerabilities, and securing AI tools or technologies, including experience leveraging AI models to identify, research, or remediate vulnerabilities.
- Expertise in network and system vulnerabilities, malware, networking protocols, multi-tiered applications, and attack methods.
- Experience in a senior technical security role, including network security, operating system security, internet/web security, and vulnerability testing.
- Strong knowledge of networking fundamentals such as TCP/IP, packet analysis, network engineering, and LAN/WAN technologies and topologies.
- Experience conducting comprehensive vulnerability assessments with tools like Wiz and Tenable.
- General knowledge and experience in Windows/Linux operating systems, baseline security configurations, audits, forensics, and patch management.
- Experience developing Standard Operating Procedures (SOPs), job aids, and hands-on training materials.
- Ability to work in a fast-paced environment with occasional on-call activities.
- Excellent interpersonal, presentation, and verbal/written communication skills.
- Self-starter with adaptability to change, motivated to set and track personal and program goals.
- Ability to manage multiple priorities, projects, deliverables, and stakeholders.
- Strong influencing skills to collaborate cross-functionally and achieve objectives.
- Active in the security industry with external networking relationships to maintain knowledge of best practices, tactics, strategies, and technologies.
- AWS Security or AWS Architect certifications are desired.
Pay
$156,500 to $181,000. This range is a general guideline and not a guarantee of compensation. Additional factors such as qualifications, skills, competencies, experience, internal equity, market data, and applicable bargaining agreements may influence the final offer.
Benefits
- Competitive total compensation package, including a performance bonus and 401k match.
- Healthcare coverage.
- Paid time off (PTO).
- A broad range of other benefits.