Security Engineer
Celtic Bank · Salt Lake City, UT · 2 wk ago
HybridFull-time
About the Role
Celtic Bank is seeking a skilled Security Engineer to help protect the Bank's systems, data, and technology environment. This role is responsible for identifying, reducing, and continuously managing internal and external security risks while leading key security initiatives across identity, network, endpoint, and cloud environments.
Responsibilities
- Administer, configure, and maintain the Rapid7 attack surface management platform, including discovery scope, scan configuration, and exposure triage.
- Build and maintain a consolidated asset inventory using the attack surface management tool, reconciling discovered assets against authoritative systems of record.
- Own cyber asset attack surface management (CAASM), correlating asset, vulnerability, and tool-coverage data to identify unmanaged, unprotected, or misconfigured assets.
- Lead the modern desktop authentication project, implementing two-factor authentication for endpoint sign-in across the environment.
- Lead the Secure Access Service Edge (SASE) conversion project, including design, phased rollout, policy definition, and migration from legacy network access controls.
- Lead the cloud access security broker (CASB) and SaaS security posture management (SSPM) projects, establishing policy, monitoring, and remediation workflows for sanctioned and unsanctioned cloud applications.
- Maintain CrowdStrike endpoint protection, including sensor deployment and health, policy tuning, detection triage, and coverage reporting.
- Maintain the Dashlane enterprise password management platform, including provisioning, group and sharing standards, and adoption reporting.
- Support incident management and response, including investigation, containment, and post-incident remediation for endpoint, identity, and cloud events.
- Track and report security posture metrics, including asset coverage, attack surface exposure, two-factor enrollment, and project milestones, to IT and security leadership.
- Develop and maintain technical documentation, including tool configurations, project designs, operational procedures, and runbooks.
Requirements
- Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field, or equivalent combination of education and experience; security certifications (e.g., Security+, CySA+, SSCP) preferred.
- 3-5 years of hands-on experience in information security or enterprise IT, with a focus on attack surface, endpoint, and identity security.
- Demonstrated experience administering an attack surface management platform (Rapid7 or comparable) and building asset inventory from discovery data.
- Experience with endpoint detection and response tooling, preferably CrowdStrike, including policy configuration, sensor health, and detection triage.
- Working knowledge of SASE, CASB, and SSPM concepts, with experience supporting or leading the deployment of at least one.
- Experience implementing multi-factor authentication for endpoint or workstation sign-in, and familiarity with enterprise password management platforms such as Dashlane.
- Understanding of information security principles, data classification, and regulatory requirements applicable to financial institutions (e.g., GLBA, FFIEC, ISO 27001).
- Experience participating in incident response, including investigation, containment, and remediation, and the ability to lead technical projects across multiple teams.
- Strong analytical, troubleshooting, and documentation skills, with the ability to communicate technical concepts clearly to both technical and non-technical audiences.
Benefits
- Medical, dental, and vision coverage
- 401(k) with employer match
- Life and long-term disability coverage
- HSA and FSA plans
- Paid holidays and paid time off
- Robust wellness program (catered meals three times a week, lunch and learns, and onsite gym)
Schedule
This position operates in a professional office environment. Utah-based employees may be eligible for a hybrid work schedule after an initial training period in the Salt Lake City, Utah office. All employees, regardless of location, may be required to travel to the Salt Lake City office for mandatory company meetings, events, or related occasions.
Physical and Other Requirements
- Routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets, and fax machines.
- Frequently required to stand, walk, use hands to type, handle documents, and perform other office-related duties.
- Exerts up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull, or otherwise move objects.
- Occasionally moves between work sites and inside the office to access file cabinets, office machinery, etc.
- Regularly required to communicate (talk or hear) and must be able to read, write, and understand fluent English.