Jobs · Information Technology · Massachusetts

Senior Information Security Engineer

First Tech Federal Credit Union · Marlborough, MA · 2 days ago
On-siteInformation Technology$117k–$140k/yrFull-time

About the role

This role provides independent Second Line of Defense (2LOD) oversight and risk assessment of the organization’s information security program, controls, and technology environment. The position supports the identification, assessment, monitoring, and reporting of information security risks to ensure alignment with the organization's risk appetite, regulatory expectations, and industry standards.

Responsibilities

  • Perform independent assessments of information security risks, controls, and processes across technology environments, applications, infrastructure, and third-party relationships.
  • Evaluate the design and effectiveness of security controls against established frameworks, regulatory requirements, and industry best practices.
  • Identify, analyze, and communicate cybersecurity risks, vulnerabilities, control weaknesses, and emerging threats to risk and business stakeholders.
  • Support governance and oversight of security domains including identity and access management, vulnerability management, cloud security, application security, data protection, and cybersecurity operations.
  • Conduct risk assessments for new technologies, projects, systems, and business initiatives to evaluate potential security and operational risks.
  • Provide effective challenge to first-line security practices, risk decisions, control implementations, and remediation strategies.
  • Monitor and assess information security metrics, key risk indicators (KRIs), control effectiveness measures, and trends to identify emerging risks and opportunities for improvement.
  • Support development and maintenance of information security risk management policies, standards, methodologies, and governance processes.
  • Participate in regulatory examinations, internal audits, risk reviews, and compliance assessments by preparing analysis, documentation, and responses to requests.
  • Partner with Technology, Information Security, Compliance, Enterprise Risk, Internal Audit, and business stakeholders to strengthen risk management practices and improve control maturity.
  • Support oversight of third-party technology providers and critical vendor security risk management activities.
  • Stay current on cybersecurity threats, regulatory developments, emerging technologies, and industry practices to evaluate potential impacts to the organization.

Essential Skills Required

  • Education: Bachelors degree in field relevant to role (or 4 additional years of relevant experience in lieu of a degree)
  • Experience: 4 - 6 years of relevant experience
  • Knowledge: Of information security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or FFIEC guidance.
  • Familiarity: With regulatory expectations applicable to financial services environments.
  • Understanding: Of cybersecurity domains, particularly artificial intelligence (AI), cloud security, network security, and data protection.
  • Ability: To provide solutions which allow the safe usage of AI technologies in a financial services organization.
  • Experience: With Model Context Protocol (MCP) governance.
  • Experience: With Microsoft Copilot, OpenAI ChatGPT, Anthropic Claude and other similar technologies.
  • Familiarity: With AI security tools such as Palo Alto Prisma AI runtime security (AIRS), Crowdstrike Falcon AI Detection and Response (AIDR) or other similar tools.
  • Experience: With cloud security tooling such as Orca, Prisma Access Cloud, Wiz or other similar tools.
  • Skills: Strong analytical and problem-solving skills with the ability to evaluate complex security and technology risks.
  • Ability: To provide objective risk assessments and effective challenge while building collaborative stakeholder relationships.
  • Support: The ability to “shift left” and incorporate security early on and throughout the development lifecycle.
  • Communication: Strong written and verbal communication skills with the ability to translate technical concepts into business-focused risk discussions.

Location

Marlborough or Chelmsford, MA (HYBRID)

Target Compensation

$116,500 - $140,000 + annual bonus

Schedule

Monday through Friday 8a-5p

Similar jobs