Senior Information Security Engineer
First Tech Federal Credit Union · Hillsboro, OR · 2 days ago
On-siteInformation Technology$117k–$140k/yrFull-time
What You'll Do
- Perform independent assessments of information security risks, controls, and processes across technology environments, applications, infrastructure, and third-party relationships.
- Evaluate the design and effectiveness of security controls against established frameworks, regulatory requirements, and industry best practices.
- Identify, analyze, and communicate cybersecurity risks, vulnerabilities, control weaknesses, and emerging threats to risk and business stakeholders.
- Support governance and oversight of security domains including identity and access management, vulnerability management, cloud security, application security, data protection, and cybersecurity operations.
- Conduct risk assessments for new technologies, projects, systems, and business initiatives to evaluate potential security and operational risks.
- Provide effective challenge to first-line security practices, risk decisions, control implementations, and remediation strategies.
- Monitor and assess information security metrics, key risk indicators (KRIs), control effectiveness measures, and trends to identify emerging risks and opportunities for improvement.
- Support development and maintenance of information security risk management policies, standards, methodologies, and governance processes.
- Participate in regulatory examinations, internal audits, risk reviews, and compliance assessments by preparing analysis, documentation, and responses to requests.
- Partner with Technology, Information Security, Compliance, Enterprise Risk, Internal Audit, and business stakeholders to strengthen risk management practices and improve control maturity.
- Support oversight of third-party technology providers and critical vendor security risk management activities.
- Stay current on cybersecurity threats, regulatory developments, emerging technologies, and industry practices to evaluate potential impacts to the organization.
Essential Skills Required
- Education: Bachelors degree in field relevant to role (or 4 additional years of relevant experience in lieu of a degree)
- Experience: 4 - 6 years of relevant experience
- Knowledge: Of information security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or FFIEC guidance.
- Familiarity: With regulatory expectations applicable to financial services environments.
- Understanding: Of cybersecurity domains, but particularly artificial intelligence (AI), cloud security, network security, and data protection.
- Ability: To provide solutions which allow the safe usage of AI technologies in a financial services organization.
- Experience: With Model Context Protocol (MCP) governance.
- Experience: With Microsoft Copilot, OpenAI ChatGPT, Anthropic Claude and other similar technologies.
- Familiarity: With AI security tools such as Palo Alto Prisma AI runtime security (AIRS), Crowdstrike Falcon AI Detection and Response (AIDR) or other similar tools.
- Experience: With cloud security tooling such as Orca, Prisma Access Cloud, Wiz or other similar tools.
- Skills: Strong analytical and problem-solving skills with the ability to evaluate complex security and technology risks.
- Ability: To provide objective risk assessments and effective challenge while building collaborative stakeholder relationships.
- Support: The ability to “shift left” and incorporate security early on and throughout the development lifecycle.
- Communication: Strong written and verbal communication skills with the ability to translate technical concepts into business-focused risk discussions.
Location
Marlborough or Chelmsford, MA | Hillsboro, OR (HYBRID)
Target Compensation
$116,500 - $140,000 + annual bonus
Schedule
Monday through Friday 8a-5p