Jobs · Idaho

Sr. IT Security Engineer

Savers | Value Village · Meridian, ID · 3 wk ago
On-siteOther

About Us

As one of the largest for-profit thrift operators in the United States, Canada, and Australia, we champion reuse and inspire a future where secondhand is second nature. We supply our stores with gently-used, one-of-a-kind items donated by the community to local nonprofit organizations. By purchasing these items directly from our partners, we redirect billions of pounds of used goods away from landfills and provide valuable funding for community-based programs. Our mission is supported by millions of loyal customers and over 22,000 team members across 300+ stores.

Our brands include Savers (U.S.), 2nd Ave (U.S.), Value Village (U.S. and Canada), Unique (U.S.), Village des Valeurs (Quebec), and Savers Australia.

What You Can Expect

  • Celebrate uniqueness in a diverse, inclusive workplace with people from varied backgrounds and perspectives.
  • Work in a purpose-driven company with a business model focused on planetary and community impact.
  • Investment in your career growth and development, aligned with our aggressive store expansion plans.

Comprehensive onboarding and training from day one, including in-house expertise through Savers University, which develops 90% of our training internally.

Benefits

  • Bundled health plans: medical, prescription, dental, and vision.
  • Company-paid life insurance for added protection and peace of mind.
  • Programs for smoking cessation, diabetes management coaching, and on-demand care options.
  • 401k plan with generous company matching contributions.
  • Paid time off for leisure or personal hobbies.
  • Mental health services to support daily life management.

Responsibilities

  • Collaborate with cross-functional teams to drive internal security, privacy, and risk governance initiatives across the enterprise.
  • Create and maintain Enterprise Policies, Standards, and Guideline documentation to align with industry frameworks.
  • Serve as a trusted security and risk advisor to stakeholders, offering actionable guidance that balances technical controls with business priorities.
  • Provide continuous security and compliance guidance for internal projects, technology evaluations, and daily operational issues.
  • Conduct detailed security and risk assessments of business applications, cloud workloads, and critical processes to identify control gaps, residual risks, and mitigation plans.
  • Communicate security risks, vulnerabilities, and recommended treatments to both technical and non-technical teams, ensuring clear risk awareness and accountability.
  • Partner with Solutions Delivery and Engineering teams to embed secure-by-design principles, risk controls, and governance checkpoints throughout the SDLC.
  • Participate in project teams and initiatives as a dedicated Security Advisor and risk representative from planning through operationalization.
  • Monitor and analyze emerging threats, regulatory changes, and vendor advisories, assessing their relevance to Savers’ risk posture.
  • Establish and manage risk and threat metrics, control scorecards, and compliance health monitoring to measure and communicate program effectiveness.
  • Collaborate closely with IT, Audit, Legal, and Business teams to ensure consistent governance, risk, and compliance alignment.
  • Maintain deep industry expertise and contribute to policy updates, control documentation, and audit readiness activities.

Requirements

  • Strong experience ensuring security, privacy, and risk governance for Internet-facing systems, SaaS applications, and cloud services.
  • Comprehensive understanding of Internet security issues, risk assessment methodologies, and mitigation strategies.
  • Experience with security tooling, automation, and control monitoring to improve visibility and reduce operational risk.
  • Technical expertise in security engineering, network and system security, authentication protocols, cryptography, and application security testing.
  • Practical experience in threat modeling, risk analysis, and control validation.
  • Knowledge of security vulnerabilities, risk treatment plans, and compensating control strategies.
  • Familiarity with security frameworks, standards, and protocols relevant to enterprise governance (e.g., NIST, ISO 27001, SOC 2, PCI DSS).
  • Excellent written and verbal communication skills, with the ability to translate technical findings into risk-based business context.
  • Analytical, resourceful, and organized, with a proactive approach to identifying and mitigating potential security risks.
  • Strong collaboration skills with a willingness to provide clear, actionable feedback in complex or sensitive governance discussions.
  • Proficiency with one or more interpreted programming or scripting languages (Python, JavaScript, Ruby, PowerShell, etc.) to support security automation and compliance evidence collection.

Qualifications

  • 8+ years’ experience in information security.
  • Industry certifications such as CISSP, CCSP, CISM, and CRISC preferred.
  • B.S. or M.S. in computer science or related field, or equivalent professional experience.

Physical Requirements

  • Ability to lift and carry up to 30 lbs.
  • Ability to express or exchange ideas by means of the spoken word.
  • Ability to receive detailed information through verbal communication and make discriminations in sound.
  • Ability to receive detailed information visually through written communication (both physical and electronic).

Schedule

Hybrid (2 days/week in Boise, ID). Travel: 10% or less.

Similar jobs

Sr. IT Security Engineer

Republic AirwaysCarmel, IN· 2 days ago
Information Technologyapply on republicairways.contacthr.com

Sr Security Engineer

MeijerMichigan, United States· 1 mo ago
Information Technologyapply on meijer.wd5.myworkdayjobs.com