Principal Security Engineer

Valley Bank

Morristown (NJ)

On-site

USD 180,000 - 240,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Valley Bank is seeking a Principal Security Engineer to lead enterprise vulnerability management across on-premises, cloud, and third-party environments. The role collaborates with Technology, Infrastructure, Cloud, Risk, and Compliance teams to align security with regulatory expectations and risk objectives.

You will design, implement and govern security controls, drive risk-based remediation, and mentor teammates while delivering executive-level metrics and reporting on security posture.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience.
  • Minimum of 10 years of information security experience in hybrid environments.
  • Deep expertise in enterprise vulnerability management across infrastructure, cloud, and applications.

Responsibilities

  • Establish and maintain security engineering capabilities and processes for vulnerability management and secure configuration.
  • Assess and govern emerging technologies, including AI, with risk frameworks and data protection.
  • Lead security architecture, standards, and roadmaps across vulnerability management, cloud security, application security, infrastructure security, identity security, and emerging technology domains.
  • Drive risk-based assessments and remediation across infrastructure, cloud platforms, applications, endpoints, identities, and external attack surfaces.
  • Design and govern security controls aligned to Zero Trust principles.
  • Develop security architecture standards and patterns for cloud, data, APIs, and AI-enabled solutions.
  • Own API Security and Integration Governance across enterprise environments.
  • Enhance security visibility through integration of platforms and automation.
  • Provide technical security leadership, governance, and executive metrics.

Skills

Vulnerability management
Asset management
Threat modeling
Cloud security
OWASP Top 10
App security
Regulatory risk
Communication
Cross-functional leadership
Prioritization

Education

Bachelor's degree in Computer Science/Information Security/Cybersecurity
Master's degree (preferred)

Job description

At Valley Bank, we believe in people's growth potential. We invest in it. We protect it. We focus it. For nearly 100 years, we've been the Bank that clients from every industry turn to for our expertise, strategies, and advice--building the kind of trust that can fuel every goal. We are the leading relationship bank built for growth--with over $60 billion in assets, 3,800 experts, and more than 200 consumer branches and commercial banking offices in communities across the US.

At Valley, we're all driven by an ambition that goes deeper than just having a job. That's why when you work for us, we make it our goal to help you focus on what drives you--working to turn your passions and strengths into assets you can use to propel your ambitions and build the professional legacy you want. Because when we say we're a relationship bank built for growth, that's not just reserved for our clients--that includes all our associates as well.

The Principal Security Engineer is responsible for the enterprise vulnerability management program and its integration with asset and configuration management systems. This role ensures accurate asset visibility, risk based vulnerability prioritization, and effective remediation tracking across on premises, cloud, and third party environments. The position partners closely with Technology, Infrastructure, Cloud, Risk, and Compliance teams to align vulnerability management practices with regulatory expectations and enterprise risk management objectives.

Responsibilities Include But Are Not Limited To
  • Establish and maintain security engineering capabilities and processes, including vulnerability management, secure configuration management, patch governance, security testing, penetration testing remediation, secure software development practices, and security automation.
  • Assess, secure, and govern emerging technologies, including AI and machine learning solutions, establishing security requirements, risk frameworks, data protection controls, model governance practices, and responsible AI security standards across the organization.
  • Lead and evolve enterprise security architecture, engineering, and cyber risk management capabilities, establishing strategy, standards, and roadmaps across vulnerability management, cloud security, application security, infrastructure security, identity security, and emerging technology domains.
  • Drive risk-based security assessments and remediation efforts across infrastructure, cloud platforms, applications, endpoints, identities, and external attack surfaces, partnering with Engineering, IT, Product, and business stakeholders to reduce enterprise risk and improve security resilience.
  • Design, implement, and govern security controls aligned to Zero Trust principles, including identity and access management, privileged access management, authentication and authorization models, conditional access policies, segmentation strategies, and continuous verification approaches.
  • Develop and maintain security architecture standards, reference designs, and engineering patterns for cloud, infrastructure, applications, APIs, data protection, identity services, and AI-enabled solutions, ensuring alignment with business objectives and regulatory requirements.
  • Own API Security and Integration Governance, defining security standards, configuration baselines, and architectural guardrails while ensuring secure API authentication, authorization, encryption, traffic management, and onboarding of new services across enterprise environments.
  • Enhance security visibility, telemetry, and automation by integrating security platforms, cloud inventories, asset management systems, identity platforms, AI-powered analytics, ticketing systems, and operational workflows to improve detection, prioritization, and response capabilities.
  • Provide technical security leadership, governance, and strategic direction, developing executive-level metrics and risk reporting, supporting audit and regulatory readiness, serving as a subject matter expert across security architecture, engineering, identity, and vulnerability management, and mentoring team members on security best practices and innovation.
Required Skills
  • Deep knowledge of enterprise vulnerability management frameworks, processes, and lifecycle management across infrastructure, cloud, application, endpoint environments.
  • Strong understanding of asset management concepts, including ITAM, CMDB, asset ownership and lifecycle governance.
  • Expert knowledge in threat modeling and risk management.
  • Strong understanding of secure cloud architecture principles, shared responsibility models, common cloud configuration risks.
  • Strong analytical skills to correlate vulnerability data, asset criticality and exposure to drive meaningful prioritization.
  • Familiarity with OWASP top 10 and web application security principles
  • Strong knowledge of application security, web and application design, databases, operating systems, hypervisors, IP networks, microservices, container technology, system integration technologies and securing cloud-based applications.
  • Strong understanding of banking regulations and third-party risk.
  • Excellent verbal and written communication skills.
  • Strong interpersonal skills to facilitate building positive working relationships at all levels within the bank.
  • Ability to handle multiple priorities simultaneously.
  • Ability to lead cross-functional discussions, remediation working sessions, and status forums to drive accountability and reduce risk.
Required Experience
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience. Minimum of 10 years of experience in information security, with significant depth in enterprise vulnerability management within complex, hybrid environments.
Preferred Experience
  • Master's degree in Computer Science, Information Systems, Cybersecurity and experience in regulated industries such as financial services. Minimum of 5 years of experience designing, operating and maturing vulnerability management programs.
  • Industry certifications such as CISSP, CISM, CRISC, or relevant GIAC certifications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Architect - Enterprise Vulnerability Cloud
Senior Security Architect - Enterprise Vulnerability Cloud

Valley Bank • Morristown (NJ)

On-site
USD 180,000 - 240,000
Director, Cyber Strategy & Architecture
Director, Cyber Strategy & Architecture

Valley Bank • Morristown (TN)

On-site
USD 130,000 - 160,000
Security Engineer 2 - Cyber Security
Security Engineer 2 - Cyber Security

WesBanco Bank Inc. • Youngstown (OH)

On-site
USD 80,000 - 110,000
Security Engineer 2 - Cyber Security
Security Engineer 2 - Cyber Security

WesBanco Bank Inc. • Toledo (OH)

On-site
USD 80,000 - 110,000
Security Engineer 2 - Cyber Security
Security Engineer 2 - Cyber Security

WesBanco Bank Inc. • Fairmont (WV)

On-site
USD 75,000 - 95,000
Security Engineer 2 - Cyber Security
Security Engineer 2 - Cyber Security

WesBanco Bank Inc. • Frankfort (KY)

On-site
USD 75,000 - 100,000
Security Engineer 2 - Cyber Security
Security Engineer 2 - Cyber Security

WesBanco Bank Inc. • Ross Township

On-site
USD 85,000 - 110,000
Security Engineer 2 - Cyber Security
Security Engineer 2 - Cyber Security

WesBanco Bank Inc. • Fort Wayne (IN)

On-site
USD 80,000 - 100,000
Security Engineer 2 - Cyber Security
Security Engineer 2 - Cyber Security

WesBanco Bank Inc. • Findlay (OH)

On-site
USD 90,000 - 120,000
Security Engineer 2 - Cyber Security
Security Engineer 2 - Cyber Security

WesBanco Bank Inc. • Cincinnati (OH)

On-site
USD 80,000 - 100,000