Principal Security Engineer

vnbcareers

Morristown (NJ)

On-site

USD 150,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

vnbcareers seeks an accomplished security leader to build and govern enterprise security engineering capabilities across vulnerability management, cloud and application security, and risk management. You will drive risk-based assessments, partner with Engineering and IT, and advance AI security governance.

The role emphasizes designing Zero Trust controls, evolving security architecture, and mentoring teams while aligning with regulatory requirements and business goals.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience.
  • Minimum of 10 years of experience in information security with deep enterprise vulnerability management.

Responsibilities

  • Establish and maintain security engineering capabilities and processes including vulnerability management, secure configuration management, patch governance, security testing, remediation, secure software development, and security automation.
  • Assess, secure, and govern emerging technologies including AI/ML solutions with security requirements, risk frameworks, data protection controls, and model governance.
  • Lead and evolve enterprise security architecture, engineering, and cyber risk management across vulnerability, cloud, app, infrastructure, identity, and emerging tech domains.
  • Drive risk-based security assessments across infrastructure, cloud, apps, endpoints, identities, and external surfaces with stakeholders to reduce risk.
  • Design, implement, and govern security controls aligned to Zero Trust principles including IAM, PAM, authentication/authorization models, conditional access, segmentation, and continuous verification.
  • Develop and maintain security architecture standards, reference designs, and patterns for cloud, infrastructure, apps, APIs, data protection, and AI-enabled solutions.
  • Own API Security and Integration Governance with secure authentication, authorization, encryption, traffic management, and onboarding of new services.
  • Enhance security visibility by integrating platforms, cloud inventories, asset management, identity, AI analytics, ticketing, and workflows for better detection and response.
  • Provide technical security leadership, governance, metrics, and risk reporting, supporting audits and mentoring teams on best practices.

Skills

Vulnerability mgmt
Asset management
Threat modeling
Secure cloud architecture
Risk management
OWASP Top 10
Application security
Banking regulations
Communication skills
Cross-functional leadership

Education

Bachelor's degree
Master's degree

Job description

Responsibilities include but are not limited to:
  • Establish and maintain security engineering capabilities and processes, including vulnerability management, secure configuration management, patch governance, security testing, penetration testing remediation, secure software development practices, and security automation.
  • Assess, secure, and govern emerging technologies, including AI and machine learning solutions, establishing security requirements, risk frameworks, data protection controls, model governance practices, and responsible AI security standards across the organization.
  • Lead and evolve enterprise security architecture, engineering, and cyber risk management capabilities, establishing strategy, standards, and roadmaps across vulnerability management, cloud security, application security, infrastructure security, identity security, and emerging technology domains.
  • Drive risk-based security assessments and remediation efforts across infrastructure, cloud platforms, applications, endpoints, identities, and external attack surfaces, partnering with Engineering, IT, Product, and business stakeholders to reduce enterprise risk and improve security resilience.
  • Design, implement, and govern security controls aligned to Zero Trust principles, including identity and access management, privileged access management, authentication and authorization models, conditional access policies, segmentation strategies, and continuous verification approaches.
  • Develop and maintain security architecture standards, reference designs, and engineering patterns for cloud, infrastructure, applications, APIs, data protection, identity services, and AI-enabled solutions, ensuring alignment with business objectives and regulatory requirements.
  • Own API Security and Integration Governance, defining security standards, configuration baselines, and architectural guardrails while ensuring secure API authentication, authorization, encryption, traffic management, and onboarding of new services across enterprise environments.
  • Enhance security visibility, telemetry, and automation by integrating security platforms, cloud inventories, asset management systems, identity platforms, AI-powered analytics, ticketing systems, and operational workflows to improve detection, prioritization, and response capabilities.
  • Provide technical security leadership, governance, and strategic direction, developing executive-level metrics and risk reporting, supporting audit and regulatory readiness, serving as a subject matter expert across security architecture, engineering, identity, and vulnerability management, and mentoring team members on security best practices and innovation.
Required Skills:
  • Deep knowledge of enterprise vulnerability management frameworks, processes, and lifecycle management across infrastructure, cloud, application, endpoint environments.
  • Strong understanding of asset management concepts, including ITAM, CMDB, asset ownership and lifecycle governance.
  • Expert knowledge in threat modeling and risk management.
  • Strong understanding of secure cloud architecture principles, shared responsibility models, common cloud configuration risks.
  • Strong analytical skills to correlate vulnerability data, asset criticality and exposure to drive meaningful prioritization.
  • Familiarity with OWASP top 10 and web application security principles
  • Strong knowledge of application security, web and application design, databases, operating systems, hypervisors, IP networks, microservices, container technology, system integration technologies and securing cloud-based applications.
  • Strong understanding of banking regulations and third-party risk.
  • Excellent verbal and written communication skills.
  • Strong interpersonal skills to facilitate building positive working relationships at all levels within the bank.
  • Ability to handle multiple priorities simultaneously.
  • Ability to lead cross-functional discussions, remediation working sessions, and status forums to drive accountability and reduce risk.
Required Experience:
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience. Minimum of 10 years of experience in information security, with significant depth in enterprise vulnerability management within complex, hybrid environments.
Preferred Experience:
  • Master's degree in Computer Science, Information Systems, Cybersecurity and experience in regulated industries such as financial services. Minimum of 5 years of experience designing, operating and maturing vulnerability management programs.
  • Industry certifications such as CISSP, CISM, CRISC, or relevant GIAC certifications.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Security Engineer
Principal Security Engineer

Valley Bank • Morristown (NJ)

On-site
USD 180,000 - 240,000
Principal Security Engineer
Principal Security Engineer

Valley National Bank • Morristown (NJ)

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

Hrimoveisararaquara • Alhambra (CA)

On-site
USD 150,000 - 230,000
Director, Cyber Strategy & Architecture
Director, Cyber Strategy & Architecture

vnbcareers • Morristown (NJ)

On-site
USD 150,000 - 220,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Fortis Industries, Inc. DBA - LTS, Inc. • Atmore (AL)

On-site
USD 100,000 - 140,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000
Security Engineer
Security Engineer

PRI Technology • New York (NY)

On-site
USD 120,000 - 180,000
Group Director, Cyber Risk & Security Engineering
Group Director, Cyber Risk & Security Engineering

Brobston Group LLC • New York (NY)

On-site
USD 180,000 - 240,000
Security Guardian
Security Guardian

Shain Associates • United States

On-site
USD 250,000 - 350,000
Security Engineer
Security Engineer

RouteOne • Farmington Hills (MI)

On-site
USD 85,000 - 115,000