Security Engineer

Socket.dev

California (MO)

Hybrid

USD 120,000 - 145,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Retirement Plan
HSA/FSA options
Paid Time Off
Telehealth services
Employee Assistance Program (EAP)
Travel Reimbursement

Job summary

Sierra Central Credit Union is seeking a Security Engineer to design, implement, and maintain the organization’s cybersecurity program in a hybrid work setting from Northern California. The role focuses on cloud security, identity protection, incident response, and risk governance within a regulated financial environment.

You will partner with internal teams and external providers to strengthen controls, perform threat detection, and drive security awareness across the organization.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, CS, or a related field or equivalent experience.
  • Minimum of four years hands‑on cybersecurity engineering in a Microsoft‑centric environment.
  • Experience implementing and supporting Microsoft 365 security and compliance solutions.
  • Experience in incident investigation, security event analysis, and response activities.
  • Experience administering email security platforms and phishing awareness programs.
  • Experience supporting risk management, audit, or compliance initiatives in regulated environments.
  • Familiarity with NCUA/FFIEC/GLBA would be a plus.

Responsibilities

  • Implement and optimize Microsoft 365 security and compliance solutions (Defender XDR, Entra ID, Intune, Purview).
  • Configure security controls for SharePoint Online, OneDrive, Teams, and DLP/sensitivity labeling.
  • Administer email security technologies including anti‑phishing and DMARC/SPF/DKIM.
  • Manage phishing simulations and security awareness training.
  • Assist with incident investigations, containment, remediation, and post‑incident reporting.
  • Coordinate with MDR providers for monitoring and threat detection.
  • Support vulnerability management through scanning, risk assessment, and remediation tracking.
  • Assist enterprise risk management, third‑party risk reviews, and regulatory examinations.
  • Ensure compliance with GLBA Safeguards and related financial security standards.
  • Contribute to data protection programs, governance, and insider risk monitoring.
  • Monitor security events across network, endpoint, cloud, and identity platforms.

Skills

Cybersecurity principles
Microsoft 365 security
Cloud security controls
Email security protocols
Firewall/VPN security
Incident investigation
Vulnerability management
Regulatory/compliance
Analytical thinking
Communication skills
Project prioritization
Independent work and teamwork

Education

Bachelor’s degree in Cybersecurity/IT/CS/IS
4+ years hands-on cybersecurity engineering
Experience with Microsoft 365 security solutions
Experience with incident analysis and response
Experience administering email security platforms
Experience supporting risk management/compliance

Tools

SIEM
EDR
MSSP/MDR

Job description

Description
About the Opportunity

Sierra Central Credit Union is a member-owned financial institution that has served Northern California communities for more than 70 years. The Security Engineer is responsible for implementing and maintaining the Credit Union's cybersecurity infrastructure, controls, and security operations program. This role plays a key part in developing and operationalizing Sierra Central Credit Union’s cybersecurity program and ensuring the security of information systems, networks, applications, and data. The Security Engineer partners with internal departments, third-party security providers, and regulatory stakeholders to protect the organization from cyber threats while maintaining compliance with applicable regulatory and industry standards.

The position reports to the VP of Information and Cyber Security and works closely with the Information Security Specialist and members of the Information Systems and Information Technology (ISIT) team. The Security Engineer serves as a technical security expert and resource for the organization, supporting risk management, incident response, audit readiness, data protection, and cybersecurity awareness initiatives.

Essential Functions

1. Implement, administer, and optimize Microsoft 365 E5 security and compliance solutions, including Defender XDR, Entra ID, Intune, Purview, and Defender for Cloud Apps.

2. Configure and maintain security controls for SharePoint Online, OneDrive, Teams, and other cloud collaboration platforms, including data loss prevention (DLP), sensitivity labelling, information protection, sharing controls, and application governance.

3. Administer enterprise email security technologies, including anti-phishing, anti-malware, impersonation protection, secure email gateway policies, and email authentication protocols such as SPF, DKIM, and DMARC.

4. Manage and report on the organization's phishing simulation and security awareness training program.

5. Assist with cybersecurity incident investigations and response activities, including threat triage, containment, remediation, root‑cause analysis, and post‑incident reporting.

6. Coordinate with managed detection and response (MDR) providers and other security partners to support ongoing monitoring and threat detection activities.

7. Support vulnerability management efforts through asset scanning, risk assessment, remediation tracking, and penetration testing initiatives.

8. Assist with enterprise risk management activities, including security control design, documentation, evidence collection, third‑party risk reviews, and regulatory examinations.

9. Support compliance with applicable laws, regulations, and industry standards, including GLBA Safeguards Rule requirements and other financial industry security expectations.

10. Participate in data protection and privacy initiatives, including data classification, data governance, insider risk monitoring, and information protection programs.

11. Monitor, analyze, and respond to security events, alerts, and suspicious activity across network, endpoint, cloud, and identity platforms.

12. Develop and maintain security documentation, standards, procedures, and operational guidelines.

13. Collaborate with business units and IT teams to identify and mitigate cybersecurity risks.

14. Provide technical guidance, mentoring, and cybersecurity training to junior staff and colleagues.

15. Remain current on emerging security threats, vulnerabilities, technologies, and industry best practices.

16. Perform other duties and projects as assigned.

Requirements
Required Skills and Abilities

1. Strong knowledge of cybersecurity principles, security architecture, threat detection, incident response, and risk management practices.

2. Advanced knowledge of Microsoft 365 security and compliance technologies, including Defender, Entra ID, Intune, Purview, and cloud security controls.

3. Proficiency in securing cloud collaboration platforms, including SharePoint Online, OneDrive, and Teams.

4. Knowledge of email security technologies and protocols, including anti-phishing controls, SPF, DKIM, and DMARC.

5. Experience with firewall administration, VPN technologies, network security practices, and related security tools.

6. Ability to investigate and analyze security incidents using logs, endpoint telemetry, identity data, and forensic evidence.

7. Understanding of vulnerability management processes and remediation practices.

8. Knowledge of regulatory, audit, and compliance requirements within a regulated industry environment.

9. Strong analytical, problem‑solving, and decision‑making skills.

10. Excellent written, verbal, and interpersonal communication skills with the ability to communicate technical concepts to both technical and non‑technical audiences.

11. Ability to prioritize multiple projects and deadlines in a fast‑paced environment.

12. Ability to work independently while collaborating effectively across departments and with third‑party vendors.

Education and Experience
Required

1. Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or an equivalent combination of education and experience.

2. Minimum of four (4) years of hands‑on cybersecurity engineering experience, including significant experience within a Microsoft-centric enterprise environment.

3. Experience implementing and supporting Microsoft 365 security and compliance solutions.

4. Experience with incident investigation, security event analysis, and response activities.

5. Experience administering email security platforms and phishing awareness programs.

6. Experience supporting risk management, audit, or compliance initiatives in a regulated environment.

Preferred

1. Experience within the financial services, banking, or credit union industry.

2. Familiarity with NCUA, FFIEC, GLBA, and related regulatory requirements.

3. Professional certifications such as CISSP, CISM, GIAC, Microsoft SC‑100, SC‑200, SC‑400, or comparable security certifications.

4. Experience with SIEM engineering, including analytics rule development, security automation, and alert triage workflows.

5. Experience working with Endpoint Detection and Response (EDR) solutions and managed security service providers (MSSP/MDR).

6. Knowledge of privacy frameworks and regulations, including GLBA and CCPA/CPRA.

7. Demonstrated experience mentoring, training, or developing security or IT professionals.

Physical Requirements and Work Environment

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential function of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  1. Prolonged periods of sitting at a desk and working on a computer – 7 to 8 hours per day.
  2. Light lifting, carrying, pushing and/or pulling objects up to 25 lbs.
  3. Intermittent walking, bending, twisting and stooping.
  4. General office environment: works generally at a desk in a well‑lighted, air‑conditioned cubicle/office, with moderate noise levels.
  5. Occasional exposure to raised floors, server noise, and limited hot/cold zones.
Work Location

This position is located at our Corporate Headquarters in Yuba City, CA, with hybrid work options available.

Compensation Range

The company anticipates offering an annual salary range between $120,000 to $145,000 for this position at the time of hire. This range includes base salary (or hourly wages) and does not include possible overtime for non‑exempt employees or any applicable performance‑based incentives or commissions.

Annual Merit Increase

Employees are eligible for a discretionary yearly merit‑based salary adjustment, based on individual performance and company results.

Comprehensive Benefits Package

We provide a robust benefits package designed to support your health, financial security, and work‑life balance including:

  • Medical, Dental & Vision Insurance options
  • Voluntary Lines including hospital indemnity, accident, and critical illness policies
  • Company Paid HRA (with enrollment in certain health plans)
  • Company Paid Basic Term Life Insurance
    • Coverage at 2× annual base salary
  • Company Paid Long‑Term Disability Insurance for Full‑Time Employees
  • Company Paid Telehealth Services Membership (Teladoc)
  • Company Paid Employee Assistance Program (EAP)
  • 401(k) Retirement Plan
    • Employer‑funded safe harbor contribution of 3% of employee's eligible earnings
    • Discretionary employer match on employee contributions
  • Flexible Spending Accounts
    • HSA
    • Medical FSA
    • Dependent Care FSA
    • Limited Purpose FSA
  • Paid Time Off
    • Vacation accruals based on status and tenure within company
    • 12 sick days accrued annually for full‑time employees
    • 1 hour for every 30 hours worked for part‑time employees
    • 11 paid holidays
  • Travel Expense Reimbursement
    • All necessary and work‑related travel expenses will be reimbursed in accordance with company policy

The preceding list of duties does not include all tasks and responsibilities that may be required with this position. Additional tasks may be assigned, as departmental and operational needs require.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Sierra Central Credit Union • Yuba City (CA)

Hybrid
USD 120,000 - 145,000
Medical, Dental & Vision Insurance
401(k) Retirement Plan
Paid Time Off
+1
Cybersecurity Analyst
Cybersecurity Analyst

Auto Glass Specialists • Flint (MI)

On-site
USD 85,000 - 125,000
Information Security Engineer
Information Security Engineer

Farmers & Merchants Bank of Long Beach • Seal Beach (CA)

On-site
USD 114,000 - 194,000
Security Administrator
Security Administrator

SAFE FCU • Sumter (SC)

On-site
USD 60,000 - 80,000
Cybersecurity Analyst
Cybersecurity Analyst

Financial-Plus-Credit-Union • Flint (MI)

On-site
USD 90,000 - 120,000
Cybersecurity Analyst
Cybersecurity Analyst

Myfpcu • Flint (MI)

On-site
USD 85,000 - 115,000
Sr IT Security Engineer
Sr IT Security Engineer

Cornerstone Capital Bank • Houston (TX)

On-site
USD 120,000 - 180,000
Senior Network & Systems Engineer
Senior Network & Systems Engineer

Monroe Community Credit Union • Monroe (MI)

On-site
USD 110,000 - 150,000
Information Security Engineer
Information Security Engineer

International Executive Service Corps • Lenexa (KS), Northern (KY)

Hybrid
USD 95,000 - 180,000
Medical, Dental, Vision
Life/AD&D
Supplemental Life/AD&D
+6
Information Security Engineer
Information Security Engineer

Clinical Reference Laboratory • Lenexa (KS)

On-site
USD 95,000 - 180,000
Medical, Dental, Vision
Life/AD&D
Section 125 FSA Plan
+4