Security Engineer 2

Hills Bank and Trust Company

Iowa City (IA)

Hybrid

USD 100,000 - 140,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid remote option
Competitive benefits

Job summary

Hills Bank and Trust Company in Iowa City is seeking a Security Engineer 2 to join our security practice. This senior role engineers, operates, and continuously improves cybersecurity controls across on‑prem and cloud environments, aligning with risk and regulatory requirements.

You will mentor junior staff, participate in incident response, design and implement zero‑trust and least‑privilege strategies, and lead security workstreams while collaborating with IT teams.

Qualifications

  • Bachelor's degree in cybersecurity, information technology, computer science, engineering, or related field; equivalent experience considered.
  • Five or more years of progressive IT experience, including at least two years in cybersecurity engineering or operations.
  • Experience with Windows and Linux, networking, IAM, endpoint security, cloud security, audit/logging, vulnerability management, and incident response.
  • Familiarity with frameworks such as NIST CSF, CIS Controls, MITRE ATT&CK; certifications preferred.

Responsibilities

  • Engineer, operate, and improve security capabilities across SIEM, XDR/EDR, endpoint, network, identity, cloud, data protection, vulnerability management, and privileged access platforms.
  • Monitor, investigate, and respond to security incidents with containment, eradication, recovery, and stakeholder communication.
  • Lead Tier 2 and Tier 3 escalation; participate in on‑call response for time‑sensitive security events.
  • Develop and automate detection and response capabilities, including security analytics, alerts, queries, enrichment, evidence collection, response workflows, and reporting.
  • Document incidents and lessons learned, and update playbooks and procedures.
  • Lead vulnerability and exposure management activities across technology environments.
  • Conduct security architecture and design reviews for projects and vendor integrations.
  • Apply zero trust, least privilege, and strong authentication principles.

Skills

Security engineering
Incident response
Threat detection
Automation
PowerShell
Python
KQL
Zero trust

Education

Bachelor's degree in cybersecurity/related field
Equivalent education/experience

Tools

Microsoft Defender XDR
Sentinel
Entra ID
Intune
Purview
Azure security
Firewalls
Vulnerability management platforms

Job description

SCHEDULE: Full-time; Exempt. Typical hours are Monday-Friday (8:00 am – 5:00 pm)

LOCATION: Hills Bank Campus / Hybrid Remote Option

BENEFITS: Our employees are our most valuable assets, so we invest in them with a comprehensive and competitive benefits package. Our philosophy of taking care of the customer extends to taking care of our employees so that they, in turn, can take good care of themselves and their families. Join Hills Bank and let us surprise you with even more perks!

SCOPE:

The Security Engineer 2 is a senior security practitioner responsible for engineering, operating, and continuously improving the Bank's cybersecurity controls. The role combines hands‑on security operations, incident response, detection engineering, vulnerability management, identity and access security, endpoint and network protection, cloud security, data protection, automation, and security architecture. This position serves as a Tier 2 and Tier 3 escalation resource and translates threat, risk, compliance, and audit requirements into practical control improvements. The Security Engineer 2 provides clear, risk‑based recommendations to technical teams and leadership, mentors junior staff, and may lead security workstreams, technical evaluations, and response activities.

ACCOUNTABILITIES:
  • Engineer, operate, and continuously improve enterprise security capabilities across SIEM, XDR/EDR, endpoint, network, identity, email, cloud, data protection, vulnerability management, and privileged access platforms.
  • Monitor, investigate, and respond to security incidents by assessing scope and impact, preserving evidence, and coordinating containment, eradication, recovery, and stakeholder communication.
  • Serve as a Tier 2 and Tier 3 escalation resource and participate in assigned on‑call response for time sensitive security events.
  • Develop, tune, and automate detection and response capabilities, including security analytics, alerts, queries, enrichment, evidence collection, response workflows, and reporting to improve coverage, accuracy, and operational efficiency.
  • Document incidents and lessons learned, and use exercises and after‑action reviews to improve response procedures and plans.
  • Lead vulnerability and exposure management activities, including assessment, risk‑based prioritization, remediation coordination, exception management, retesting, and validation across technology environments.
  • Conduct security architecture and design reviews for projects, technology changes, products, cloud services, and vendor integrations.
  • Define and document practical security requirements, risks, and control recommendations aligned with business needs and risk tolerance.
  • Apply zero trust, least privilege, and strong authentication principles to control access to systems, applications, and data.
  • Use defense in depth and secure‑by‑design practices to embed effective controls throughout the technology lifecycle.
  • Implement network, system, and application segmentation to reduce exposure, restrict unauthorized access, and limit the impact of security events.
  • Incorporate resilience and recovery requirements into new and existing environments to support continuity and timely restoration following a disruption.
  • Develop and maintain secure configuration standards and hardening baselines across endpoints, servers, networks, cloud services, applications, and security tools.
  • Assess and improve security controls, posture management, and logging in Microsoft 365, Azure, and other approved cloud and software‑as‑a‑service environments.
  • Integrate security platforms with asset management, identity, ticketing, and change management processes to enable coordinated visibility, efficient investigations and response, and effective security lifecycle management.
  • Support data classification, encryption, data loss prevention, retention, and secure information management, partnering with business and control owners to implement data protection requirements.
  • Support penetration testing, control validation, and other authorized security testing. Analyze results and recommend corrective actions.
  • Perform security risk assessments, control testing, and compliance reviews. Collect evidence for regulatory examinations, audits, and independent assessments.
  • Provide technical input to third‑party risk reviews, contracts, solution assessments, and supply chain security evaluations.
  • Develop, deliver, or support security awareness training for Bank employees on relevant threats, policies, controls, and secure practices.
  • Use programming languages such as PowerShell, Python, KQL, and other approved methods to automate repeatable security engineering and operational work.
  • Communicate security posture, material findings, residual risk, remediation status, trends, metrics, and prioritized recommendations to technical teams and leadership.
  • Evaluate security technologies and services through requirements analysis, proof of concepts, risk assessments, total cost analysis, implementation planning, and operational supportability reviews.
  • Maintain accurate security procedures, playbooks, standards, technical documentation, inventories, records, and operational metrics.
  • Support third‑party security reviews and security awareness activities within assigned areas of responsibility.
  • Review artificial intelligence use cases for security, data protection, access, monitoring, and oversight requirements.
  • Mentor junior staff, share technical knowledge, and lead assigned security workstreams and response activities.
  • Contribute technical expertise to security strategy, architecture roadmaps, investment priorities, and continuous improvement initiatives.
  • Perform other duties as assigned.
EDUCATION AND SPECIAL REQUIREMENTS/PREFERENCES:
  • Bachelor's degree in cybersecurity, information technology, computer science, engineering, or a related field is preferred. An equivalent combination of education, relevant experience, and industry certifications may be considered.
  • Five or more years of progressive information technology experience, including at least two years of hands‑on cybersecurity engineering or operations and demonstrated experience investigating security events and administering enterprise security controls.
  • Working knowledge of Windows and Linux, networking, identity and access management, endpoint security, cloud security, audit/logging, vulnerability management, and incident response.
  • Enterprise security technology experience such as Microsoft Defender XDR, Sentinel, Entra ID, Intune, Purview, Azure security, firewalls, vulnerability management platforms, network monitoring, and privileged access tools.
  • Ability to use PowerShell, Python, Kusto Query Language, APIs, regular expressions, or similar scripting and query technologies.
  • Knowledge of recognized frameworks such as NIST CSF, CIS Controls, MITRE ATT&CK, and financial services regulatory guidance are preferred.
  • Relevant role‑aligned certifications are preferred, along with excellent analytical, troubleshooting, documentation, presentation, and interpersonal skills.
EQUAL OPPORTUNITY EMPLOYER/VETERANS/DISABILITY
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Sr. Security Engineer
Sr. Security Engineer

HKS Architects • Dallas (TX)

On-site
USD 120,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Cyber Security Engineer
Cyber Security Engineer

E & C Mid-Atlantic Ventures, LLC • Torch of Friendship (FL)

On-site
USD 90,000 - 130,000
Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Information Security Officer
Information Security Officer

City First Bank • Washington

On-site
USD 120,000 - 170,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Eleven Recruiting • Santa Monica (CA)

On-site
USD 140,000 - 190,000
Cyber Security Engineer III
Cyber Security Engineer III

First Citizens Bank • North Carolina

On-site
USD 110,000 - 150,000
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc. • Dallas (TX)

On-site
USD 90,000 - 130,000