At MFS, you will find a culture that supports you in doing what you do best. Our employees work together to reach better outcomes, favoring the strongest idea over the strongest individual. We put people first and demonstrate care and compassion for our community and each other. Because what we do matters - to us as valued professionals and to the millions of people and institutions who rely on us to help them build more secure and prosperous futures.
THE ROLE
A technical security resource responsible for implementing, and maintaining security measures to protect personnel, property, and information assets. This role combines demonstrated abilities in various information security disciplines across multiple security domains with solid understanding of security technologies and platforms.
The role also requires a developed understanding of modern technology, with a solid understanding of related IT disciplines and how they interoperate.
Some characteristics include troubleshooting efforts of multiple security technologies and controls, developing control design(s), supporting monitoring efforts, maintaining a solid understanding of the field, its practices and controls, and its related technologies, and staying current of current technologies, threats, vulnerabilities and exposures.
The Sr. Security Engineer is an active participant and contributor multiple security-related activities and may participate one or more program(s), project(s), scope of work, or processes that drive results.
This role requires some oversight and guidance.
WHAT YOU WILL DO
- Subject matter resource in one or more disciplines in the field of Cyber/Information Security, while maintaining a solid understanding of the field, its programs, practices and controls, and its related technologies, threats, vulnerabilities, risks and exposures.
- Influences the implementation, integration and maintenance of enterprise-class security programs and solutions with quality outcomes, such as incident response, identity and access management, cloud, application and network security, key and certificate management, vulnerability management, threat detection, security information and event management and able to quickly learn and adapt solutions as introduced to the security technology portfolio.
- Support efforts for the assessment, establishment and monitor countermeasures that protect, detect and/or deter when an unauthorized and/or suspicious activity.
- Works closely with senior security practitioners and technology and business groups to assess, identify, design and implement security controls, processes, procedures and solutions within risk tolerance.
- Supporting the assessment, identification, design, and implementation of approved methods and technologies to automate manual security-related tasks, improving efficiency and quality wherever practicable and appropriate.
- Supports and administers enterprise identity, authentication, access governance, privileged access, and Application Identity Management (AIM) processes, helping ensure appropriate access controls are maintained throughout the identity lifecycle .
- Monitors and analyzes database access and activity, privileged user activity, and sensitive data access patterns to identify unauthorized, suspicious, or policy-violating behavior.
- Maintains and supports security governance, risk, compliance, policy, and control management processes, including the Archer control registry, control validation, evidence collection, issue tracking, and audit support.
- Develops and implements security automation, scripting, orchestration, reporting, and workflow improvements that reduce manual effort, improve data quality, and strengthen control effectiveness.
- Evaluates and applies artificial intelligence and machine learning capabilities in accordance with approved AI policy and governance to enhance security operations, monitoring, analysis, investigation, and operational efficiency, while assessing and helping defend against AI-related risks.
- Delivers peer-reviewed security risk assessment and due diligence outcomes to methodically analyze technology, solutions and processes, identifying risks from both a technical and business perspective, and recommending strategies to mitigate within risk tolerances.
- Assists with security investigations according to documented procedures and management's directives.
- Maintains confidentiality in these matters and works to ensure the confidentiality of other information which is encountered during the discharge of security responsibilities.
- Advances projects of moderate complexity, having broad goals and agreed upon outcomes, under some supervision.
- Accountable for meeting assigned performance and project objectives, including timelines and budget, provides innovative suggestions for solutions and executes plans.
- Effectively communicates to supervisor, often technical, cyber security concepts clearly and accurately through non-technical means, to ensure that all stakeholders are