Senior Information Security Engineer

Digital Federal Credit Union

Marlborough (MA)

Hybrid

USD 117,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical/Dental/Vision
401(k) match
Paid time off
Paid holidays
Employee lending discounts

Job summary

First Tech Federal Credit Union is seeking a Second Line of Defense risk professional to oversee information security program risk across technology, cloud, and data protection. You will assess controls, communicate findings, and foster risk-aware decisions with stakeholders in a hybrid setup.

Responsibilities include risk assessments for new tech, governance of security domains, and reporting on risks and trends to leadership.

Qualifications

  • Bachelor's degree in a field related to the role or 4 extra years of relevant experience.
  • 4–6 years of information security experience.
  • Knowledge of NIST CSF, NIST 800-53, ISO 27001, CIS Controls, FFIEC guidance.
  • Understanding of cloud, AI, network security, and data protection.
  • Ability to provide safe usage guidance for AI in finance.
  • Experience with MCP governance.
  • Familiar with Microsoft Copilot, OpenAI tools and similar tech.
  • Experience with Azure and AWS security controls.
  • Experience with cloud security tooling (Orca, Prisma Access, Wiz).
  • Strong analytical and problem-solving skills.
  • Effective risk communication to business stakeholders.
  • Shift-left security mindset across development lifecycles.

Responsibilities

  • Perform independent assessments of information security risks, controls, and processes.
  • Evaluate design and effectiveness of security controls against frameworks and requirements.
  • Identify, analyze, and communicate cybersecurity risks to stakeholders.
  • Support governance of security domains including IAM, vulnerability, cloud, data protection.
  • Conduct risk assessments for new technologies and initiatives.
  • Provide challenge to risk decisions and remediation strategies.
  • Monitor KRIs, control effectiveness, and security trends.
  • Develop and maintain risk management policies and governance processes.
  • Participate in regulatory examinations and internal audits with documentation.
  • Collaborate with Technology, Compliance, Risk, Internal Audit and business units.
  • Prepare reporting and presentations on technical risks and gaps.
  • Oversee third-party technology providers and vendor risk activities.
  • Stay current on cybersecurity threats and regulatory developments.

Skills

Information security
Risk assessment
NIST CSF / 800-53
Cloud security
AI security governance
Regulatory compliance
MCP governance
Azure & AWS
Communication
Stakeholder mgmt

Education

Bachelor's degree or 4 years experience

Job description

Description

This role provides independent Second Line of Defense (2LOD) oversight and risk assessment of the organization's information security program, controls, and technology environment. The position supports the identification, assessment, monitoring, and reporting of information security risks to ensure alignment with the organization's risk appetite, regulatory expectations, and industry standards. Through risk analysis, control evaluations, and effective challenge, this role helps strengthen the organization's cybersecurity posture and operational resilience.

Here’s what you can expect from the job and what you need to be successful:

What You’ll Do
  • Perform independent assessments of information security risks, controls, and processes across technology environments, applications, infrastructure, and third-party relationships.
  • Evaluate the design and effectiveness of security controls against established frameworks, regulatory requirements, and industry best practices.
  • Identify, analyze, and communicate cybersecurity risks, vulnerabilities, control weaknesses, and emerging threats to risk and business stakeholders.
  • Support governance and oversight of security domains including identity and access management, vulnerability management, cloud security, application security, data protection, and cybersecurity operations.
  • Conduct risk assessments for new technologies, projects, systems, and business initiatives to evaluate potential security and operational risks.
  • Provide effective challenge to first-line security practices, risk decisions, control implementations, and remediation strategies.
  • Monitor and assess information security metrics, key risk indicators (KRIs), control effectiveness measures, and trends to identify emerging risks and opportunities for improvement.
  • Support development and maintenance of information security risk management policies, standards, methodologies, and governance processes.
  • Participate in regulatory examinations, internal audits, risk reviews, and compliance assessments by preparing analysis, documentation, and responses to requests.
  • Partner with Technology, Information Security, Compliance, Enterprise Risk, Internal Audit, and business stakeholders to strengthen risk management practices and improve control maturity.
  • Prepare reporting and presentations that communicate technical risks, control gaps, and security trends to a variety of audiences.
  • Support oversight of third-party technology providers and critical vendor security risk management activities.
  • Stay current on cybersecurity threats, regulatory developments, emerging technologies, and industry practices to evaluate potential impacts to the organization.
Essential Skills
  • Required Education: Bachelors degree in field relevant to role (or 4 additional years of relevant experience in lieu of a degree)
  • Required Experience: 4 - 6 years of relevant experience
  • Knowledge of information security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or FFIEC guidance. Familiarity with regulatory expectations applicable to financial services environments.
  • Understanding of cybersecurity domains, but particularly artificial intelligence (AI), cloud security, network security, and data protection.
  • Ability to provide solutions which allow the safe usage of AI technologies in a financial services organization.
  • Experience with Model Context Protocol (MCP) governance
  • Experience with Microsoft Copilot, OpenAI ChatGPT, Anthropic Claude and other similar technologies.
  • Familiarity with AI security tools such as Palo Alto Prisma AI runtime security (AIRS), Crowdstrike Falcon AI Detection and Response (AIDR) or other similar tools.
  • Deep experience with securing and governing Microsoft Azure and Amazon Web Services (AWS).
  • Experience with cloud security tooling such as Orca, Prisma Access Cloud, Wiz or other similar tools.
  • Strong analytical and problem-solving skills with the ability to evaluate complex security and technology risks.
  • Ability to provide objective risk assessments and effective challenge while building collaborative stakeholder relationships.
  • Support the ability to "shift left" and incorporate security early on and throughout the development lifecycle.
  • Strong written and verbal communication skills with the ability to translate technical concepts into business-focused risk discussions.
Location

Marlborough or Chelmsford, MA | Hillsboro, OR (HYBRID)

Target Compensation

$116,500 - $140,000 + annual bonus

Schedule

Monday through Friday 8a-5p

Who We Are

Every great journey begins with a bold idea-and ours is no different. First Tech and DCU were founded on the belief that financial solutions should put people first. That belief has fueled decades of innovation and service, rooted in the tech sector and expanding to support members from all walks of life.

What makes First Tech different?

Every great journey begins with a bold idea-and ours is no different. First Tech and DCU were founded on the belief that financial solutions should put people first. That belief has fueled decades of innovation and service, rooted in the tech sector and expanding to support members from all walks of life.

Employees are eligible for:
  • Traditional medical, dental, and vision coverage
  • Generous 401(k) match
  • Paid Time Off: You’ll accrue up to 15 days in your first year. In addition, you’ll receive 40 hours of sick time and 3 personal days, which refresh annually
  • Paid federal holidays
  • Special employee pricing on lending products such as mortgage, auto, and personal loans (eligibility subject to standard account requirements and underwriting criteria)
Employment Statements:

First Tech is an equal opportunity employer, and we value diversity, inclusion, and equity at our company. We evaluate qualified applicants without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.

If you’re applying for a job and need a reasonable accommodation for any part of the employment process, please send an email to recruiters@firsttechfed.com and let us know the nature of your request and contact information. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this email address.

First Tech is not currently offering Visa transfer/sponsorship for this position.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Engineer
Senior Information Security Engineer

Digital Federal Credit Union • Hillsboro (OR)

Hybrid
USD 117,000 - 140,000
Traditionally medical, dental, and视觉
Generous 401(k) match
Paid Time Off: up to 15 days + 40 sick
+2
Senior Information Security Engineer
Senior Information Security Engineer

First Tech Federal Credit Union • Marlborough (MA)

Hybrid
USD 117,000 - 140,000
Health insurance
401(k) match
Paid time off
+2
VP, Fraud Risk Management
VP, Fraud Risk Management

First Tech Federal Credit Union • Hillsboro (OR)

Hybrid
USD 220,000 - 260,000
Medical, dental, and vision coverage
Generous 401(k) match
Paid Time Off and holidays
+1
VP, Fraud Risk Management
VP, Fraud Risk Management

First Tech Federal Credit Union • Marlborough (MA)

Hybrid
USD 220,000 - 260,000
Medical benefits
401(k) match
Paid time off
+1
Director, Internal Audit - Compliance
Director, Internal Audit - Compliance

First Tech Federal Credit Union • Hillsboro (OR)

On-site
USD 164,000 - 197,000
Health insurance
401(k) match
Paid time off
+2
Director, Internal Audit - Compliance
Director, Internal Audit - Compliance

First Tech Federal Credit Union • Marlborough (MA)

On-site
USD 164,000 - 197,000
Medical, dental, and vision coverage
Generous 401(k) match
Paid time off and holidays
Director, Internal Audit - Compliance
Director, Internal Audit - Compliance

First Tech Federal Credit Union • Chelmsford (MA)

On-site
USD 164,000 - 197,000
Medical coverage
Dental coverage
Vision coverage
+4
Director, Internal Audit - Operational Risk
Director, Internal Audit - Operational Risk

Digital Federal Credit Union • Hillsboro (OR)

On-site
USD 164,000 - 197,000
Medical, dental, vision coverage
401(k) match
PTO & holidays
+1
Director, Internal Audit - Operational Risk
Director, Internal Audit - Operational Risk

Digital Federal Credit Union • Chelmsford (MA)

On-site
USD 164,000 - 197,000
Medical/Dental/Vision
401(k) match
Paid time off
+1
Director, Internal Audit - Operational Risk
Director, Internal Audit - Operational Risk

First Tech Federal Credit Union • Hillsboro (OR)

Hybrid
USD 164,000 - 197,000
Health, dental, vision benefits
401(k) match
Paid time off & holidays
+1