Security Engineering & Architecture
Why This Role Stands Out
This hybrid Security Engineering & Architecture role offers a fantastic opportunity to build and shape cutting-edge security solutions across cloud, data, and AI environments, with significant hands-on technical leadership. You'll thrive here if you're a senior practitioner eager to mentor a team while remaining deeply technical, driving secure innovation for a reputable firm. Apply to leverage your expertise and grow your career in a dynamic setting.
Quick Overview
Job Description
Security Engineering Lead will lead and execute cybersecurity engineering across our existing on-premises infrastructure, new AWS cloud environment, Snowflake data platform, and emerging AI application ecosystem.
This is not a pure oversight or policy role. The primary need is a senior technical security practitioner who can hands-on design, build, harden, implement, troubleshoot, and continuously improve security controls. The role will manage and mentor a small team of talented security engineers, but the individual must remain deeply hands-on and comfortable acting as the senior technical architect executor for cybersecurity engineering.
The ideal candidate has strong financial services experience, has previously helped secure a new AWS environment from the ground up, understands traditional infrastructure and data center security, and can help the Bank safely adopt cloud, data, and AI technologies.
Key Responsibilities
1. Security Engineering & Architecture
Own the design, implementation, and continuous improvement of security controls across infrastructure, cloud, applications, data platforms, and AI solutions.
Responsibilities include:
- Design and implement practical security architectures for on-premises systems, AWS, Snowflake, and internally developed AI applications.
- Translate cybersecurity standards and risk requirements into deployable technical controls.
- Build secure-by-design patterns for identity, network segmentation, encryption, logging, monitoring, endpoint protection, vulnerability management, and access governance.
- Serve as a senior technical security advisor to infrastructure, engineering, data, AI, and vendor teams.
- Evaluate new technologies and ensure security requirements are embedded early in design and delivery.
- AWS security is a critical part of this role. AWS defines cloud security as a shared responsibility model, where AWS is responsible for security “of” the cloud and customers are responsible for security “in” the cloud. This role will own the Bank’s side of that responsibility across identity, networking, data protection, monitoring, governance, and workload security.
2. AWS Cloud Security
Lead the security design and implementation for the Bank’s new AWS environment.
Responsibilities include:
- Secure a new AWS environment from initial design through operationalization.
- Implement multi-account security patterns, IAM controls, least privilege access, SCPs, logging, monitoring, encryption, secrets management, vulnerability scanning, and network segmentation.
- Design secure VPC, subnet, routing, security group, and NACL patterns.
- Implement controls across services such as IAM, Organizations, CloudTrail, CloudWatch, GuardDuty, Security Hub, Config, KMS, Secrets Manager, Macie, Inspector, S3, Lambda, RDS, EC2, ECS/EKS as applicable.
- Partner with infrastructure and engineering teams to embed security into CI/CD, IaC, cloud provisioning, and operational support.
- Establish AWS security baselines and exception management processes.
- AWS specifically highlights data protection, encryption in transit, IAM, infrastructure security, security groups, subnet controls, resilience, and compliance validation as part of managing security responsibilities for Amazon VPC.
3. On-Premises Infrastructure & Data Center Security
Own security engineering for the Bank’s existing data center and infrastructure environment.
Responsibilities include:
- Maintain and improve controls across servers, endpoints, firewalls, networks, Active Directory, privileged access, remote access, vulnerability management, patching, EDR, SIEM/logging, backup security, and segmentation.
- Strengthen identity and access controls across Microsoft/Windows environments.
- Support remediation of audit findings and security gaps across existing infrastructure.
- Partner with IT operations to ensure cybersecurity controls are practical, sustainable, and operationally reliable.
- Help modernize legacy security patterns while reducing operational risk.
4. Snowflake & Data Platform Security
Support the secure implementation and operation of Snowflake and the Bank’s broader data platform.
Responsibilities include:
- Design and review Snowflake access controls, role hierarchy, authentication, MFA/SSO integration, network policies, data classification, masking, row-level access, and audit logging.
- Partner with data engineering and analytics teams to ensure sensitive banking data is protected appropriately.
- Support security patterns for data ingestion, transformation, sharing, and reporting.
- Ensure appropriate monitoring, alerting, and governance around privileged access, service accounts, and data movement.
- Snowflake experience is strongly preferred; direct implementation experience is a major plus.
5. AI Security
Lead security work for internally developed AI applications and AI-enabled business capabilities.
Responsibilities include:
- Define and implement security guardrails for AI applications, including RAG, chatbots, AI agents, document intelligence, and internally developed AI tools.
- Address AI-specific risks such as prompt injection, data leakage, insecure output handling, excessive agency, model misuse, unsafe integrations, and sensitive information exposure.
- Partner with AI/data engineering teams to secure model access, data flows, vector stores, APIs, plugins/tools, and application permissions.
- Establish controls for AI application logging, monitoring, testing, human review, access governance, and incident response.
- Monitor external AI-enabled cyber threats, including phishing, social engineering, malware generation, deepfakes, and adversarial automation.
- AI security is now a distinct discipline. The OWASP Top 10 for LLM Applications identifies risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, supply chain vulnerabilities, and sensitive information disclosure. NIST has also published a Generative AI Profile under its AI Risk Management Framework to help organizations identify and manage risks unique to generative AI.
6. Team Leadership & Mentorship
Manage a small team of approximately two security engineers while remaining hands-on.
Responsibilities include:
- Provide technical direction, mentoring, and daily guidance to security engineers.
- Help upskill the team in AWS, Snowflake, AI security, automation, and modern security engineering practices.
- Assign work, review technical outputs, and ensure timely execution of security initiatives.
- Build a culture of ownership, urgency, documentation, and practical risk reduction.
- Act as manager, lead and senior individual contributor.
7. Audit, Risk & Vendor Management
Serve as the technical cybersecurity point of contact for internal security audit, regulatory exams, and vendor security matters.
Responsibilities include:
- Face off with Security Audit, Risk, Compliance, and regulatory stakeholders.
- Provide evidence, explanations, remediation plans, and technical responses for audit findings.
- Translate audit and regulatory requirements into specific technical actions.
- Support vendor security assessments, third-party reviews, and ongoing vendor oversight.
- Review vendor security architecture, access models, SOC reports, control gaps, and remediation plans.
- Partner with the Information Security Officer, IT leadership, and business stakeholders to ensure cybersecurity controls meet banking expectations.
Similar jobs
SOUTHCOM Cyber Intelligence Analyst with Security Clearance
CACI · Doral, United States
Just now$75.2k - $158.1k/yrCyber Operation Plans Analyst with Security Clearance
Department of the Army · Fort Meade, United States
1 minute agoSecurity Operations Center Level 1 Analyst - Onsite - Long Term Contract - Harrisburg, PA - B4179B
Technovision, Inc. · Harrisburg, United States
41 minutes agoSenior Principal Cyber Security Engineer with Security Clearance
Dexian Signature Federal · Chantilly, United States
43 minutes agoCyber Security Engineer with must have Transportation Domain & any one of these certificates (CISSP, CISM, GIAC, GICSP)
Analytics Solutions · Albany, United States
1 hour agoSecurity / ATO Specialist
Promantus, Inc · Washington, United States
1 hour ago