Information Security Engineer
Firstrust Bank Horsham, Pennsylvania, United States
Banking · 201-500 employees
About the role
The Information Security Engineer will manage network and cloud security infrastructure while proactively conducting threat hunting and incident response activities. Additionally, the role involves overseeing business continuity planning and administering data governance through the Microsoft Purview suite.
What they look for
Requirements
Candidates must possess a bachelor's degree in a relevant field and at least 5 years of progressive experience in cybersecurity engineering. Strong technical proficiency in firewall management, threat hunting methodologies, and regulatory compliance frameworks is required.
Benefits
Full description
FIRSTRUST BANK Recognizes the leader in you
As one of the region’s foremost community banking institutions, we take pride in fostering leadership.
As a Firstrust employee, your growth is our growth.
For you, that means great benefits, performance-based pay, a meaningful role, and resources to help your success.
For us, that means employees who offer exemplary customer service with a commitment to our values - honesty, integrity and accountability.
*Hybrid Position*
We are seeking a highly skilled and motivated Information Security Engineer to join our IT Security team. In this role, you will be a key defender of our infrastructure, bridging the gap between advanced threat defense, cloud security, and corporate compliance.
The ideal candidate possesses a deep technical understanding of modern cloud architectures (SASE/CASB), a proactive mindset for threat hunting, and the diligence required to manage Business Continuity/Disaster Recovery (BC/DR) operations and data governance via Microsoft Purview.
JOB DUTIES AND RESPONSIBILITIES:
1. Network & Cloud Security (SASE, CASB, Firewalls)
- Design, deploy, and maintain Next-Generation Firewall (NGFW) policies and rules ensuring least-privilege access.
- Manage and optimize our Secure Access Service Edge (SASE) architecture to support a secure remote/hybrid workforce.
- Implement and monitor Cloud Access Security Broker (CASB) solutions to gain visibility into shadow IT, enforce data compliance, and prevent data leakage across SaaS applications.
- Maintain firewall change management processes, including peer review, staging/testing, and post-change validation.
2. Threat Hunting & Incident Response
- Proactively conduct threat hunting campaigns across network, endpoint, and cloud logs to identify anomalous behavior and latent threats that bypass traditional security controls.
- Analyze security telemetry (SIEM/XDR) to reconstruct attack vectors and develop custom detection rules.
- Act as a core member of the Incident Response team, including containment, eradication, and post-incident analysis.
- Maintain current awareness of emerging threat actor groups, CVEs, and exploitation trends relevant to our industry and technology stack.
- Remain available outside of standard business hours to respond to escalated, high-priority security events as needed.
3. Business Continuity & Disaster Recovery (BC/DR)
- Collaborate with business stakeholders to develop, maintain, and update Business Continuity and Disaster Recovery plans.
- Coordinate and lead regular BC/DR tabletop exercises and technical disaster recovery drills (failovers, backups restoration).
- Ensure defined RPOs and RTOs are achievable, tested, and aligned with regulatory requirements — flagging gaps to leadership with clear remediation paths.
4. Microsoft Purview: Data Governance & eDiscovery
- Administer and optimize the Microsoft Purview compliance suite with hands-on ownership of: Information Protection (sensitivity labels, auto-labeling policies), Data Loss Prevention (DLP) policies across M365 and endpoint, Compliance Manager (assessment tracking, control mapping), and Advanced eDiscovery.
- Design and manage end-to-end eDiscovery workflows: creating review sets, applying legal holds, running targeted content searches, managing custodian communications, and producing defensible data exports in coordination with legal counsel.
- Develop and refine DLP policies to reduce false positives, improve policy coverage, and generate actionable alerts — working with business units to balance security with operational productivity.
- Monitor Purview audit logs and compliance dashboards, escalating anomalies and producing regular reports for security leadership and legal/compliance stakeholders.
OTHER JOB DUTIES AND RESPONSIBILITIES:
- Assists in the development of new business for Firstrust. Is alert to expressed customer/prospect needs to suggest appropriate services. Directs customers to appropriate person to establish business relationships.
- Other duties as assigned.
PHYSICAL AND SENSORY REQUIREMENTS:
- Prolonged periods sitting at a desk and working on a computer.
- Regularly required to drive a motor vehicle, occasional air travel, attending meetings at various venues, including but not limited to customers’ offices and/or properties, restaurants and other meeting locations, and ascend/descend stairs and or ladders occasionally to perform inspections.
- The employee may be required to lift files/materials up to 20 pounds to take to various locations.
- The incumbent will be expected to operate a computer terminal.
- Prolonged periods sitting at a desk and working on a computer
POTENITAL ON-THE-JOB-RISKS:
- None identified.
EDUCATION, TRAINING AND EXPERIENCE:
- Education: Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or equivalent practical experience.
- Experience: 5+ years of progressive experience in cybersecurity engineering or a dual security/compliance role.
- Technical Expertise:
- Firewalls: Hands-on production-level configuration and administration of NGFW platforms.
- Threat Hunting: Demonstrated experience running structured hunting campaigns, not just reactive alert investigation. Must be able to articulate past hunts, methodologies used, and outcomes achieved
- SIEM/XDR: Proficiency in KQL (Microsoft Sentinel) and/or Splunk SPL for threat hunting, detection engineering, and forensic analysis.
- Experience administering or supporting SASE/CASB platforms.
- Microsoft Purview: Meaningful hands on experience with DLP Policies, Compliance Manager, Information Protection, Advanced eDiscovery).
- Strong understanding of threat actor TTPs (MITRE ATT&CK framework) and query languages (e.g., KQL, Splunk SPL) for threat hunting.
- Experience writing, testing, and auditing BC/DR documentation and participating in routine exercises.
Experience in a regulated industry ([finance/healthcare/etc.]) with frameworks such as [SOC 2, ISO 27001, HIPAA, NIST CSF]
Communication & Collaboration
- Strong written communication: ability to document procedures, write post-incident reports, and translate technical risk for legal, compliance, and executive audiences
- Proven ability to partner with non-technical business units to balance security controls with operational productivity
Firstrust Bank provides equal employment opportunity without regard to race, color, creed, sex (including pregnancy), age, gender, (including gender nonconformity and status as a transgender or transsexual individual), physical or mental disability, religion, national origin, genetics, marital status, veteran’s status, ancestry, citizenship, sexual orientation, or other characteristics protected by applicable law. This policy applies to all areas of employment, including, without limitation, recruitment, hiring, training and development, promotion, transfer, termination, compensation, benefits, and all other conditions and privileges of employment in accordance with applicable federal, state and local laws.
Firstrust Bank is an Equal Opportunity Employer.
If you have a disability and need an accommodation to complete the application process, please email Firstrust Bank Human Resources Department HResources@firstrust.com. Include your full name, best way to reach you, and the accommodation needed to assist with the application process.
Firstrust provides reasonable accommodations so that disabled individuals may participate in the application and selection process. Please state your reasonable accommodation request for assistance in your message.
Only reasonable accommodation requests related to applying for a specific position within Firstrust will be reviewed at the email address and phone number supplied.
Please advise Firstrust of any accommodation you require to express an interest in a specific opening by emailing or calling: reasonableaccomdations@firstrust.com or 215-728-8265.
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr