Senior Information Security Engineer
Farmers and Merchants Bank of Long Beach · Seal Beach, California, United States · $124K–$211K/yr
Banking · 501-1,000 employees
About the role
The Senior Information Security Engineer designs, implements, and manages enterprise-grade security solutions across hybrid and cloud environments. They also lead incident response efforts, drive security automation, and provide technical leadership to improve the bank's overall security maturity.
What they look for
Requirements
Candidates must have at least 7–9+ years of experience in information security engineering and a bachelor's degree in computer science or equivalent. Strong expertise in cloud security, enterprise security technologies, and regulatory compliance frameworks is required.
Full description
The Senior Information Security Engineer is a highly technical, hands-on engineering role responsible for designing, implementing, and owning enterprise-grade security solutions across the Bank’s infrastructure, cloud platforms, and identity environments. This role operates with significant autonomy and is expected to function as a technical leader within the Security Engineering team.
In addition to operational responsibilities, the Senior Information Security Engineer will drive security architecture patterns, detection engineering, and control strategy, partnering closely with the CISO, Information Security Architect, and IT leadership to influence enterprise security direction and risk posture.
This role is expected to act as a subject matter expert and technical escalation point, proactively identifying gaps, engineering scalable solutions, and improving the maturity of the Bank’s security program through automation, optimization, and innovation. This role may require after-hours support for critical incidents and production issues.
Key Responsibilities
- Design, engineer, and own end-to-end security solutions across on-premises, hybrid, and cloud environments (Azure, M365, SaaS).
- Serve as a technical lead for security control design, translating architectural requirements into resilient, scalable, and auditable implementations.
- Function as a security engineering escalation point for complex incidents, investigations, and cross-domain issues.
- Lead configuration, tuning, and lifecycle management of enterprise security technologies (firewalls, WAF, IDS/IPS, EDR/XDR, SIEM, DLP, CASB, IAM solutions).
- Develop and maintain advanced detection logic and use cases (SIEM rules, correlation searches, behavioral analytics).
- Engineer and implement security automation and orchestration (Python, PowerShell, APIs, SOAR platforms) to reduce manual effort and improve response times.
- Lead or support incident response activities, including containment strategy, root cause analysis, and post-incident remediation plans.
- Perform threat modeling, risk assessments, and control gap analysis for systems and applications.
- Collaborate with architects to define and enforce secure design patterns and reference architectures.
- Evaluate emerging threats and technologies; recommend and implement security improvements aligned with evolving attack trends.
- Conduct advanced vulnerability analysis and prioritize risk based on exploitability and business impact.
- Analyze logs, network flows, and endpoint telemetry to identify and investigate sophisticated attack patterns and adversary behaviors.
- Provide technical mentoring, guidance, and peer review for junior engineers and analysts.
- Participate in security tool selection, evaluation, and proof-of-concept initiatives.
Key Responsibilities – On-Call Support
- Participate in on-call rotation and function as a primary escalation engineer for high-severity incidents.
- Lead or support major incident response efforts, including coordination across IT, vendors, and leadership.
- Drive incident postmortems (RCA) and ensure corrective actions are implemented and validated.
- Provide after-hours support for critical security events and production issues.
- Ensure adherence to incident response playbooks, SLAs, and regulatory reporting requirements.
Compliance Responsibilities
- Ensure security engineering work aligns with regulatory frameworks and audit requirements (FFIEC, SOC 2, PCI DSS, etc.).
- Partner with GRC and audit teams to provide technical validation, evidence, and control effectiveness reporting.
- Support continuous control monitoring and compliance automation initiatives.
- Ensure all engineered solutions adhere to banking regulations (BSA, AML, OFAC, CIP, privacy laws).
Bank Compliance
Complies with all applicable state and federal banking laws, regulations, and internal policies related but not limited to lending, operations, and deposit requirements, including Bank Secrecy Act (BSA), Anti-Money Laundering (AML) requirements, Office of Foreign Assets Control (OFAC) regulations, Customer Identification Program (CIP) requirements, Financial Elder Abuse reporting laws, Sexual Harassment prevention policies, information security and privacy requirements.
Required Knowledge
- Deep expertise in enterprise security architecture and engineering principles.
- Hands-on experience designing and implementing enterprise security technologies (firewalls, WAFs, IDS/IPS, EDR/XDR, SIEM, IAM).
- Advanced knowledge of cloud security architecture (Azure, M365, Defender, Sentinel, Intune).
- Strong understanding of detection engineering, threat intelligence, and MITRE ATT&CK mapping.
- Experience with security logging pipelines and telemetry normalization.
- Experience with enterprise networking and secure connectivity (segmentation, VPN, ZTNA).
- Ability to perform packet capture analysis and adversary detection at scale.
- Experience with secure SDLC, DevSecOps practices, and infrastructure-as-code security.
- Experience with SOAR platforms or security automation frameworks.
- Familiarity with threat hunting and adversary simulation concepts.
Knowledge, Skills, and Abilities
- Proven ability to design security solutions from requirements with minimal supervision.
- Ability to influence technical direction and security standards across teams.
- Strong capability in root cause analysis and systems thinking.
- Demonstrated experience leading technical initiatives or security engineering projects.
- Ability to prioritize security risks in business context and communicate impact to leadership.
- Experience mentoring engineers and raising team technical maturity.
- Ability to operate in ambiguous environments and define solutions independently.
Equipment Operated
- Operates standard electronic computers and customary office equipment required to perform essential job functions.
- Use of equipment is required, with or without reasonable accommodation, in accordance with the Americans with Disabilities Act (ADA) and the California Fair Employment and Housing Act (FEHA).
Physical Requirements & Work Environment
The physical demands and work environment characteristics described below are representative of those that must be met by an employee to successfully perform the essential functions of this position. Nothing in this description is intended to limit the availability of reasonable accommodation under applicable law.
- Ability to perform repetitive movements associated with office and computer-based work.
- Ability to sit and or stand for extended periods of time to perform essential job functions.
- Ability to lift, carry, or move objects weighing up to 25 pounds, with or without reasonable accommodation.
- Ability to use hands and fingers to manage, manipulate, or feel objects and operate standard office equipment.
- Work is primarily performed in an office environment with a controlled temperature and standard office conditions.
Education and Experience
- Minimum 7–9+ years of progressively responsible experience in information security engineering, architecture, or related technical roles.
- Bachelor’s degree in computer science or equivalent experience required.
- Demonstrated experience designing and implementing enterprise security solutions.
- Experience leading complex security engineering projects.
- Preferred certifications: CISSP, CCSP, GCIH, Azure Security Engineer, etc.
- Preferred: cloud-native security architectures and advanced threat detection engineering.
- Preferred: exposure to adversary emulation, red teaming, or purple team exercises.
Minimum Absence Requirement
Some positions within the Bank have been designated as sensitive positions due to access to critical systems, records, or processes. In accordance with Bank policy and sound internal‑control practices, employees in sensitive positions are required to complete a mandatory consecutive absence from essential duties each calendar year to support segregation of duties and independent review.
The required absence will be scheduled in coordination with management to ensure continuity of operations. Administration of absence, including paid or unpaid status, will comply with all applicable federal, state, and local wage and hour and leave laws, including California requirements.
Required Minimum Absence for This Position: Two (2) Consecutive Weeks
Officer Title Eligibility
For qualified positions, the Bank may designate an Officer Title based on the role’s job level, scope of responsibility, and alignment with established competency frameworks. Eligibility for an Officer Title designation is contingent upon the employee meeting defined competency, performance, and experience requirements and is governed by applicable Bank policies, governance standards, and required approval processes.
- This position is eligible for an Officer Title.
Compensation
The listed range represents the full compensation range for this position. Placement within the range will be determined based on factors including skills, relevant experience, job‑related qualifications, geographic location, and internal equity, in accordance with Bank compensation policies.
- Exempt Salary Range: $123,760 – $211,120 per year
Disclaimer
This job description is intended to describe the general nature and level of work being performed and is not intended to be an exhaustive list of all duties, responsibilities, or qualifications. Employees may be required to perform other duties as assigned, consistent with business needs and applicable law.
Farmers and Merchants Bank of Long Beach reserve the right to modify, amend, or discontinue job duties or requirements at any time. Nothing in this job description creates a contract of employment, either express or implied, or alters the at‑will nature of employment.
08.06.26