Church Mutual Insurance Company, S.I.

Senior Security Engineer

Church Mutual Insurance Company, S.I. Merrill, Wisconsin, United States

Insurance · 1,001-5,000 employees

6 h ago
security Principal (10+ yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Security Engineer leads major security engineering initiatives, defines control standards, and provides technical leadership across multiple domains. They are responsible for managing complex incident response activities, mentoring staff, and optimizing the enterprise security technology stack.

What they look for

Cybersecurity Incident Response Detection Engineering Security Architecture Cloud Security Identity Security Endpoint Security Network Security Vulnerability Management Forensics Automation Risk Management Threat Intelligence SIEM EDR DLP

Requirements

Candidates must have 10+ years of hands-on experience in cybersecurity with a degree in CS, IS, or a related field. Proven expertise in detection engineering, incident response, and enterprise security architecture is required.

Full description

BASIC PURPOSE:

The Senior Security Engineer drives major security engineering initiatives and provide technical leadership across multiple domains, and works across teams to align security capabilities with business objectives. This role defines control enhancements. Leads advanced investigation, shapes engineering standards, and mentors Engineers and Administrators Must demonstrate advanced cross-domain capability (identity, endpoint, network, cloud) and lead complex detection and incident response activities. Individuals unable to lead hands-on technical work will not meet expectations.

 

PRIMARY JOB RESPONSIBILITIES:

  • Exercise expert-level judgment to independently investigate and report complex cyber incidents, setting standards for incident response and mentoring junior staff on advanced cases.
  • Oversee system cybersecurity operations, making high-stakes decisions in ambiguous scenarios and shaping escalation protocols for critical issues.
  • Lead and define initial cyber incident triage strategies, determining scope and urgency with authority, and guiding the team through complex incidents.
  • Set organizational standards for vulnerability identification and documentation, utilizing advanced tools and methodologies, and influencing escalation practices for non-standard or high-risk findings.
  • Direct advanced data analysis using CND tools (IDS alerts, firewall logs, host system logs), recognizing sophisticated threat patterns and mentoring others in expert analysis.
  • Ensure the highest standards of incident documentation, reviewing and resolving discrepancies with expert judgment, and influencing documentation practices across the team.
  • Lead root cause analysis for major incidents, applying advanced analytical skills and shaping investigative methodologies for the organization.
  • Stay at the forefront of cybersecurity threats and best practices, driving process improvements and influencing team knowledge sharing.
  • Architect and optimize the Security technology stack, resolving advanced issues and leading strategic process improvements that impact enterprise security.
  • Lead response efforts to active attacks in cloud and on-premises environments, exercising advanced judgment and authority in high-stakes scenarios.
  • Provide expert input on threat protection, leading initiatives that drive team efficiency and influence organizational security practices.
  • Independently report and lead reviews of suspected policy violations, shaping investigative standards for cases requiring further scrutiny.
  • Lead risk mitigation efforts, making high-stakes decisions to manage exposure and influencing improvements to organizational risk management processes.
  • Drive the development of enterprise-wide security architectures and standards, leading strategic meetings and initiatives that influence organizational direction.
  • Oversee baseline and risk assessments, setting standards for data collection and analysis, and guiding the team through complex findings.
  • Provide advanced cybersecurity consultation, leading enterprise-wide health checks and resolving complex questions that shape organizational security posture.
  • Lead research into emerging cybersecurity threats, applying deep functional knowledge and influencing investigative approaches for complex incidents.
  • Maintain and review the enterprise cybersecurity risk register, setting standards for risk documentation and resolving unusual entries with expert judgment.
  • Lead forensic investigations and advanced cybersecurity activities, setting standards for data collection and documentation, and mentoring junior analysts.
  • Manage intrusion prevention systems and define endpoint protection policies, leading strategic improvements and influencing routine security practices.
  • Triage advanced threat detection (ATD) alerts, exercising expert judgment and shaping team approaches to complex alerts.
  • Provide advanced advice and assistance on cybersecurity matters, mentoring junior analysts and influencing the resolution of complex questions.
  • Lead training sessions and drive adoption of new cybersecurity and communication technologies, shaping team efficiency and mentoring others.
  • Level Expectations (Performance and Scope Indicators)

The following outlines how performance is evaluated at this level. These are not additional job responsibilities, but indicators of scope, autonomy, impact, and influence expected of this role.

Scope: Leads major security initiatives, projects, and engineering workstreams across multiple domains. Serves as subject-matter expert for technical control architecture, detection logic design, investigation methodology, and enterprise security tooling.

Autonomy: Operates with high autonomy. Makes technical decisions, designs solutions, and resolves complex issues. Escalates only when strategic trade-offs or cross-team impacts arise.

Impact: Shapes security capabilities across the entire organization. Defines engineering patterns, raises maturity levels, and drives large-scale improvements that reduce risk and improve operational efficiency.

People Influence: Mentors engineers and administrators. Leads small technical squads or project teams. Provides input into workforce capability development. Influences Architecture, Infrastructure, and Ops.

 

QUALIFICATIONS:

Required

  • Proven leadership in detection engineering, IR, automation, or architecture.
  • Ability to design and maintain enterprise detection logic and automation workflows.
  • Advanced experience with EDR, DLP, SIEM, identity security, VM, and NDR at engineering depth.
  • Ability to act as escalation point for complex, multi-vector incidents.
  • Expertise across identity, endpoint, cloud, network, and data security domains.
  • Degree in CS/IS/Cybersecurity or equivalent; 10+ years hands-on experience.

Technical Competencies

  • Capability to evaluate and improve control architecture.
  • Ability to lead hunts, develop analytics, and guide complex IR cases.
  • Ability to drive technical initiatives requiring cross-functional coordination.

Preferred

  • CISSP, SC-300, GIAC certifications.
  • Experience influencing enterprise architecture and leadership decision-making.

 

WORK ENVIRONMENT:

❖ Office

  • Professional office environment. Regularly uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines.
  • Regularly required to communicate; sit; stand; walk; use hands to finger, handle or feel; and reach with hands and arms.
  • Supervisory Responsibilities – None
  • CM Group Office – Hybrid

Similar roles