City Bank

Information Security Engineer

City Bank Lubbock, Texas, United States

Financial Services · 501-1,000 employees

20 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Information Security Engineer is responsible for designing, implementing, and maintaining the bank's security controls across various domains including cloud, identity, and AI governance. They also lead incident response activities, perform vulnerability assessments, and ensure compliance with regulatory requirements.

What they look for

Security Engineering Vulnerability Management Incident Response Identity And Access Management Cloud Security AI Governance Forensic Analysis Risk Analysis Firewall Administration Endpoint Security Data Governance Security Metrics Vendor Management Business Continuity Planning Disaster Recovery

Requirements

The role requires a high degree of autonomy and technical expertise in managing security technologies and enterprise systems. Candidates must be capable of collaborating with IT, risk, and business units to improve the overall security posture of the organization.

Full description

Job DetailsJob Location: Operations Center - Lubbock, TX 79407Position Type: Full TimeThe Information Security Engineer is responsible for the design, implementation, operation, and continuous improvement of the Bank’s information security program. This role provides hands-on engineering and operational ownership across security domains, including security operations, threat and vulnerability management, identity and access management, incident response, cloud security, and AI governance. The Information Security Engineer serves as a key technical resource responsible for securing enterprise systems, managing and optimizing security technologies, and ensuring alignment with regulatory requirements and emerging threats. This position operates with a high degree of autonomy and accountability and collaborates closely with IT, Risk, and business units.

 

Essential Duties

The Information Security Engineer may perform, be responsible for, or assist in one or more of the following information security functions:

Security Engineering & Operations - Design, implement, and maintain enterprise security controls and technologies. Monitor security systems, analyze logs and alerts, and perform investigations. Continuously improve detection and response capabilities. Threat and Vulnerability Management - Perform vulnerability scanning, threat monitoring, and risk analysis. Prioritize, track, and coordinate remediation activities with IT and business stakeholders. Incident Response - Lead incident response activities, including investigation, containment, eradication, and recovery. Perform forensic analysis and document findings. Participate in after-hours response as needed. Identity & Access Management - Own and administer the Bank’s Identity and Access Management (IAM) program. Design and enforce identity governance, provisioning, deprovisioning, authentication, and authorization controls. Manage role-based access models, privileged access management, and identity lifecycle processes. Ensure access decisions align with least privilege and regulatory expectations. Oversee access certifications and continuously improve identity control effectiveness. AI Governance & Emerging Technology Risk - Support and administer governance processes for AI systems and tools used within the Bank. Maintain inventory, risk classification, and monitoring of AI agents and solutions. Ensure alignment with internal policies, regulatory expectations, and model risk management requirements. Collaborate with stakeholders to evaluate and onboard new AI use cases securely. Cloud Security - Design, implement, and maintain cloud security controls aligned with the Bank’s architecture. Monitor cloud environments for misconfigurations, threats, and compliance issues. Security Tools Administration - Administer and optimize security technologies, including firewalls, endpoint security platforms, and related tools. Evaluate and implement new security solutions as needed. Data Governance & Retention - Support oversight of data protection, classification, and retention practices. Assist in the management and reporting of tools supporting data governance. Data Analysis & Reporting - Develop and present security metrics, dashboards, and reports for leadership, committees, and auditors. Support risk reporting and program maturity tracking. Security Awareness & Training - Support the development and execution of security awareness and training programs. Track effectiveness and recommend improvements. Vendor Management - Participate in vendor onboarding, risk assessments, and ongoing monitoring activities. Support administration of vendor risk management tools. Business Continuity Planning - Support business continuity and disaster recovery planning, testing, and improvement efforts.

Equal Opportunity Employer/Veterans/DisabledQualifications

Similar roles