Information Security Engineer
Flagstar Bank Troy, Alabama, United States · $76K–$139K/yr
Banking · 5,001-10,000 employees
About the role
The Information Security Engineer supports the design, implementation, and maintenance of enterprise-wide security solutions across cloud and on-premises environments. Responsibilities include monitoring security systems, automating routine tasks, and ensuring compliance with regulatory standards.
What they look for
Requirements
Candidates must have at least 5 years of progressive experience in enterprise-scale information security and 3 years of hands-on experience across multiple security domains. A high school diploma or equivalent is the minimum educational requirement.
Benefits
Full description
Position Title
Information Security Engineer
Location
Troy, MI 48098
Job Summary
The Information Security Engineer supports the design, implementation, and maintenance of enterprise-wide security solutions to protect systems, data, and users across the organization. This role contributes to the development of secure architecture, operational standards, and processes that ensure consistent and reliable protection across both cloud-based and on-premises environments. Working closely with senior engineers and cross-functional teams, the Information Security Engineer helps implement scalable and resilient security controls that align with business needs and compliance requirements. Responsibilities include monitoring, troubleshooting, and optimizing security systems, as well as assisting in the integration of new tools and technologies to strengthen the organization’s overall security posture. This role is ideal for professionals looking to deepen their expertise in enterprise security while contributing to continuous improvement and operational excellence.
Job Responsibilities:
JOB RESPONSIBILITIES
- Support the management and optimization of enterprise IT security platforms to ensure availability, performance, and protection.
- Assist in the implementation and maintenance of security solutions across on-premises, hybrid, and multi-cloud environments.
- Apply and monitor security controls for networks, systems, applications, and data, ensuring proper integration of tools and platforms.
- Perform configuration, patching, upgrades, and health monitoring of IT security tools.
- Troubleshoot platform issues and work with vendors and internal teams to implement fixes and improvements.
- Collaborate with application owners and business stakeholders to support the onboarding of systems into the security ecosystem.
- Ensure secure integration of applications and services in compliance with internal policies and regulatory standards.
- Contribute to the deployment and maintenance of security solutions across diverse environments.
- Assist in the development and execution of security automation initiatives to improve operational efficiency and reduce manual tasks.
- Support scripting and use of APIs to automate routine security functions.
- Help implement and maintain security policies, standards, and procedures, ensuring compliance with industry regulations.
- Apply cloud security to best practices and support enforcement of Zero Trust and least privilege models.
- Work with infrastructure, development, and operations teams to embed security into systems and application lifecycles.
- Participate in assessments of new projects and technologies to identify security implications.
- Support the implementation of Role-Based Access Control (RBAC) models under guidance from senior engineers.
- Assist in creating dashboards and reports to track the effectiveness of security controls.
- Support audit activities by maintaining accurate documentation and evidence of control adherence.
- Participate in changing control processes for security systems, ensuring alignment with ITIL or similar frameworks.
- Stay informed on emerging security technologies and trends.
- Contribute ideas and feedback to help improve the organization’s security posture and anticipate future challenges.
- Uses independent judgement and discretion to make decisions.
- Analyzes and resolves problems.
ADDITIONAL ACCOUNTABILITIES
- Performs special projects, and additional duties and responsibilities as required.
- Consistently adheres to regulatory and compliance policies and standards linked to the job as listed and complete required compliance trainings. Accountable to maintain compliance with applicable federal, state and local laws and regulations.
JOB REQUIREMENTS
Required Qualifications:
- Education level required: High School / High School Equivalency (GED, HiSET, TASC) / Foreign Equivalent.
- Minimum experience required: 5+ years of progressive experience supporting and implementing enterprise-scale information security solutions across diverse environments.
- 3+ years of hands-on experience across multiple security domains, including security operations, architecture, vulnerability management, and compliance support.
- Demonstrated ability to implement secure frameworks and apply security controls in both cloud-based and on-premises environments.
- Solid understanding of cybersecurity principles, industry standards, and best practices.
- Experience in the deployment and maintenance of security infrastructures across on-premises, hybrid, and multi-cloud platforms.
- Proficiency in scripting and automation to support routine security tasks and improve operational efficiency.
- Working knowledge of regulatory compliance, including SOX (Sarbanes-Oxley), with experience supporting audit readiness through documentation and technical safeguards.
- Proven ability to collaborate with cross-functional teams, assist in risk assessments, and contribute to automation efforts that enhance provisioning, certification, and governance processes.
Preferred Qualifications:
- Solid working knowledge of Information Security policies, standards, and procedures, with experience applying them in day-to-day operations.
- Experience supporting the implementation of IT Security frameworks aligned with regulatory requirements such as NIST, ISO 27001, SOX, and HIPAA.
- Hands-on technical proficiency in deploying and maintaining security solutions across enterprise environments.
- Strong understanding of IAM/PAM principles, including Zero Trust, least privilege, RBAC, JIT access, and identity lifecycle management.
- Ability to contribute to access management initiatives, evaluate technical options, and support communication of strategies to stakeholders.
- Experience collaborating with senior engineers and contributing to knowledge sharing and best practices within the team.
- Working knowledge of relational databases (e.g., SQL Server, Oracle), with experience writing queries and analyzing access-related data for audits and reporting.
- Proficient in producing clear documentation and reports, including security assessments and actionable recommendations.
- Effective communicator and team player, able to engage with business stakeholders to gather requirements and resolve access-related issues.
- Supports cross-functional teams in the design and implementation of secure access controls, contributing technical insights and execution support.
- Demonstrated ability to assist in risk assessments, identifying access-related risks and supporting mitigation strategies.
- Strong analytical and problem-solving skills, with attention to detail in access reviews, audits, and investigations.
- Willingness to participate in On-Call support, including incident response and troubleshooting IAM/PAM issues outside business hours.
- Familiarity with financial systems (e.g., mortgage lending, funding, closing platforms) is a plus, especially in regulated environments.
- Performs assigned projects and additional responsibilities as needed to support security operations.
- Adheres to compliance policies and standards, completing required training and maintaining awareness of applicable laws and regulations.
- Supports architectural decisions and technical standards under guidance from senior engineers, contributing to the resolution of complex security challenges.
Job Competencies:
- Strong analytical and problem-solving skills, with the ability to address complex security issues and contribute to effective solutions within established frameworks.
- Solid experience in security architecture and implementation, with working knowledge across diverse technological environments.
- Familiarity with threat analysis, incident response, and digital forensics, with a focus on supporting proactive security measures and operational resilience.
- Effective team collaborator, capable of supporting technical direction and contributing to shared goals across multi-disciplinary teams.
- Clear and concise written and verbal communication skills, with the ability to convey technical concepts to peers and stakeholders.
- Demonstrates a strong ability to build and maintain effective relationships with stakeholders by communicating clearly, engaging in proactive collaboration, and leveraging cross functional insights. Aligns relationship building efforts with enterprise goals to accelerate performance and drive strategic results.
- Builds trusted client relationships, whether internal or external, by identifying needs and delivering tailored solutions to enhance the overall client experience.
- Fosters or supports a positive work culture and productive work environment, displaying importance of effective relationships with customers and stakeholders.
- Focused on aligning day-to-day security efforts with broader organizational objectives to support performance and compliance.
- Committed to delivering client-focused solutions, whether internal or external, by understanding requirements and contributing to secure, scalable implementations.
- Capable of managing and prioritizing multiple security tasks and projects, ensuring timely execution and alignment with team goals.
- Knowledge of the following Tools & Technologies:IAM: Azure AD, RSA, SailPoint; PAM: CyberArk, Beyond Trust; Scripting: PowerShell, Python, Bash; Cloud: AWS IAM, Azure RBAC, GCP IAM; Security: MFA, SSO, LDAP, SAML, OAuth2, OpenID Connect; Compliance: SOX, NIST 800-53.
- Demonstrates a strong ability to build and maintain effective relationships with stakeholders by communicating clearly, engaging in proactive collaboration, and leveraging cross functional insights. Aligns relationship building efforts with enterprise goals to accelerate performance and drive strategic results.
- Builds trusted client relationships, whether internal or external, by identifying needs and delivering tailored solutions to enhance the overall client experience.
- Fosters or supports a positive work culture and productive work environment, displaying importance of effective relationships with customers and stakeholders.
- Physical demands (ADA): No unusual physical exertion is involved.
Flagstar is an Equal Opportunity Employer
We are committed to providing clear and accurate compensation information in accordance with applicable laws. Actual starting base pay will be determined based on location, experience, and other non-discriminatory factors permitted by law. Total compensation may also include variable incentives, bonuses, commissions, or other awards as outlined in the offer of employment. Flagstar provides teammates access to a variety of benefits including medical, dental, vision, life, and disability insurance, as well as a comprehensive leave program. Please click the following link for detailed information: Benefits | Flagstar Bank
Pay Range
$75,750.00 - $139,380.00
Similar roles
-
Security Engineer
Applied Network Solutions Inc Linthicum, Maryland, United States · $100K–$200K/yr
-
Security Engineer with Akamai WAF
Syncreon Consulting New York, New York, United States
-
Cyber Security Engineer
UL Solutions Northbrook, Illinois, United States · $96K–$130K/yr
-
OT Network & Security Engineer
Vulcan Elements Research Triangle Park, North Carolina, United States
-
Senior Security Engineer, Access Security
Google New York, New York, United States · $174K–$252K/yr
-
Senior Security Engineer
Zepz United Kingdom