Celtic Bank

Security Engineer

Celtic Bank · Salt Lake City, Utah, United States

Financial Services · 201-500 employees

4 h ago
Remote Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer will identify and manage internal and external security risks while leading key initiatives across identity, network, endpoint, and cloud environments. They are responsible for administering critical security platforms, maintaining asset inventories, and supporting incident response activities.

What they look for

Security engineering Attack surface management Rapid7 CrowdStrike Endpoint protection Identity security SASE CASB SSPM Incident response Asset inventory Multi-factor authentication Dashlane Technical documentation Risk management

Requirements

Candidates must have a bachelor's degree in a related field and 3–5 years of hands-on experience in information security or enterprise IT. Proficiency with attack surface management tools, endpoint detection and response, and knowledge of security frameworks like GLBA or ISO 27001 is required.

Benefits

Medical Dental Vision 401(k) with employer match Life insurance Long-term disability coverage HSA plans FSA plans Paid time off Wellness program

Full description

Celtic Bank is seeking a skilled Security Engineer to help protect the Bank’s systems, data, and technology environment. This role is responsible for identifying, reducing, and continuously managing internal and external security risks while leading key security initiatives across identity, network, endpoint, and cloud environments.

The Security Engineer will administer critical security platforms, maintain a consolidated technology asset inventory, and lead projects involving modern desktop authentication, Secure Access Service Edge (SASE), Cloud Access Security Broker (CASB), and SaaS Security Posture Management (SSPM). This position will also support incident response activities and help continuously strengthen the Bank’s overall security capabilities.

What You’ll Do• Administer, configure, and maintain the Rapid7 attack surface management platform, including discovery scope, scan configuration, and exposure triage. 

  • Build and maintain a consolidated asset inventory using the attack surface management tool, reconciling discovered assets against authoritative systems of record. 
  • Own cyber asset attack surface management (CAASM), correlating asset, vulnerability, and tool-coverage data to identify unmanaged, unprotected, or misconfigured assets. 
  • Lead the modern desktop authentication project, implementing two-factor authentication for endpoint sign-in across the environment. 
  • Lead the Secure Access Service Edge (SASE) conversion project, including design, phased rollout, policy definition, and migration from legacy network access controls. 
  • Lead the cloud access security broker (CASB) and SaaS security posture management (SSPM) projects, establishing policy, monitoring, and remediation workflows for sanctioned and unsanctioned cloud applications. 
  • Maintain CrowdStrike endpoint protection, including sensor deployment and health, policy tuning, detection triage, and coverage reporting. 
  • Maintain the Dashlane enterprise password management platform, including provisioning, group and sharing standards, and adoption reporting. 
  • Support incident management and response, including investigation, containment, and post-incident remediation for endpoint, identity, and cloud events. 
  • Track and report security posture metrics, including asset coverage, attack surface exposure, two-factor enrollment, and project milestones, to IT and security leadership. 
  • Develop and maintain technical documentation, including tool configurations, project designs, operational procedures, and runbooks. 
  • Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field, or equivalent combination of education and experience; security certifications (e.g., Security+, CySA+, SSCP) preferred. 
  • 3–5 years of hands-on experience in information security or enterprise IT, with a focus on attack surface, endpoint, and identity security. 
  • Demonstrated experience administering an attack surface management platform (Rapid7 or comparable) and building asset inventory from discovery data. 
  • Experience with endpoint detection and response tooling, preferably CrowdStrike, including policy configuration, sensor health, and detection triage. 
  • Working knowledge of SASE, CASB, and SSPM concepts, with experience supporting or leading the deployment of at least one. 
  • Experience implementing multi-factor authentication for endpoint or workstation sign-in, and familiarity with enterprise password management platforms such as Dashlane. 
  • Understanding of information security principles, data classification, and regulatory requirements applicable to financial institutions (e.g., GLBA, FFIEC, ISO 27001). 
  • Experience participating in incident response, including investigation, containment, and remediation, and the ability to lead technical projects across multiple teams. 
  • Strong analytical, troubleshooting, and documentation skills, with the ability to communicate technical concepts clearly to both technical and non-technical audiences. 
  • Medical, dental, vision
  • 401(k) with employer match
  • Life and long-term disability coverage
  • HSA and FSA plans
  • Holidays and paid time off requests
  • Robust wellness program (we’re talking catered meals three times a week, lunch and learns, and onsite gym!)

Headquartered in the heart of downtown Salt Lake City, Utah, Celtic Bank was named a top SBA lender in the nation in 2025! Celtic Bank is a leading nationwide lender specializing in SBA 7(a), SBA 504, USDA B&I, express loans, asset-based loans, commercial real estate loans and commercial construction loans.

Celtic Bank is an equal opportunity employer and complies with all applicable federal, state and local fair employment practices laws.

Physical and Other Requirements

This job operates in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines. The demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.

  • Stationary Work: The employee is frequently required to stand; walk; use hands to type, handle documents, and perform other office related duties. Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.
  • Mobility: The employee in this position needs to occasionally move between work sites and inside the office to access file cabinets, office machinery, etc.
  • Communicate: The employee is regularly required to talk or hear and will frequently communicate with others. Must be able to read, write and understand fluent English.
  • Work Model: The employee in this position will work either a fully Onsite or Hybrid work model. All employees, regardless of location, may be required to travel to the Salt Lake City office for mandatory company meetings, events, or related occasions.
  • Utah-based employees: Hybrid work schedule available after initial training period in our Salt Lake City, Utah office – department and job requirements will determine eligibility.