> Markdown version of [/jobs/ext/1995195-senior-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/1995195-senior-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Engineer - **Company:** Digital Federal Credit Union - **Location:** Dawson Creek, United States - **Experience:** Expert - **Salary:** $116,500.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, Network Security, Software Vulnerability Management, Microsoft Power Automate, Software Security, CIS Benchmarks, GPT - **Published:** August 8, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17868658?backUrl=%2Fcareer%2F17868658%2FSenior-Information-Security-Engineer-Oregon-Hillsboro ## About the Role * Required Education: Bachelors degree in field relevant to role (or 4 additional years of relevant experience in lieu of a degree) * Required Experience: 4 - 6 years of relevant experience * Knowledge of information security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or FFIEC guidance. Familiarity with regulatory expectations applicable to financial services environments. * Understanding of cybersecurity domains, but particularly artificial intelligence (AI), cloud security, network security, and data protection. * Ability to provide solutions which allow the safe usage of AI technologies in a financial services organization. * Experience with Model Context Protocol (MCP) governance * Experience with Microsoft Copilot, OpenAI ChatGPT, Anthropic Claude and other similar technologies. * Familiarity with AI security tools such as Palo Alto Prisma AI runtime security (AIRS), Crowdstrike Falcon AI Detection and Response (AIDR) or other similar tools. * Deep experience with securing and governing Microsoft Azure and Amazon Web Services (AWS). * Experience with cloud security tooling such as Orca, Prisma Access Cloud, Wiz or other similar tools. * Strong analytical and problem-solving skills with the ability to evaluate complex security and technology risks. * Ability to provide objective risk assessments and effective challenge while building collaborative stakeholder relationships. * Support the ability to "shift left" and incorporate security early on and throughout the development lifecycle. * Strong written and verbal communication skills with the ability to translate technical concepts into business-focused risk discussions. ## Description This role provides independent Second Line of Defense (2LOD) oversight and risk assessment of the organization's information security program, controls, and technology environment. The position supports the identification, assessment, monitoring, and reporting of information security risks to ensure alignment with the organization's risk appetite, regulatory expectations, and industry standards. Through risk analysis, control evaluations, and effective challenge, this role helps strengthen the organization's cybersecurity posture and operational resilience. Here's what you can expect from the job and what you need to be successful: What You'll Do: * Perform independent assessments of information security risks, controls, and processes across technology environments, applications, infrastructure, and third-party relationships. * Evaluate the design and effectiveness of security controls against established frameworks, regulatory requirements, and industry best practices. * Identify, analyze, and communicate cybersecurity risks, vulnerabilities, control weaknesses, and emerging threats to risk and business stakeholders. * Support governance and oversight of security domains including identity and access management, vulnerability management, cloud security, application security, data protection, and cybersecurity operations. * Conduct risk assessments for new technologies, projects, systems, and business initiatives to evaluate potential security and operational risks. * Provide effective challenge to first-line security practices, risk decisions, control implementations, and remediation strategies. * Monitor and assess information security metrics, key risk indicators (KRIs), control effectiveness measures, and trends to identify emerging risks and opportunities for improvement. * Support development and maintenance of information security risk management policies, standards, methodologies, and governance processes. * Participate in regulatory examinations, internal audits, risk reviews, and compliance assessments by preparing analysis, documentation, and responses to requests. * Partner with Technology, Information Security, Compliance, Enterprise Risk, Internal Audit, and business stakeholders to strengthen risk management practices and improve control maturity. * Prepare reporting and presentations that communicate technical risks, control gaps, and security trends to a variety of audiences. * Support oversight of third-party technology providers and critical vendor security risk management activities. * Stay current on cybersecurity threats, regulatory developments, emerging technologies, and industry practices to evaluate potential impacts to the organization. ## Related Videos - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)