> Markdown version of [/jobs/ext/2308933-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/2308933-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Affinity, Inc. - **Location:** Saint Paul, MN, United States (Remote available) - **Experience:** Experienced - **Salary:** $92,700.0 - $120,500.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Security Management, Intrusion Detection and Prevention, Network Administration, Open Source Technology, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Enterprise Data Management, Cyber Threat Analysis, Information Technology, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88193881/1 ## About the Role * 3+ years of experience in an Information Security role. * Intermediate experience in Network Administration/Architecture, Security Framework Usage, SIEM Usage. * Extensive experience in a range of threat intel/recon tools, including propriety and open source models. * Strong understanding of security theories including Defense-In-Depth, Cyber KillChain, Assumed Breach, Zero Trust. * Ability to initiate, react to, and take direction on specific course or response, action, and mitigation that is heavily dependent and individualized to the security situation., Decision Making/Problem Solving/Advising * Ability to analyze information to solve issues and make informed, sound decisions, within established policies and procedures * Skilled in assessing needs, offering solutions, and building trust through effective consultation. * Ability to recognize operational inefficiencies and identify improvement opportunities Collaboration/Building Relationships * Proven ability to build and maintain positive working relationships with members and internal stakeholders by demonstrating professionalism, reliability, and responsiveness in daily interactions. * Ability to collaborate effectively within and across teams. Accountability * Ability to take accountability of responsibilities, commitments, and outcomes. Communication * Strong ability to communicate clearly, effectively and professionally. Learning * Ability to actively pursue opportunities to expand knowledge and skills; applying learning to improve performance. * Willingness to learn new skills, processes, and technologies with support and training. Adaptability * Demonstrated adaptability and willingness to take on new responsibilities. * Demonstrated ability to show resilience and adaptability in the face of challenges or changes. * Technology Experience * Intermediate computer and technology skills and knowledge, with the ability to navigate between multiple systems with ease. Other Skills * Time Management skills and the ability to prioritize workload based on department and member needs. * Ability to complete tasks with accuracy and thoroughness. * Demonstrated reliability, integrity, and ability to maintain confidentiality. Preferred * Bachelor's degree in Cybersecurity, Information Security, Computer Science, Math, or similar field. * Certification in CISSP, GCTI, CTIA, CASP+ or equivalent. ## Description The Information Security Engineer plays a key role in protecting Affinity Plus Federal Credit Union from cybersecurity threats by designing, implementing, managing, and continuously improving the technologies and controls that support the Information Security Program. This position is responsible for maintaining and enhancing security infrastructure, supporting threat detection and response capabilities, conducting security assessments, and collaborating with internal teams and external partners to strengthen the organization's security posture. The role serves as a technical subject matter expert and helps ensure security systems, processes, and defenses are effective against current and emerging threats while supporting the confidentiality, integrity, and availability of corporate data and resources., Security Engineering & Infrastructure Management * Serve as a key resource in the evaluation, selection, implementation, configuration, and ongoing management of information security tools, technologies, and platforms. * Maintain, support, and optimize the security infrastructure and technologies utilized by the Information Security Program. * Collaborate with technology teams to ensure security solutions are effectively integrated, configured, and maintained across the enterprise. * Evaluate existing security controls and recommend enhancements to improve operational effectiveness, efficiency, and security posture. * Lead the implementation and lifecycle management of security technologies, ensuring solutions remain current, supported, and aligned with organizational needs. Threat Management, Detection & Response * Collaborate with Information Security team members to develop, maintain, and continuously enhance Security Information and Event Management (SIEM) capabilities and detection strategies. * Coordinate with threat intelligence sharing organizations and security partners to facilitate the collection, analysis, and sharing of relevant threat intelligence. * Conduct threat intelligence, threat hunting, and reconnaissance activities to identify emerging threats, assess risks, and improve organizational preparedness and response capabilities. * Monitor and evaluate threat intelligence information to identify potential impacts to the organization and recommend appropriate mitigation strategies. * Act as a technical resource during the investigation, analysis, and response to security events and incidents. * Develop and maintain detection use cases, correlation rules, alerts, and dashboards to improve visibility into potential security threats and suspicious activity. Vulnerability Management & Security Assessments * Ensure internal and external vulnerability assessments, attack surface reviews, scans, and security testing activities are conducted regularly. * Analyze assessment results and collaborate with stakeholders to prioritize remediation efforts and reduce organizational risk. * Partner with third-party security providers and internal teams to support penetration tests, security assessments, tabletop exercises, audits, and related testing activities. * Validate remediation efforts and verify identified vulnerabilities have been appropriately addressed. Security Strategy, Governance & Continuous Improvement * Assist in the development, implementation, maintenance, and communication of enterprise-wide information security strategies, standards, procedures, and policies. * Provide technical expertise and recommendations to support strategic security initiatives and program enhancements. * Research emerging technologies, security trends, vulnerabilities, and threat landscapes to support the continuous improvement of the Information Security Program. * Collaborate with Information Technology, business stakeholders, and security partners to strengthen organizational cybersecurity capabilities. Security Consulting & Collaboration * Serve as a technical subject matter expert for information security technologies, controls, and best practices. * Partner with internal teams to provide security guidance and recommendations for projects, operational initiatives, and technology implementations. * Support awareness and education efforts by sharing technical security knowledge and best practices with stakeholders across the organization. * Build and maintain productive relationships with internal teams, vendors, industry groups, and external security partners. * Other duties as assigned, This role is: Virtual First - Requires reliable internet access and home office setup. Onsite work will be required throughout the year for training, team meetings and events; typically in or near St. Paul, MN. Applicants should live in Minnesota or Wisconsin or within a reasonable commuting distance to the metro area. Physical Requirements * Sitting 90-95% and standing 5-10%. * Working at a computer 98% of the day. * Repetitive movements, including but not limited to typing, mousing, phones, etc. * May require to lift, carry, push or pull up to 30 pounds. * Bending, twisting, kneeling, stooping, or crouching on occasion. Requires onsite presence based on coordination of work with other employees and/or departments. May require travel to attend on-site meetings/events for collaboration, connection, project work, All-Employee Day, etc. Required Work Schedule Standard Monday through Friday business hours with a willingness to work a flexible schedule as needed. Consistent and reliable attendance is a required essential function of this role to meet the needs of the department/team and organization. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Demystifying application networking in the cloud](https://www.wearedevelopers.com/videos/675-demystifying-application-networking-in-the-cloud) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)