Principal Engineer, IT Infrastructure & Security

Verus Mortgage Capital
Bloomington, MN, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$160,000.0 - $175,000.0
Working hours
Regular working hours
Job source

Tech stack

IEEE 802.1X User Authentication Microsoft Azure Bash Shell Cloud Computing Cyber Security Information Systems Data Security Digital Forensics Disaster Recovery Identity and Access Management Intrusion Detection and Prevention
+15 more
Virtual Private Networks (VPN) Network Security Network Segmentation Performance Tuning Windows PowerShell Azure Active Directory Zero Trust Network Access Security Information and Event Management Traffic Analysis Data Logging Load Balancing Data Classification Data Layers Information Technology Cybercrime

Job description

We’re looking for a hands-on infrastructure and security leader to architect, secure, and operate our hybrid enterprise environment. You’ll own our defense-in-depth security model and Zero Trust strategy across identity, devices, network, applications, and data. You’ll be the one building and running it, not just directing it. This role also has direct oversight of our Network & Systems Administrator., Enterprise Architecture & Zero Trust - Design and implement secure infrastructure across on-prem and Azure environments, applying Zero Trust principles throughout.

  • Identity-driven access, device trust enforcement, and network micro-segmentation
  • Defense-in-depth strategy spanning perimeter, endpoint, identity, and data layers

Network & Security Engineering - Own enterprise networking and perimeter/internal security, along with threat detection and response.

  • Enterprise firewall management, including advanced threat protection and application control
  • Network segmentation, access control, and authentication (RADIUS/802.1X)
  • Traffic analysis and anomaly detection, integrated into centralized logging/SIEM

Cloud & Identity (Azure) Architect our Azure environment and hybrid identity model.

  • Azure infrastructure: VMs, VNets, load balancers, and hybrid connectivity (VPN/ExpressRoute)
  • Hybrid identity via Entra ID, including conditional access, MFA, and privileged identity management
  • Infrastructure-as-code and automation of cloud provisioning

Endpoint & Data Security - Manage endpoint security, MDM, and data protection strategy.

  • Device lifecycle management and MDM/MAM policy enforcement
  • EDR/XDR deployment, tuning, and threat hunting
  • Data classification, encryption, and loss prevention

Monitoring & Incident Response - Build observability and lead our response to security and infrastructure incidents.

  • Centralized monitoring, alerting, and performance baselining
  • Incident response, digital forensics, and root cause analysis
  • Disaster recovery and business continuity planning and testing
  • Provide after-hours support for critical UIT issues and service disruptions when necessary.

Compliance & Governance - Align infrastructure and controls to relevant regulatory frameworks.

  • NIST, CIS, ISO 27001, and FFIEC alignment
  • Audit support, risk assessments, and architecture/control documentation

Automation & Leadership - Reduce manual work and serve as a technical authority for the team.

  • Scripting and automation (PowerShell, Bash, or similar) across routine operations
  • Technical escalation points and mentor to engineering staff
  • Direct oversight of the Network & Systems Administrator, * Enterprise Architecture Leadership: Designs secure, scalable infrastructure aligned with business and security objectives
  • Cybersecurity Expertise: Implements advanced security frameworks and defense-in-depth strategies
  • Cloud & Network Engineering: Demonstrates deep expertise across hybrid infrastructure and enterprise networking
  • Technical Leadership: Serves as a trusted technical authority and mentor across the organization
  • Automation & Innovation: Continuously improves operational efficiency through automation and modern engineering practices

How This Role Demonstrates Our Values:

  • Integrity: Protects company systems, data, and infrastructure through disciplined security and governance practices
  • Collaboration: Partners across IT, Security, and business teams to deliver secure and scalable solutions
  • Excellence: Maintains high standards for infrastructure reliability, performance, and operational maturity
  • Critical Curiosity: Evaluates emerging technologies and continuously improves enterprise architecture and security posture, Maintaining a reliable, uninterrupted high speed internet connection is a requirement of hybrid or remote positions. All job duties and responsibilities must be performed within the guidelines of the Verus Residential Mortgage Employee Handbook and established company policies and procedures. It is the responsibility of each employee to maintain confidentiality of the company, its clients and to follow applicable laws and regulations in the performance of duties. Verus Mortgage Capital is an equal opportunity employer. All qualified applicants are welcomed to apply and will receive consideration for employment without unlawful discrimination because of a person’s race, religious creed, color, national origin, citizenship status, ancestry, marital status, sex, age, or sexual orientation, or because of a person’s disability or medical condition.

About Invictus Capital Partners / Verus Mortgage Capital Verus Mortgage Capital is an independent national mortgage investor. Verus offers its Sellers responsible non-prime and Jumbo prime lending products that fill the credit void in today’s market. Verus consistently evaluates today’s market and credible borrower financing needs to offer our partners innovative solutions. Verus Mortgage Capital is an affiliate of Invictus Capital Partners please visit our website at https://verusmc.com/.

Requirements

  • Bachelor’s degree in computer science, information systems, cybersecurity, engineering, or a related field - or equivalent experience/certifications
  • 7+ years of progressive experience in network engineering, cloud infrastructure, or cybersecurity, with hands-on ownership of enterprise-scale environments
  • Strong, hands-on expertise across enterprise networking/firewalls, Microsoft Azure architecture, and modern EDR/XDR tooling
  • Working knowledge of Zero Trust principles, hybrid identity (Azure AD/Entra ID), and endpoint/MDM management
  • Experience supporting regulatory or compliance frameworks common in financial services (e.g., NIST, FFIEC, ISO 27001)
  • Comfortable scripting and automating routine operations (PowerShell, Bash, or similar)

Benefits & conditions

Pulled from the full job description Tuition reimbursement Paid parental leave Parental leave Health insurance 401(k) matching Paid time off Vision insurance, * Competitive compensation package, including base salary and performance-based bonus opportunities

  • 401(k) plan with 100% company match up to 4%
  • Comprehensive health coverage: medical, dental, vision, HSA, and FSA options
  • Generous paid time off: 20 days PTO, company holidays, and sick time
  • Paid parental leave
  • Company-paid life insurance and disability coverage
  • Employee Assistance Program (EAP): mental health, financial, and wellness support
  • Professional development: tuition reimbursement and growth opportunities
  • Commuter and transit benefits

Successful applicants will exemplify strong ethics, integrity, respect for others, accountability for decisions and actions, and good citizenship.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:58 min

Shifting security permissions from applications to the data layer

Neena Thomas Neena Thomas · World Congress 2026 Europe

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

55 sec

Integrating recommended UI architectures with Jetpack Compose

Crístian Viana · World Congress 2023

Videos

See all

Related articles

See all