> Markdown version of [/jobs/ext/445464-vp-security-engineering](https://www.wearedevelopers.com/jobs/ext/445464-vp-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # VP, Security Engineering - **Company:** Banc of California - **Location:** Santa Ana, CA, United States - **Experience:** Expert - **Salary:** $121,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Access Control List, Cyber Security, Information Systems, Intrusion Detection and Prevention, Network Security, Networking Basics, Security Information and Event Management, Network Access Control, System Availability, Software Security, Mitre Att&ck, Information Technology, Data Analytics, Purple Team (Cyber Security) - **Published:** June 5, 2026 - **Apply:** https://dejobs.org/x/x/DE8EBC1D735D455387440383BDC7C657/job/ ## About the Role * 8+ years of experience with network security, security engineering and/or incident response. * Experience in regulated environments or critical infrastructure preferred (banking, financial services, healthcare, defense, federal government, military) * Vision for modern security operations; balances control rigor with business agility. * Data-driven continuous improvement, SLA management, and platform reliability. * Ability to challenge assumptions and simplify complex systems. * Demonstrates knowledge of, adherence to, monitoring and responsibility for compliance with state and federal regulations and laws as they pertain to this position. * Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy. * Industry methods for evaluating, implementing, and disseminating information technology (IT) security assessment, monitoring, detection, and remediation tools and procedures utilizing standards-based concepts and capabilities. * Computer networking concepts and protocols, and network security methodologies. * Host/network access control mechanisms (e.g., access control list, capabilities lists). * Intrusion detection methodologies and techniques for host and network-based intrusions. * System and application security threats and vulnerabilities, * Proven leadership supporting SIEM/XDR or EDR/SOAR, outsourced SOC vendors, NAC, and major security incidents. * Integration of cyber intelligence and information sources into existing processes (e.g., alerts, advisories, bulletins). * Bachelor's degree in Computer Science, Information Systems, Cyber Security, or other quantitative fields. * Prior banking and/or financial services background is a plus. * CISSP required; CCSP, CISA or CISM Certification also preferred. * High School diploma or equivalent required ## Description The VP, Security Engineer is responsible for designing, implementing, and maintaining enterprise security controls to protect the organization's systems, applications, and data. This role partners closely with IT, Identity, business units, and application teams to integrate security into architecture and operational processes. A key stakeholder in the evaluation and deployment of security technologies, and supports detection, response, and remediation activities for security incidents. The Security Engineer is also responsible for the implementation of security standards and automation, assesses emerging threats and vulnerabilities, and provides technical expertise to reduce risk while enabling business operations. Performs all duties in accordance with the Company's policies and procedures, all U.S. state and federal laws and regulations, wherein the Company operates., * Design, implement, and maintain core security engineering controls across SIEM, EDR, email security, DLP, and related platforms * As needed, develop, tune, and maintain SIEM detection content, use cases, and analytics aligned to MITRE ATT&CK coverage * Engineer and mature threat detection & response capabilities, including automation, enrichment, and response workflows * Serve as a technical lead during major security incidents, supporting investigation, containment, remediation, and post incident root cause analysis * Partner with incident response and SOC teams to improve detection fidelity, response time, and coverage metrics * Implement and enforce secure architecture standards * Integrate security controls into cloud, infrastructure, and application environments in collaboration with platform and development teams * Evaluate, deploy, and integrate new security tools and technologies in support of the security roadmap * Support red & purple team exercises, attack simulations, and detection validation efforts * Document standards, runbooks, and engineering procedures to support operational consistency and scale * Provide technical mentorship and guidance to junior security engineers and cross functional partners * Involved with interviewing and hiring decisions. * Prepare and deliver employee performance evaluations, goal planning, and counseling. * Manage, support, coach and train employees. * Follow all established policies and procedures. * Perform other duties and projects as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)