Information Security Engineer

City Bank
Lubbock, TX, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cloud Computing Security Cyber Security Data Governance Identity and Access Management Log Analysis Cloud Platform System Firewalls (Computer Science) Vulnerability Analysis

Job description

The Information Security Engineer is responsible for the design, implementation, operation, and continuous improvement of the Bank’s information security program. This role provides hands-on engineering and operational ownership across security domains, including security operations, threat and vulnerability management, identity and access management, incident response, cloud security, and AI governance. The Information Security Engineer serves as a key technical resource responsible for securing enterprise systems, managing and optimizing security technologies, and ensuring alignment with regulatory requirements and emerging threats. This position operates with a high degree of autonomy and accountability and collaborates closely with IT, Risk, and business units., The Information Security Engineer may perform, be responsible for, or assist in one or more of the following information security functions:

  • Security Engineering & Operations - Design, implement, and maintain enterprise security controls and technologies. Monitor security systems, analyze logs and alerts, and perform investigations. Continuously improve detection and response capabilities.
  • Threat and Vulnerability Management - Perform vulnerability scanning, threat monitoring, and risk analysis. Prioritize, track, and coordinate remediation activities with IT and business stakeholders.
  • Incident Response - Lead incident response activities, including investigation, containment, eradication, and recovery. Perform forensic analysis and document findings. Participate in after-hours response as needed.
  • Identity & Access Management - Own and administer the Bank’s Identity and Access Management (IAM) program. Design and enforce identity governance, provisioning, deprovisioning, authentication, and authorization controls. Manage role-based access models, privileged access management, and identity lifecycle processes. Ensure access decisions align with least privilege and regulatory expectations. Oversee access certifications and continuously improve identity control effectiveness.
  • AI Governance & Emerging Technology Risk - Support and administer governance processes for AI systems and tools used within the Bank. Maintain inventory, risk classification, and monitoring of AI agents and solutions. Ensure alignment with internal policies, regulatory expectations, and model risk management requirements. Collaborate with stakeholders to evaluate and onboard new AI use cases securely.
  • Cloud Security - Design, implement, and maintain cloud security controls aligned with the Bank’s architecture. Monitor cloud environments for misconfigurations, threats, and compliance issues.
  • Security Tools Administration - Administer and optimize security technologies, including firewalls, endpoint security platforms, and related tools. Evaluate and implement new security solutions as needed.
  • Data Governance & Retention - Support oversight of data protection, classification, and retention practices. Assist in the management and reporting of tools supporting data governance.
  • Data Analysis & Reporting - Develop and present security metrics, dashboards, and reports for leadership, committees, and auditors. Support risk reporting and program maturity tracking.
  • Security Awareness & Training - Support the development and execution of security awareness and training programs. Track effectiveness and recommend improvements.
  • Vendor Management - Participate in vendor onboarding, risk assessments, and ongoing monitoring activities. Support administration of vendor risk management tools.
  • Business Continuity Planning - Support business continuity and disaster recovery planning, testing, and improvement efforts.

Requirements

Do you have experience in Vulnerability scanning implementation?

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:53 min

Reinventing data governance as a collaborative business foundation

Farooq Sheikh Farooq Sheikh +3 · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all