American Enterprise Group

Information Security Engineer 3 - Hybrid- Des Moines, Iowa

American Enterprise Group • $100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Advanced knowledge of security architecture and engineering principles, cloud security, and data protection controls.
  • Strong familiarity with Microsoft Azure and Microsoft 365 security solutions.
  • In-depth understanding of Zero Trust principles and identity-related security threats.
  • Ability to navigate and apply security frameworks and regulatory compliance standards.
  • Bachelor's degree in a relevant discipline, or equivalent work experience accepted.
  • Preferred certifications include CISSP, CCSP, and relevant Microsoft security certifications.
  • 7+ years of experience in information security or related technical fields.

Responsibilities

  • Architect and implement security controls for systems, applications, and cloud services.
  • Conduct security architecture reviews and risk assessments for new technologies and integrations.
  • Partner with Identity and Access Management to enforce secure authentication and access policies.
  • Collaborate with security service providers for enhanced monitoring and incident response capabilities.
  • Lead investigations of significant security incidents, documenting findings and developing improvement plans.
  • Identify and communicate vulnerabilities in systems and provide remediation guidance.
  • Ensure security measures keep pace with emerging technologies and threats.

Benefits

  • Opportunities for professional development and growth within the company.
  • Work with cutting-edge technologies in a collaborative environment.
  • Flexibility in work arrangements, potentially including remote work options.
  • Access to industry-relevant training and certifications.
  • Engagement in impactful projects that protect sensitive information.
Full Job Description
The Information Security Engineer 3 provides senior-level security engineering expertise for the architecture, design, implementation, operation, and continuous improvement of security technologies and controls that protect the confidentiality, integrity, and availability of company systems and data.

This position provides senior technical expertise in security architecture, cloud security, vulnerability and exposure management, incident response, data protection, security monitoring oversight, and emerging technology risk assessment. The role partners with technology teams, Identity and Access Management, business stakeholders, managed security service providers, and leadership to reduce security risk while enabling business objectives.

Be successful in this role

Someone in this role will:

  • Security Architecture and Engineering
    • Architects, implements, maintains, and improves information security controls and countermeasures.
    • Conducts security architecture reviews for systems, applications, cloud services, integrations, and technology initiatives.
    • Reviews proposed technologies, software platforms, vendor solutions, integrations, and cloud services to identify security risks and recommend appropriate safeguards before implementation.
    • Evaluates technical designs and recommends controls based on company policies, technical standards, regulatory obligations, risk, and business objectives.
    • Develops security baselines, technical standards, implementation guidance, and secure configuration requirements.
    • Provides senior technical expertise and security consultation to project teams, engineers, architects, system owners, and business stakeholders.
  • Cloud Security
    • Provides senior technical expertise for the design, implementation, and assessment of security controls supporting Microsoft Azure, Microsoft 365, software-as-a-service platforms, and other approved cloud services.
    • Assesses cloud resources, storage, networking, applications, identities, integrations, and service configurations for security risk.
    • Develops and maintains cloud security baselines and configuration standards.
    • Identifies cloud security exposures and partners with technology owners to develop practical remediation or risk-reduction plans.
    • Reviews encryption, public access, logging, privileged access, network connectivity, and data protection requirements for cloud services.
    • Provides technical guidance for cloud security posture management and continuous improvement activities.
  • Identity Security
    • Partners with the Identity and Access Management team to support secure authentication, authorization, privileged access, and identity governance initiatives.
    • Applies an understanding of Microsoft Entra ID, multifactor authentication, Conditional Access policy concepts, risk-based access controls, privileged access, and Zero Trust principles when assessing security designs and incidents.
    • Assesses security risks associated with user accounts, service accounts, application identities, machine identities, credentials, and third-party access.
    • Provides security guidance and architectural recommendations without performing routine user provisioning, access fulfillment, or Identity and Access Management administration.
    • Supports investigations involving credential compromise, unauthorized access, suspicious authentication activity, and identity-based threats.
  • Security Monitoring and Detection Oversight
    • Partners with managed security service providers and security operations partners to support monitoring, detection, investigation, and response activities.
    • Provides senior technical expertise for escalated alerts, investigations, threat analysis, and response activities requiring internal security engineering support.
    • Develops and improves detection capabilities, alerting logic, dashboards, queries, reporting, and monitoring coverage.
    • Provides technical guidance for improving monitoring effectiveness, detection coverage, escalation quality, and security visibility.
    • Identifies gaps in logging, telemetry, data quality, and visibility and coordinates improvements with appropriate technology teams.
    • Assesses emerging threats and recommends updates to monitoring, detection, and defensive controls.
  • Incident Response
    • Provides senior technical expertise for escalated security events, investigations, and incident response activities.
    • Leads, supports, or provides technical expertise for investigation, containment, remediation, recovery, and post-incident review activities associated with significant security incidents.
    • Investigates unauthorized access, malicious activity, credential compromise, policy breaches, and potential data exposure.
    • Coordinates response activities with managed security service providers, technology teams, leadership, legal and privacy partners, cyber insurance providers, and third-party responders as appropriate.
    • Documents technical findings, contributing factors, corrective actions, and recommended improvements.
    • Develops and maintains incident response procedures, technical playbooks, and investigation methods.
  • Vulnerability and Exposure Management
    • Identifies, evaluates, prioritizes, and communicates vulnerabilities and security exposures affecting company systems, applications, cloud services, and data.
    • Uses business context, asset criticality, data classification, exploitability, external exposure, and compensating controls to help prioritize risk reduction.
    • Provides technical expertise and recommendations to system owners regarding remediation plans, compensating controls, and risk-reduction strategies.
    • Validates remediation activities and provides technical input for exception or risk acceptance decisions.
    • Supports vulnerability scanning, penetration testing, attack-surface reviews, control validation, and security assessments.
    • Develops reporting that communicates material exposures, remediation progress, aging, and recurring control weaknesses.
  • Application Security and DevSecOps
    • Partners with application development, infrastructure, and architecture teams to integrate security into the system development lifecycle.
    • Reviews application architecture, authentication, authorization, data handling, interfaces, application programming interfaces, and third-party components.
    • Supports secure code analysis, dependency review, secrets detection, application testing, and remediation processes.
    • Identifies opportunities to automate security checks within development and deployment workflows.
    • Provides practical technical guidance for application and software supply-chain risks.
  • Data Protection and Privacy
    • Provides technical expertise for the design, implementation, and assessment of controls related to data classification, encryption, retention, information protection, and data loss prevention.
    • Evaluates how regulated, confidential, and sensitive information is collected, stored, processed, transmitted, shared, and disposed of.
    • Partners with Information Privacy, Legal, Compliance, business owners, and technology teams to address data protection requirements.
    • Assesses security controls for information subject to HIPAA and other applicable legal, contractual, and regulatory obligations.
    • Supports investigations involving potential unauthorized disclosure or exposure of sensitive information.
  • Security Automation
    • Provides technical expertise in developing and maintaining scripts, integrations, workflows, queries, and automation that improve security monitoring, investigation, reporting, and remediation.
    • Uses appropriate scripting, query, application programming interface, source control, and orchestration technologies to improve operational efficiency.
    • Automates repeatable security processes where practical while maintaining appropriate testing, documentation, approval, and change controls.
    • Supports the integration of security checks into infrastructure-as-code and deployment processes when appropriate.
  • Security Governance, Risk, and Compliance
    • Analyzes changes in the threat, technology, regulatory, and compliance environments and evaluates their effect on organizational risk.
    • Contributes technical expertise to the development and maintenance of information security policies, standards, procedures, baselines, and guidelines.
    • Provides technical evidence and support for audits, regulatory examinations, security assessments, and control reviews.
    • Performs security risk and control assessments and recommends practical risk-treatment options.
    • Provides technical expertise supporting third-party technology, vendor security, and architecture reviews.
    • Communicates technical risks, control options, compensating safeguards, and residual risk to technical and nontechnical audiences.
  • Security Service Management
    • Provides technical oversight for managed security service providers and security technology partners.
    • Reviews monitoring effectiveness, escalation quality, service performance, detection coverage, and investigation outcomes.
    • Collaborates with providers to improve monitoring capabilities, response playbooks, detection logic, and incident handling processes.
    • Provides technical guidance to help ensure outsourced security services meet business and security requirements.
  • Artificial Intelligence and Emerging Technology Security
    • Provides technical expertise in assessing risks associated with artificial intelligence, generative artificial intelligence, automation, and emerging technologies.
    • Reviews proposed use cases, integrations, data flows, access models, and vendor capabilities for security concerns.
    • Recommends safeguards addressing sensitive data exposure, access control, logging, third-party access, and misuse risks.
    • Partners with privacy, legal, technology, and governance stakeholders to support secure and responsible adoption of emerging technologies.
  • Communication and Collaboration
    • Communicates technical risks, findings, and recommendations clearly to technical and nontechnical audiences.
    • Builds collaborative relationships across Information Security, Information Technology, business departments, and third-party providers.
    • Leads or contributes to complex security initiatives involving multiple teams and stakeholders.
    • Creates clear technical documentation, architecture diagrams, standards, procedures, investigation records, and leadership updates.
    • Provides technical mentoring and guidance to other security professionals.

Qualifications

  • Advanced knowledge of security architecture and engineering principles, cloud security concepts, vulnerability and exposure management, incident response, and data protection controls.
  • Strong knowledge of Microsoft Azure and Microsoft 365 security capabilities and experience with enterprise security monitoring, endpoint protection, cloud security posture management, and vulnerability management platforms.
  • Strong understanding of Microsoft Entra ID, multifactor authentication, Conditional Access policy concepts, privileged access, identity-related threats, and Zero Trust principles.
  • Working knowledge of application security, secure development practices, software dependencies, security automation, scripting, application programming interfaces, and infrastructure-as-code concepts.
  • Working knowledge of security and risk frameworks and the legal, contractual, privacy, and regulatory requirements applicable to regulated organizations.
  • Ability to analyze complex technical information, identify material risk, prioritize work, and recommend practical safeguards that account for security, operational, and business needs.
  • Ability to independently lead or contribute senior technical expertise to security initiatives and incident response activities.
  • Ability to communicate complex security concepts in clear language and produce accurate, defensible technical documentation.
  • Ability to collaborate across teams without assuming operational ownership of systems managed by other departments.
  • Ability to exercise sound judgment, manage competing priorities, and appropriately handle confidential information.
  • Bachelor's degree in information security, cybersecurity, computer
  • science, information systems, engineering, or a related field. A combination of education and relevant work experience may be accepted in lieu of a degree.
  • Preferred Certifications:
    • Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), a relevant Microsoft security certification, a GIAC certification, CompTIA Security+ or SecurityX, or a comparable security or cloud certification.
  • 7+ years of progressive experience in information security, security engineering, cloud security, infrastructure security, security operations, or a related technical discipline.
  • Demonstrated experience designing, implementing, operating, or assessing enterprise security controls.
  • Demonstrated experience providing senior technical leadership for complex security initiatives or investigations.
  • Experience with cloud security, vulnerability management, security monitoring, endpoint security, data protection, application security, or related security technologies.
  • Experience working with managed security service providers is preferred.
  • Experience in insurance, healthcare, financial services, or another regulated industry is preferred.
  • Experience with several of the following is preferred. Equivalent technologies and transferable experience may be considered:
    • Microsoft Azure and Microsoft 365 security capabilities, including Microsoft Defender, Microsoft Sentinel, Microsoft Purview, and Microsoft Entra ID.
    • Application control and allowlisting platforms, such as ThreatLocker or equivalent technologies.

About American Enterprise Group

American Enterprise Group is an insurance company that provides life, health, and annuity products. The company was founded in 1924 and is headquartered in Des Moines, Iowa. American Enterprise Group operates through its subsidiaries, which include American Republic Insurance Company, Medico Insurance Company, and Great Western Insurance Company. The company's mission is to provide financial security and peace of mind to its customers through its insurance products.
Learn more about American Enterprise Group
Size
500 employees
Industry
Founded
1903

Similar Jobs

More Jobs at American Enterprise Group

More Information Technology Jobs

Find similar Information Security Engineer 3 - Hybrid- Des Moines, Iowa jobs: