FIRSTRUST BANK
Recognizes the leader in you*Hybrid Position*We are seeking a highly skilled and motivated Information Security Engineer to join our IT Security team. In this role, you will be a key defender of our infrastructure, bridging the gap between advanced threat defense, cloud security, and corporate compliance.
The ideal candidate possesses a deep technical understanding of modern cloud architectures (
SASE/CASB), a proactive mindset for
threat hunting, and the diligence required to manage
Business Continuity/Disaster Recovery (BC/DR) operations and data governance via
Microsoft Purview.
JOB DUTIES AND RESPONSIBILITIES: 1. Network & Cloud Security (SASE, CASB, Firewalls)- Design, deploy, and maintain Next-Generation Firewall (NGFW) policies and rules ensuring least-privilege access.
- Manage and optimize our Secure Access Service Edge (SASE) architecture to support a secure remote/hybrid workforce.
- Implement and monitor Cloud Access Security Broker (CASB) solutions to gain visibility into shadow IT, enforce data compliance, and prevent data leakage across SaaS applications.
- Maintain firewall change management processes, including peer review, staging/testing, and post-change validation.
2. Threat Hunting & Incident Response- Proactively conduct threat hunting campaigns across network, endpoint, and cloud logs to identify anomalous behavior and latent threats that bypass traditional security controls.
- Analyze security telemetry (SIEM/XDR) to reconstruct attack vectors and develop custom detection rules.
- Act as a core member of the Incident Response team, including containment, eradication, and post-incident analysis.
- Maintain current awareness of emerging threat actor groups, CVEs, and exploitation trends relevant to our industry and technology stack.
- Remain available outside of standard business hours to respond to escalated, high-priority security events as needed.
3. Business Continuity & Disaster Recovery (BC/DR)- Collaborate with business stakeholders to develop, maintain, and update Business Continuity and Disaster Recovery plans.
- Coordinate and lead regular BC/DR tabletop exercises and technical disaster recovery drills (failovers, backups restoration).
- Ensure defined RPOs and RTOs are achievable, tested, and aligned with regulatory requirements - flagging gaps to leadership with clear remediation paths.
4. Microsoft Purview: Data Governance & eDiscovery- Administer and optimize the Microsoft Purview compliance suite with hands-on ownership of: Information Protection (sensitivity labels, auto-labeling policies), Data Loss Prevention (DLP) policies across M365 and endpoint, Compliance Manager (assessment tracking, control mapping), and Advanced eDiscovery.
- Design and manage end-to-end eDiscovery workflows: creating review sets, applying legal holds, running targeted content searches, managing custodian communications, and producing defensible data exports in coordination with legal counsel.
- Develop and refine DLP policies to reduce false positives, improve policy coverage, and generate actionable alerts - working with business units to balance security with operational productivity.
- Monitor Purview audit logs and compliance dashboards, escalating anomalies and producing regular reports for security leadership and legal/compliance stakeholders.
OTHER JOB DUTIES AND RESPONSIBILITIES:- Assists in the development of new business for Firstrust. Is alert to expressed customer/prospect needs to suggest appropriate services. Directs customers to appropriate person to establish business relationships.
- Other duties as assigned.
PHYSICAL AND SENSORY REQUIREMENTS:- Prolonged periods sitting at a desk and working on a computer.
- Regularly required to drive a motor vehicle, occasional air travel, attending meetings at various venues, including but not limited to customers' offices and/or properties, restaurants and other meeting locations, and ascend/descend stairs and or ladders occasionally to perform inspections.
- The employee may be required to lift files/materials up to 20 pounds to take to various locations.
- The incumbent will be expected to operate a computer terminal.
- Prolonged periods sitting at a desk and working on a computer
POTENITAL ON-THE-JOB-RISKS:EDUCATION, TRAINING AND EXPERIENCE:- Education: Bachelor's degree in Computer Science, Cyber Security, Information Technology, or equivalent practical experience.
- Experience: 5+ years of progressive experience in cybersecurity engineering or a dual security/compliance role.
- Technical Expertise:
- Firewalls: Hands-on production-level configuration and administration of NGFW platforms.
- Threat Hunting: Demonstrated experience running structured hunting campaigns, not just reactive alert investigation. Must be able to articulate past hunts, methodologies used, and outcomes achieved
- SIEM/XDR: Proficiency in KQL (Microsoft Sentinel) and/or Splunk SPL for threat hunting, detection engineering, and forensic analysis.
- Experience administering or supporting SASE/CASB platforms.
- Microsoft Purview: Meaningful hands on experience with DLP Policies, Compliance Manager, Information Protection, Advanced eDiscovery).
- Strong understanding of threat actor TTPs (MITRE ATT&CK framework) and query languages (e.g., KQL, Splunk SPL) for threat hunting.
- Experience writing, testing, and auditing BC/DR documentation and participating in routine exercises.
Experience in a regulated industry ([finance/healthcare/etc.]) with frameworks such as [SOC 2, ISO 27001, HIPAA, NIST CSF]
Communication & Collaboration- Strong written communication: ability to document procedures, write post-incident reports, and translate technical risk for legal, compliance, and executive audiences
- Proven ability to partner with non-technical business units to balance security controls with operational productivity