OverviewEnterprise Context & Vision
Banner Life has experienced significant growth over the past several years, driven by digital transformation and platform led innovation. As we look ahead, we have an ambitious goal to more than triple our revenue over the next decade by expanding into new products, distribution channels, and customer experiences.
As the organization scales through cloud modernization, data expansion, AI enabled capabilities, and new business growth, it requires cybersecurity capabilities that are engineered into platforms, products, cloud services, data ecosystems, AI enabled workloads, and digital operations from the beginning.
Within this context, Security Engineering & Technology Enablement is the CHANGE / TRANSFORM cyber pillar responsible for building, modernizing, automating, and scaling the technical security capabilities needed to support the future enterprise.
Purpose and Objective
The Manager, Security Engineering & Technology Enablement is accountable for the design, engineering, modernization, lifecycle management, and continuous improvement of enterprise security platforms and technical controls.
This role owns the security engineering roadmap across cloud security, identity security, endpoint / DLP / email security, network security, application / AI security, security automation, security tooling, and control implementation. It ensures security capabilities are scalable, supportable, integrated, measurable, and aligned to Banner Life’s future-state technology architecture.
This role represents the CHANGE / TRANSFORM / Build pillar of the Cybersecurity Target Operating Model, working closely with Security Operations & Cyber Defense and Cyber Governance, Compliance & Security Architecture to ensure operational gaps, incidents, detection needs, risk decisions, and architecture patterns are translated into engineered security capabilities.
Responsibilities
Core Responsibilities
- Security Engineering Strategy & Roadmap
- Define and evolve the enterprise security engineering roadmap aligned to cyber strategy, business growth, technology modernization, and emerging threats.
- Establish engineering standards, design patterns, lifecycle plans, and modernization priorities for security tools and technical controls.
- Ensure security engineering capabilities support cloud, infrastructure, application, data, AI, identity, endpoint, and digital platform growth.
- Partner with the CISO, Security Architecture, Infrastructure, Cloud, Data, Product, and application Engineering to align security engineering to enterprise roadmaps.
- Security Platform & Tooling Modernization
- Own lifecycle management, modernization, integration, and optimization of enterprise security tools and platforms.
- Ensure security tools are configured, integrated, monitored, and improved to deliver measurable control effectiveness.
- Drive reduction of tool fragmentation, manual effort, technical debt, and unsupported security technologies.
- Partner with Security Operations to ensure tools support effective detection, response, telemetry, and operational use cases.
- Cloud, Identity & Infrastructure Security Engineering
- Lead engineering of security controls across cloud, hybrid infrastructure, identity, network, and endpoint environments.
- Ensure cloud security posture, identity controls, network security patterns, endpoint controls, DLP, email security, and access security capabilities are engineered for scale and resilience.
- Partner with Infrastructure, Cloud, and IT Operations teams to ensure controls are supportable, observable, and ready for RUN transition.
- Ensure Zero Trust and identity-first principles are translated into practical security engineering outcomes.
- Application, Data & AI Security Enablement
- Lead security engineering support for application security, API security, secure SDLC, AI / LLM security, and data protection capabilities.
- Partner with Application Engineering, Product, Data, and AI teams to build repeatable security patterns and controls.
- Support secure adoption of AI-enabled workloads, including model access controls, logging, monitoring, data protection, and responsible usage.
- Engineer security controls for agentic AI and tool-integration protocols (e.g., Model Context Protocol / MCP), including authorization scoping, tool-call auditing, data egress controls, and governance of AI-to-system access.
- Ensure security requirements are embedded into digital product and platform engineering practices.
- Automation, Integration & Engineering Excellence
- Drive security automation, scripting, workflow integration, policy-as-code, and repeatable control deployment.
- Improve integration between security platforms, ITSM, CI/CD pipelines, cloud services, identity platforms, observability, and reporting tools.
- Develop reusable engineering patterns that reduce operational effort and improve consistency.
- Promote engineering discipline, documentation, knowledge transfer, and operational readiness.
- Partner & Delivery Enablement
- Govern security technology partners and implementation partners to ensure delivery quality, knowledge transfer, and sustainable internal capability.
- Ensure external partners accelerate security engineering maturity without replacing internal decision ownership.
- Partner with Security Operations and Governance leaders to ensure engineering changes improve risk posture and operational outcomes.
- Support business cases and investment decisions for security technology modernization.
Key Outcomes & Measures of Success
- Modernized security platforms and reduced technical debt.
- Improved cloud, identity, endpoint, data, application, and AI security control maturity.
- Stronger integration between security engineering and security operations.
- Increased automation and reduced manual operational effort.
- Security capabilities engineered for scale, supportability, and future growth.
- Clear transition of engineered capabilities into RUN / Security Operations ownership.
- Measurable improvement in security control effectiveness across cloud, identity, endpoint, application, data, and AI environments.
Qualifications
Education
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field required.
- Equivalent combination of education and deep security engineering leadership experience will be considered.
Required Experience / Knowledge
- 6+ years of experience in security engineering, cloud security, identity security, infrastructure security, application security, security architecture, or security technology leadership.
- Experience leading security platform modernization or control implementation in an enterprise environment.
- Strong knowledge of cloud security, identity security, endpoint security, DLP, email security, network security, application security, API security, and AI / LLM security concepts, including agentic AI and tool-integration protocols such as Model Context Protocol (MCP).
- Experience securing AI agent and MCP server architectures, including authorization/access scoping for AI-to-system tool calls, audit logging of agent actions, data egress controls, and governance of third-party/connected AI tools.
- Experience implementing or managing security tools, integrations, automation, monitoring, logging, and control platforms.
- Experience partnering with infrastructure, cloud, application, data, and product engineering teams to deliver secure-by-design capabilities.
- Strong understanding of Zero Trust, policy-as-code, automation, observability, secure SDLC, and operational readiness.
- Ability to translate security strategy and architecture into practical engineering outcomes.
- Strong communication, vendor management, and cross-functional leadership skills.
Preferred Certifications
- CISSP, CCSP, Azure Security Engineer, AWS Security Specialty, GIAC, GSEC, GCSA, Kubernetes / container security, or equivalent preferred. AI/agentic security credentials such as the GIAC AI-focused certifications, ISACA AAISM, or equivalent AI security/governance credentials are a plus given this role's AI and MCP security scope.
Skills & Leadership Competencies
- Strong engineering leadership with the ability to translate cyber strategy, architecture, and risk priorities into practical security platforms, controls, and technical capabilities.
- Ability to define engineering standards, design patterns, reusable controls, and implementation approaches that improve security maturity at scale.
- Strong understanding of cloud security, identity security, endpoint protection, DLP, email security, network security, application security, API security, AI / LLM security, agentic AI and MCP / tool-integration security, automation, and security tooling.
- Practical judgment in balancing security, usability, delivery speed, cost, operational readiness, and long-term maintainability.
- Ability to partner effectively with Security Operations to translate incidents, detection gaps, vulnerabilities, and operational pain points into engineered improvements.
- Ability to partner effectively with Cyber Governance, Compliance & Security Architecture to translate policies, standards, risk decisions, and architecture patterns into implementable controls.
- Strong communication skills, including the ability to explain technical security decisions, trade-offs, risks, and implementation plans to both technical and non-technical stakeholders.
- Proven ability to lead modernization of security platforms, reduce technical debt, improve integration, and increase automation.
- Ability to govern security technology partners and implementation partners through delivery quality, knowledge transfer, internal capability growth, and sustainable outcomes.
- Proven ability to mentor security engineers and raise maturity across security engineering, automation, platform integration, cloud security, identity security, and application / AI security practices.
- Collaborative leadership style with the ability to work across Cybersecurity, Infrastructure, Cloud, Data, Product, Application Engineering, IT Operations / XLA, and Enterprise Architecture.
What’s in it for you?
The expected hiring compensation range for this position is $144,800 - $199,100 annually. This is a hybrid opportunity working in Frederick, MD.
The total compensation package for this position may include other elements, such as a sign-on bonus, long term incentives, and annual bonuses. This role is eligible to participate in the Annual Incentive Plan. The current target payment for the position is 20% of base salary, modified for corporate and individual performance. Bonuses are pro-rated based on start date. This role has 20 vacation days and 10 sick days that are accrued on a bi-weekly basis. Employees also have 9 paid holidays throughout the calendar year.
We have a competitive compensation and benefits package focused on your overall wellbeing. Employee benefits include health, life, and dental insurance; 401K with company match up to 6% as well as a pension package; generous time off; and wellbeing initiatives throughout the year (we like doing fun stuff). We’re big on professional development and we’ll support and mentor you in your career progression and expect you to help us pay it forward by helping us develop tomorrow's leaders and growth-focused professionals. We value our teams and our communities and believe in giving back. Enjoy time off to volunteer for those causes that matter most to you!