Principal Information Security Engineer

Beacon Bank

$96K — $177K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Information Technology, Cybersecurity, or related field preferred
  • 7+ years of experience in information security, cybersecurity engineering, or related technology roles
  • 3+ years in a regulated financial institution or similarly regulated industry preferred
  • Experience with security technologies including Microsoft Entra ID, cloud security, and endpoint security
  • Familiarity with AI security measures and technologies, particularly for Generative AI and Machine Learning
  • Security certifications such as CISSP, CISM, or related credentials favored
  • Strong understanding of banking security expectations and NIST Cybersecurity Framework.

Responsibilities

  • Administer and enhance enterprise information security technologies and lead the continuous improvement programs
  • Develop and guide the Information Security Engineering staff while providing operational oversight
  • Maintain security standards across multiple security domains
  • Collaborate with Identity and Access Management to enhance security controls like role-based access
  • Act as the technical leader for AI security architecture, ensuring compliance and risk management practices
  • Document and maintain security standards, procedures, and operational playbooks for security platforms
  • Support audit and regulatory activities by providing technical evidence and remediating findings.

Benefits

  • Opportunity to work with cutting-edge security technologies
  • Leadership role allowing for influence over security strategy and team development
  • Collaborative work environment across various business units
  • Exposure to AI security frameworks and emerging technologies
  • Engagement in compliance and risk assessment processes with operational significance.
Full Job Description
Officer: VP

Division: Technology

Department: Information Security

Reports to: Chief Security Officer

Status: Exempt/ Officer

Grade: 13

Salary Range: $96,089 - $177,069

Actual compensation within the pay range will be determined based on factors including, but not limited to, skills, prior relevant experience, and specific work location.

Location: MA, CT, NY, VT, RI

Principal Objective

Supports the Company's Information Security Program by engineering, architecting, maintaining, and improving security technologies, identity and access controls, monitoring capabilities, and defensive security processes. The Principal Information Security Engineer partners with Information Technology, Identity and Access Management, Risk, Compliance, application owners, business units, and third-party service providers to protect Company systems, data, customers, and employees.

Key Accountabilities:
  • Administer, maintain, and enhance enterprise information security technologies, including endpoint security, email security, data loss prevention, application security, network security, identity protection, cloud security, logging, monitoring, and security related platforms. Lead the design, implementation, and continuous improvement of enterprise security architecture and engineering programs.
  • Lead and develop Information Security Engineering staff while serving as the senior technical contributor, providing operational oversight, and strategic direction.
  • Maintain security standards across cloud, network, endpoints, identity, application, and data security domains.
  • Partner with Identity and Access Management to improve access control, privileged access management, authentication, conditional access, role-based access, and user lifecycle security controls.
  • Serve as the Company's technical leader for AI security architecture and AI risk management. Assists in designing security frameworks and technical guardrails for Generative AI, Machine Learning, Agentic AI, and emerging AI technologies. Assists with evaluating security risks associated with AI platforms, agents, models, APIs, third-party AI vendors, and cloud AI services. Assists with developing controls for data protection, AI monitoring, identity management, and secure AI deployment.
  • Develop and maintain security standards, procedures, runbooks, technical documentation, diagrams, control evidence, and operational playbooks for assigned security platforms and processes.
  • Assist with security assessments for new systems, technology changes, vendor solutions, mergers, integrations, branch initiatives, and enterprise projects to ensure appropriate security requirements are identified and implemented.
  • Support audit, regulatory, risk assessment, and compliance activities by providing evidence, explaining technical controls, remediating findings, and maintaining documentation that demonstrates control effectiveness.
  • Identify opportunities to automate security operations, improve alert quality, reduce manual processes, strengthen detection capabilities, and mature the Company's overall security posture.
  • Requires a high degree of collaboration with IT Operations, Infrastructure, Service Desk, Application Support, Risk Management, Internal Audit, Compliance, and business stakeholders to resolve security issues and support secure business operations.
  • Participate in security incident response, change management, disaster recovery, business continuity, and other operational activities as required.
  • Ensure compliance with all banking laws, rules, regulations, and prescribed policies/practices/procedures necessary to reduce risk and uphold ethical standards related to and required by one's duties.


Education:
  • Bachelor's degree in Information Security, Computer Science, Information Technology, Cybersecurity, or related field preferred.
  • Equivalent combination of education, technical certifications, and relevant experience may be considered.
  • Security certifications such as CISSP, CISM, CCSP, GIAC, Security+, Microsoft Security certifications, or related credentials preferred.


Experience:
  • 7+ years of experience in information security, cybersecurity engineering, security operations, infrastructure security, identity security, or related technology roles.
  • 3+ years of experience supporting security technologies in a regulated financial institution, banking environment, or similarly regulated industry preferred.
  • Experience with Microsoft Entra ID, Active Directory, privileged access management, email security tools, endpoint security tools, cloud security, network security, data security, security automation, SIEM/logging.
  • Experience securing AI, Generative AI, Machine Learning, Agentic AI, or similar AI ecosystems. Experience implementing security controls for AI systems, including data loss prevention (DLP), access controls, encryption, prompt security, model protection, vendor security reviews, and monitoring for AI-related threats and misuse.


Skills & Knowledge:

  • Strong understanding of information security principles, defense-in-depth, identity and access management, incident response, secure configuration, and security monitoring.
  • Working knowledge of banking security expectations, risk management practices, audit evidence requirements, and regulatory frameworks such as FFIEC, GLBA, NIST Cybersecurity Framework, and related industry guidance.
  • Strong technical troubleshooting skills with the ability to analyze security events, system behavior, logs, vulnerabilities, and control exceptions.
  • Ability to translate technical security issues into clear business risk language for IT, business, risk, audit, and executive stakeholders.
  • Strong written and verbal communication skills, including the ability to develop standards, procedures, summaries, diagrams, and control evidence.
  • Strong organizational skills with the ability to manage multiple priorities, document work clearly, meet deadlines, and drive issues to resolution.
  • High degree of professionalism, discretion, integrity, and sound judgment when handling sensitive information and security incidents.
  • Proficient in Microsoft Office Suite and collaboration platforms.


Similar Jobs

More Jobs at Beacon Bank

More Information Technology Jobs

Find similar Principal Information Security Engineer jobs: