DescriptionJob Description
Sr. IT Security Engineer
Location: Boise, Idaho
Travel: 10% or less
Summary:
The Sr. IT Security Engineer is an internal security engineering role supporting business stakeholders and IT technical teams in developing, maintaining, and operating secure, compliant line-of-business systems and processes across Savers. This position plays a dual role-providing deep technical security expertise while ensuring alignment with enterprise risk management, governance, and compliance frameworks. This is a hands-on and analytical role requiring broad knowledge across multiple security disciplines, including Cloud Security, Application Security, Security Engineering, Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Security Risk and Compliance.
Successful candidates will have a demonstrable record of applying security principles, controls, and frameworks (NIST, ISO 27001, CIS, SOC 2, PCI) in planning, implementation, maintenance, and monitoring of security technologies and practices, while creating policies and documentation to uphold frameworks. The role reports to the Director of IT Security and contributes directly to Savers' risk-based approach to sustainable security.
Essential Job Functions:
- Collaborate with cross-functional teams to drive internal security, privacy, and risk governance initiatives across the enterprise.
- Creating and maintain Enterprise Policies, Standards, and Guideline documentation to support alignment of Industry Frameworks
- Serve as a trusted security and risk advisor to stakeholders, offering actionable guidance that balances technical controls with business priorities.
- Provide continuous security and compliance guidance for internal projects, technology evaluations, and daily operational issues.
- Conduct detailed security and risk assessments of business applications, cloud workloads, and critical processes to identify control gaps, residual risks, and mitigation plans.
- Communicate security risks, vulnerabilities, and recommended treatments to both technical and non-technical teams, ensuring clear risk awareness and accountability.
- Partner with Solutions Delivery and Engineering teams to embed secure-by-design principles, risk controls, and governance checkpoints throughout the SDLC.
- Participate in project teams and initiatives as a dedicated Security Advisor and risk representative from planning through operationalization.
- Monitor and analyze emerging threats, regulatory changes, and vendor advisories, and assess their relevance to Savers' risk posture.
- Establish and manage risk and threat metrics, control scorecards, and compliance health monitoring to measure and communicate program effectiveness to varying levels of leadership.
- Collaborate closely with IT, Audit, Legal, and Business teams to ensure consistent governance, risk, and compliance alignment across the organization.
- Maintain deep industry expertise and contribute to policy updates, control documentation, and audit readiness activities.
Required Knowledge, Skills and Abilities:- Strong experience ensuring security, privacy, and risk governance for Internet-facing systems, SaaS applications, and cloud services.
- Comprehensive understanding of Internet security issues, risk assessment methodologies, and mitigation strategies.
- Experience with security tooling, automation, and control monitoring to improve visibility and reduce operational risk.
- Technical expertise in security engineering, network and system security, authentication protocols, cryptography, and application security testing.
- Practical experience in threat modeling, risk analysis, and control validation.
- Knowledge of security vulnerabilities, risk treatment plans, and compensating control strategies.
- Familiarity with security frameworks, standards, and protocols relevant to enterprise governance (e.g., NIST, ISO 27001, SOC 2, PCI DSS).
- Excellent written and verbal communication skills, with the ability to translate technical findings into risk-based business context.
- Analytical, resourceful, and organized, with a proactive approach to identifying and mitigating potential security risks.
- Strong collaboration skills with a willingness to provide clear, actionable feedback in complex or sensitive governance discussions.
- Proficiency with one or more interpreted programming or scripting languages (Python, JavaScript, Ruby, PowerShell, etc.) to support security automation and compliance evidence collection.
Minimum Required Education, Training and Experience:
- 8+ years' experience in information security.
- Industry certifications such as CISSP, CCSP, CISM and CRISC preferred
- B.S. or M.S. in computer science or related field or equivalent professional experience
Physical Requirements:
- Ability to lift and carry up to 30 lbs.
- Ability to express or exchange ideas by means of the spoken word.
- Ability to receive detailed information through verbal communication, and to make the discriminations in sound.
- Ability to receive detailed information visually through written communication (both physical and electronic).
FLSA Status
Tools and Equipment Used:
- Laptop or desktop computer, phone, copy machine, etc.
Travel:
Work Address:
Page 1 of 2
This job description is not intended to be all-inclusive. Employee may perform other related duties as assigned to meet the ongoing needs of the organization.