SonicJobs Logo
Left arrow iconBack to search

Information Security Engineering Manager

EagleBank
Posted 2 days ago, valid for 10 days
Location

Silver Spring, MD, US

Salary

$141,076 - $241,844 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • EagleBank is seeking an Information Security Manager with a minimum of 10 years of experience in information security operations, engineering, or administration, and 4 years of experience leading a technical team.
  • The role involves monitoring and maintaining security engineering controls, leading a team of five Information Security Engineers, and ensuring the confidentiality and integrity of the bank's information systems.
  • Candidates should have expertise in Microsoft network security, security tools, and scripting languages, along with relevant certifications such as CISSP or CEH.
  • The projected annual salary for this position ranges from $141,076 to $241,844, with additional compensation possible based on experience and skills.
  • EagleBank values inclusion, employee growth, and wellbeing, offering various benefits including 100% 401(k) matching and wellness discounts.

Overview

We are a values driven organization putting Relationships FIRST. EagleBank (NASDAQ – EGBN) is focused on being Flexible, Involved, Responsive, Strong, and Trusted. By prioritizing meaningful connections with our customers, employees, and shareholders, we relentlessly deliver the most compelling, valuable service to our customers.EagleBank is committed to inclusion, equity, and respect. We celebrate diversity and intentionally seek out opportunities to learn from one another’s experience. We believe employees are essential to the building of relationships and we prioritize investing in employee growth and wellbeing. Employee involvement is fostered through resource groups, mentorship programs, community service, and scholarship opportunities for continued education. With features including maternity and parental leaves, wellness discounts, healthcare premium sharing, employer funding in your HSA account, and 100% 401(k) matching up to 4%, we pride ourselves in the ways we support our internal relationships. The minimum and maximum projected annualized salary for this position is: $141,076.00 to $241,844.00. Additional compensation may be possible based on experience and skills.

Responsibilities

The Information Security Manager is responsible for monitoring, analyzing and maintaining EagleBank's technical security engineering controls in support of EagleBank's Information Security Program. This role will be focused on security engineering of the EagleBank applications and network which includes creation and timely execution of project plans, tool installations, assisting with upgrades of EagleBank's technology environments and ensuring that appropriate external feeds and threat intelligence are integrated into the operational tools. The role executes controls to maintain the confidentiality, integrity and availability of EagleBank's information systems and infrastructure and supports the bank's operational goals.

 

 

Major duties and responsibilities:

  • Lead a team of five (5) Information Security Engineers.
  • Independently identify and propose remediations for risks related to Bank IT infrastructure.
  • Support information security projects and lead engineers, vendors, and consultants.
  • Review, analyze, and update network security tool configuration and architecture, and document, troubleshoot, and remediate issues.
  • In collaboration with the CISO, identify opportunities to mature information security engineering capabilities and processes, executing some and assigning tasks to others for execution.
  • Interfaces directly with senior members of IT Operations team to address cross-cutting issues and events.
  • Acts as backup Incident Response lead for Information Security team.
  • Work with managed service providers, network administrators, and Security Operations to resolve problems, evaluate new solutions, recommend changes, and investigate incidents.
  • Analyze reports, identify, and distribute action items or service tickets to support teams or vendors to address InfoSec engineering issues.
  • Document and submit Change Management requests on behalf of the InfoSec engineering team and present changes to Change Advisory Board when appropriate.
  • Sets weekly tasks and runs regular security engineering team meetings and one on one is with direct reports. Responsible for performance, setting annual goals including employee development and training.
  • Manage and distribute the triage and analysis of security events escalated from the Tier-2 support teams.
  • Act as Backup to the CISO.

Qualifications

Requirements:

  • Bachelor’s Degree in Arts/Sciences (BA/BS) in Computer Science or Information Systems, Information Technology or related focused technical training or in lieu 4 additional years of engineering and project management experience
  • 10 years experience in a combination of information security operations/engineering/administration with emphasis on deploying security tools and capabilities
  • 8 years experience configuring and implementing information security technologies
  • 8 years experience working in Microsoft network security environment with knowledge of Active Directory, Intune, Azure AD and Azure Sentinel, O365 / Security Center
  • 4 years experience leading a team of technical professionals
  • One or more of the following certifications (or equivalent): − CASP (CompTIA Advanced Security Practitioner) or ISC2 CISSP − EC-Council Certified Ethical Hacker (CEH) − AZ-500 Microsoft Azure Security Engineer Associate
  • Expert knowledge of security tools used for vulnerability management (Tenable Nessus, Qualys, Nexpose), privileged access management (CyberArk), Security Event Incident Management (Microsoft Sentinel), Microsoft Endpoint Security (EDR)
  • Expert knowledge of scripting languag(es) such as PowerShell, KQL
  • Expert knowledge of Microsoft Defender for Cloud
  • Expert knowledge of Active Directory (AD)
  • Expert knowledge of TCP/IP networking: networking topology, protocols and services
  • Expert knowledge of Palo Alto firewalls, Panorama and firewall operations
  • Experience with operations and optimization of Secure Web Gateway (preferably Netskope)
  • Experience with Email Security tooling (Proofpoint, Purview) and optimization
  • Experience leading tool, application, and system security assessments / evaluations
  • Experience with security elements of Intune, Conditional Access Policy implementations
  • Experience with security engineering of Linux servers
  • Strong Active Directory and Windows Group Policy (GPO) knowledge
  • Experience leading security collaboration with operations teams responsible for networking technology and protocols, including routers, switches, VPNs, email gateways

Preferences:

  • 4 years experience with AD tools for inventory, analysis and report on Active Directory structure, objects, permissions, etc
  • 4 years experience with malware analysis using sandboxes
  • 4 years security engineering/administration in the financial sector
  • One or more of the following certifications (or equivalent): − CCNA − EC-Council Certified Security Analyst (ECSA) − SC-100 Microsoft Cybersecurity Architect − ISC2 System Security Certified Practitioner (SSCP) − ISACA certifications (CRISC) − GSE GIAC Security Expert − GIAC Certifications such as GPPA, GCHI, GPEN − GSAE (GIAC Security Audit Essentials) − GWAPT (GIAC Certified Web Application Penetration Tester)
  • Experience with network auditing tools such as StealthBits, Varonis
  • Experience leading engineering support for escalations, investigations, and incident response

Don't meet all the requirements? We encourage you to still apply if you think you are the right person to join our community. We are always interested connecting with people inspired by our mission and values. If you aren't hired for this position, your resume will remain available for the next year and might be considered for future openings. Note: You can update your resume as often as needed.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.