Security Engineer
Sierra Central Credit UnionUSA5d ago
SecurityEngineeringremotecurated-jd
Job description
Security Engineer at Sierra Central Credit Union.
About the role
Sierra Central Credit Union is seeking a professional to manage and improve our cybersecurity infrastructure and operational controls. You will work with internal teams and external partners to protect our information systems while ensuring we meet financial industry regulatory standards.
Key facts
What you'll do
- Administer Microsoft 365 E5 security tools including Defender XDR, Entra ID, Intune, Purview, and Defender for Cloud Apps.
- Secure cloud collaboration platforms such as SharePoint, OneDrive, and Teams using data loss prevention and sensitivity labels.
- Manage email security protocols including SPF, DKIM, DMARC, and anti-phishing gateways.
- Lead phishing simulation exercises and security awareness training.
- Investigate security incidents and coordinate with managed detection and response providers.
- Conduct vulnerability assessments, asset scanning, and penetration testing support.
- Assist with regulatory audits, third-party risk reviews, and GLBA compliance documentation.
- Monitor network and endpoint activity to identify and remediate security threats.
Requirements
- Bachelor degree in Cybersecurity, Computer Science, Information Systems, or equivalent experience.
- Minimum of 4 years of hands-on cybersecurity engineering experience in a Microsoft-centric environment.
- Expertise in Microsoft 365 security, incident response, and email security administration.
- Experience supporting risk management or compliance initiatives within a regulated sector.
- Ability to analyze security logs, endpoint telemetry, and forensic evidence.
- Proficiency with firewall, VPN, and network security technologies.
- Strong communication skills for explaining technical security concepts to diverse audiences.
Nice to have
- Experience in the credit union, banking, or financial services industry.
- Familiarity with NCUA, FFIEC, GLBA, and CCPA/CPRA regulations.
- Professional certifications such as CISSP, CISM, GIAC, or Microsoft SC-100, SC-200, SC-400.
- Background in SIEM engineering, security automation, or EDR solutions.
- Experience mentoring junior staff or IT professionals.
Skills & tools
- Microsoft 365 E5, Defender XDR, Entra ID, Intune, Purview, Defender for Cloud Apps
- SharePoint, OneDrive, Teams
- Email security (SPF, DKIM, DMARC)
- Vulnerability management
- Incident response and threat triage
- Network security (Firewalls, VPN)
Practical notes
- Benefits include medical, dental, and vision insurance, company-paid life insurance, long-term disability, and a 401(k) plan with a 3% safe harbor contribution.
- Employees receive 11 paid holidays, vacation time, and 12 sick days per year.
- This role requires working on-site at our corporate headquarters in Yuba City.
- Physical requirements include sitting for 7 to 8 hours daily and occasional lifting of up to 25 lbs.