Build credit. Build savings. Build dreams.
Principal Information Security Engineer
Location
United States
Posted
46 days ago
Salary
$180K - $210K / year
Seniority
Lead
Job Description
Principal Information Security Engineer
Self Financial, Inc.
Self Financial is a venture-backed, high-growth FinTech company with a mission to increase economic inclusion and financial resilience by empowering people to build credit and build savings. We're looking for people who share our passion and are driven to tackle challenges, find solutions and make the financial space better for the communities we serve. Our team is passionate about challenging the status quo of the credit industry by providing people accessible tools to take control of their credit. Executing on our mission requires deep collaboration across our teams to ensure our products reach the people who can benefit from them the most, particularly the 100 million+ Americans who have no or low credit. We celebrate diversity and are committed to creating an inclusive environment for all employees. To that end, we seek to recruit, develop and retain the most talented people from a diverse candidate pool. Role Summary The Principal Information Security Engineer is responsible for owning cybersecurity operations and defense across all Self products and infrastructure. This role plays a critical part in protecting customer data, ensuring compliance with SOC 2 and PCI requirements, and partnering closely with engineering and IT teams to detect, investigate, and respond to security threats. The ideal candidate brings deep expertise in security operations, threat detection, and incident response with hands-on experience in tools like Splunk Enterprise, CrowdStrike, Wiz, and Netskope. What You Will Do - Own end-to-end cybersecurity operations, including threat detection, incident response, and vulnerability management across all Self products and infrastructure - Build, tune, and maintain detection content in Splunk Enterprise (SIEM) to identify threats, anomalies, and policy violations - Operate and optimize CrowdStrike for endpoint detection and response (EDR), including alert triage, threat hunting, and containment - Manage cloud security posture using Wiz, including misconfiguration identification, risk prioritization, and remediation tracking - Administer and optimize Netskope for CASB and secure web gateway (SWG) functions, including DLP policy enforcement, shadow IT visibility, and web threat protection - Design, manage, and optimize Next-Generation Firewalls (NGFW) and cloud native networking to enforce zero-trust principles and secure perimeter defenses. - Lead incident response efforts - from detection through containment, eradication, and post-incident review - Conduct proactive threat hunting across endpoint, network, and cloud environments - Partner with engineering and infrastructure teams to remediate critical security findings and reduce attack surface - Lead and perform third-party vendor security reviews and risk assessments - Support SOC 2 and PCI compliance efforts, including audit preparation and evidence collection - Identify security risks across the environment and recommend mitigation strategies - Monitor emerging cybersecurity threats and translate them into actionable detection and prevention controls Who You Are - 12+ years of experience in cybersecurity, security operations, or information security engineering - Hands-on experience with Splunk Enterprise for SIEM, log management, and detection engineering - Proficiency with CrowdStrike for endpoint detection, response, and threat hunting - Experience using Wiz or similar CSPM tools for cloud security visibility and risk remediation - Hands-on experience with Netskope or similar CASB/SSE platforms for data loss prevention, shadow IT, and secure web access - Strong background in incident response, including investigation, containment, and root cause analysis - Experience with vulnerability management programs and remediation workflows - Solid understanding of network security, cloud security (AWS/GCP/Azure), and identity and access management - Experience supporting or operating within SOC 2 and PCI compliance environments - Ability to partner effectively with engineering and infrastructure teams to drive security outcomes - Strong risk assessment, prioritization, and communication skills Preferred Qualifications - Experience performing third-party vendor security assessments - Familiarity with cloud-native architectures and container security - Prior experience in fintech, regulated industries, or environments handling sensitive customer data - Experience with threat intelligence platforms and integrating feeds into detection workflows - Security certifications such as CISSP, CISM, GCIA, GCIH, GCED, or equivalent experience Base salary range: $ 180,000-210,000 annually. Individual pay is based on factors unique to each candidate, including skill set, experience, and other job-related reasons. Benefits and Perks: We have the compensation and benefits you expect. But there's one thing that Self Financial can offer that many companies cannot: we can positively change the world, while making a profit. We are a team of Builders, empowering our customers to build their dreams. We have a Do the Right Thing ethos in all that we do, and we hope you value that approach, too. Our perks include: - Company equity in the form of Stock Options - Performance-based bonuses - Generous employer-paid health, vision and dental insurance coverage - Flexible vacation policy - Educational assistance - Free gym membership - Casual dress code - Team building events and activities - Remote work arrangements/ flexible work schedule - Paid parental leave Self Financial requires all employees hired to successfully pass a background check. We are an Equal Opportunity Employer. At this time, we are only able to consider applicants who are U.S. Citizens or Green Card Holders for employment opportunities. We appreciate your understanding.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Facilities Technician - Pickerington
Huntington National BankSine 1866, Huntington National Bank has served midwestern communities with banking and financial services for consumers and businesses of all sizes. The regiona
Description This position is considered remote; however, you must be located in the southern Columbus/Pickerington area. You will be responsible for 20-30 Huntington Bank branch locations. Summary: The Facilities Technician manages retail & corporate bank properties in various counties. They are an emergency responder - on call and overtime is mandatory based on business need. Primary focus is to self-perform 40-60% of maintenance work. Duties & Responsibilities: - Project planning, budgeting and all aspects of maintenance, construction, relocation, and remodeling. - Supply own basic tools including hammer, wrenches, screwdrivers, pliers, saws. Power tools will be supplied if needed. - Develops work processes for vendors and contractors. - Communicates with internal customers/natural owners. - Computer proficiency, general maintenance skills and HVAC knowledge required. - Operate Facilities Management work order system - Participate in staff and departmental meetings - Complete required in-person & on-line training sessions - Visit every assigned property quarterly - Complete annual site assessments and record in work order software program - Provide support to Functional Coordinator, Facilities Manager II & Regional Facility Manager - Primary focus will be to self -perform 40-60% of non-contracted services - Verify Vendor performance and pricing - Interim HVAC filter changes - Lighting repairs - Plumbing repairs - Electrical repairs - Exterior repairs - Interior repairs - Non Specific task - Other duties as assigned This position is considered remote; however, you must be located in the southern Columbus/Pickerington area. You will be responsible for 20-30 Huntington Bank branch locations. Basic Qualifications: - High School Diploma or equivalent - Valid Driver's License. Huntington will provide a company vehicle to use for work purposes - 3+ years Facilities Management experience to include basic preventative maintenance of multiple facilities, minor repairs involving plumbing, heating/cooling, basic electrical repairs and furniture moves, and the coordination and scheduling of maintenance with various vendors - Prior experience with creating and maintaining a budget for facility repairs & vendor proposal reviews Preferred Qualifications: - Trade Certifications preferred - Computer Proficiency to include MS Outlook, Word, and Excel. - Experience with Facilities Management software - Knowledge and skills related to building Maintenance incl. HVAC - Ability to lift loads of up to 50 pounds. - Excellent written and verbal communication skills - Good project management skills including budgeting and documentation - Time Management - Leadership: Organizes work flow for designated group and/or projects: reviews the work of others, sets team goals - Quality Assurance: Adheres to bank policies and procedures and complies with legal and regulatory requirements. Follows, or in some cases establishes, as required, effective controls and processes to ensure risks are measured, monitored and controlled and compliance requirements are adhered to on an on-going basis. Keep abreast of risk-related changes that may impact assigned work functions and processes. - Qualified individual must be self-motivated requiring minimal supervision and possess a desire to promote "Best in Class" service through their actions. Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay) No Workplace Type: Remote Our Approach to Office Workplace Type Certain positions outside our branch network may be eligible for a flexible work arrangement. We’re combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team. Huntington will not sponsor applicants for this position for immigration benefits, including but not limited to assisting with obtaining work permission for F-1 students, H-1B professionals, O-1 workers, TN workers, E-3 workers, among other immigration statuses. Applicants must be currently authorized to work in the United States on a full-time basis. Huntington is an Equal Opportunity Employer. Tobacco-Free Hiring Practice: Visit Huntington's Career Web Site for more details. Note to Agency Recruiters: Huntington will not pay a fee for any placement resulting from the receipt of an unsolicited resume. All unsolicited resumes sent to any Huntington colleagues, directly or indirectly, will be considered Huntington property. Recruiting agencies must have a valid, written and fully executed Master Service Agreement and Statement of Work for consideration.
Senior CyberSecurity Engineer
HumanaLouisville, Kentucky-based Humana is a leading healthcare company that offers a variety of health, wellness, and insurance products and services designed to off
• Design, implement, and maintain PAM solutions, including vaulting, credential rotation, session management, and privileged access workflows. • Drive hands-on remediation of high-risk privileged access to ensure principle of least privilege is adhered to and comprehensive controls safeguard existing privileged entitlements. • Implement and enhance privileged access controls across Windows, Linux/AIX, MacOS, Active Directory/Azure AD, cloud platforms, and databases. • Partner with application, infrastructure, and cloud engineering teams to ensure privileged access is correctly inventoried, vaulted, rotated, and governed. • Support onboarding of applications and services into PAM solutions, including privilege mapping, configuration, and testing. • Collaborate with the Associate Director on roadmap execution, technical design decisions, and delivery of program initiatives. • Provide technical input into PAM posture reporting, risk remediation efforts, and audit/compliance responses. • Develop and maintain technical documentation, standards, runbooks, and operational procedures for PAM services. • Participate in incident response, troubleshooting, and root-cause analysis for PAM-related issues. • Support on-call responsibilities and escalation handling for privileged access services as required. • Stay current on emerging PAM technologies, threats, and best practices to continuously improve PAM capabilities.
• Lead planning, execution, and delivery of complex, cross‑functional cybersecurity and technology risk projects aligned to enterprise priorities that have enterprise‑wide impact, heightened regulatory scrutiny, and elevated risk posture. • Partner with business and technology leaders to shape strategy, define scope and objectives, influence delivery approach, and ensure alignment across stakeholders. • Facilitate and lead cross‑functional working groups to remove barriers, mitigate risk, and ensure accountability • Develop project plans, schedules, RACI matrices, risk/issue logs, and status reporting. • Ensure project execution follows enterprise lifecycle, cyber governance, and regulatory requirements (OCC, GLBA, NIST).
• ensures the generation of demand and selling Security Managed Services solutions • guides on addressing the objections that a client may pose in moving to a managed services solution • guides on allocating and deciding sales time between assigned clients and new prospect opportunities • ensures focus remains on the top clients/prospects and balance opportunity size with likely outcomes • works cross functionally with partners and/ or vendors to drive select deals through vendor-based opportunities • advises on regional sales governance processes and deal Clinics to profile opportunities • guides on building deep and long-term relationships with client leaders in a Managed Services opportunity • owns the maintenance of a high level of relevant service knowledge to have meaningful conversations with clients • develops the knowledge base of company's services solutions within a services practice by sharing best practices with internal teams as well as client teams • drives the sales process by managing a pipeline of opportunities and creating and documenting a shared strategy to meet sales targets • advises on the negotiation of deals with clients and lead the internal account management team to enable conclusion of services deals • leads on regional reporting cadence as it relates to regional performance and major deal reviews




