First Citizens Bank logo
First Citizens Bank

This job posting is expected to remain active for 31 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.

Principal Cyber Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 10,001+H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

13 days ago

Salary

0

Seniority

Lead

Job Description

Principal Cyber Security Engineer

First Citizens Bank

Role Description This is a remote position that can be hired in NC, AZ, VA, NJ, and TX. This person should possess strong analytical and technical problem-solving skills as well as experience in the different phases of the system life cycle, to support multiple projects, develop standard operating procedures, and perform day-to-day functional administration and support for Privileged Access Management (PAM). The engineer should have in-depth experience in the management of passwords/credentials (such as default accounts, service accounts, keys, etc.) in PAM solutions. - Support the deployment and integration of privileged account security solutions. - Ability to discuss technical concepts and interdependencies with customers. - Experience gathering high-level functional and operational requirements. - Experience developing and managing multiple system designs concurrently. - Provide operation and maintenance of existing PAM solutions. - Develop design documentation, standard operating procedures (SOPs), and implementation/deployment plans for privileged account security solutions and identity governance solutions. - Provide after-hours and on-call production support when required. - Develop diagrams and documentation to support infrastructure configuration changes. - Provide security tool enhancements and performance tuning to increase capability to support new requirements. - Plan, test, and deploy firmware, software upgrades, and security fixes. Qualifications - Bachelor's Degree and 8 years of experience in Systems Engineering, Network, or Information Security OR High School Diploma or GED and 12 years of experience in Systems Engineering, Network, or Information Security. Requirements - Experience supporting PAM solutions (CyberArk, HashiCorp, Delinea, etc.) in an enterprise environment. - Hands-on PowerShell/Python or similar scripting experience. - Ability to proficiently utilize SailPoint identity management system is a plus. - Proficiency with MS Visio, PowerPoint, Word, and Excel. - Background in information security systems with specific knowledge around access control. - Background in role-based access control for privileged access. - Hands-on Windows 2019 or later Server administration experience. - Hands-on Active Directory and LDAP query experience. - Functional understanding of TCP/IP networks and firewalls. - Functional understanding of the following protocols: TCP, UDP, DNS, NetBIOS, HTTP, HTTPS, SMTP, SNMP, SSH, SSL. - Strong UNIX/Linux system administration experience. Benefits Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits .

Related Categories

Related Job Pages

More Security Engineer Jobs

Okta logo

Staff Product Security Engineer

Okta

Founded in 2009, Okta is a publicly-traded software company headquartered in San Francisco, California. Described as the leading independent provider of identit

Role Description As a Staff Product Security Engineer, you will play a critical role in safeguarding Okta’s products by: - Conducting comprehensive security reviews. - Guiding engineering teams in secure development practices. - Handling externally reported vulnerabilities. - Engaging in code reviews, penetration testing, and architectural security assessments. This role is not suited for individuals who rely solely on automated vulnerability scanning. Instead, you must possess a deep technical understanding of: - Web applications. - Backend services. - Penetration testing methodologies. - Secure design principles. A successful candidate will have: - Expertise in authentication protocols (SAML, OAuth, OIDC). - Threat modeling experience. - A strong desire to automate security processes by building tools that proactively identify vulnerabilities. - Ability to communicate risks, impact, and remediation strategies to developers, leadership, and external audiences. - A deep technical background in assessing AI-integrated software architectures and securing Large Language Models (LLMs). - An attacker mindset—thinking critically, creatively, and like an adversary when solving security challenges. We actively support public disclosure of research and findings through white papers, blog posts, and conference presentations. Qualifications - Expertise in identifying OWASP Top 10 / CWE Top 25 vulnerabilities through manual code review. - Strong experience in penetration testing and secure development practices. - Deep technical background in assessing Large Language Models (LLMs) and securing AI-integrated software architectures. - Proficiency in multiple programming languages (e.g., Java, Go, Python, C/C++). - Deep understanding of authentication & authorization protocols (OIDC, SAML, OAuth). - Strong communication skills to explain risks and remediation to developers and leadership. - Ability to automate security testing using LLMs and scripting (Python, Bash, etc.). - Experience leading security incidents and risk assessments. Requirements - Experience in mobile (iOS/Android) and desktop (Windows/macOS) security testing. - Familiarity with SAST, DAST, SCA, and fuzzing tools. - Strong cryptographic knowledge and secure implementation practices. - Experience analyzing network protocols and traffic security. - Ability to develop proof-of-concept exploits to demonstrate vulnerabilities. Benefits - Annual base salary range for this position for candidates located in Spain is between €74.000 and €101.000 EUR. - Equity (where applicable) and bonus. - Comprehensive healthcare coverage and financial benefits including paid time off and parental leave.

Spain
€74K - €101K / year

Federal Cyber Security Analyst

Rhymetec

Rhymetec is a cybersecurity company that partners with businesses to protect, detect, and respond to evolving cyber threats, guided by its mission to provide security that enables

Full TimeRemoteTeam 33Since 2015

Title: Federal Cyber Security Analyst Location: Remote (U.S., New York Preferred) About Rhymetec: Rhymetec was founded in New York City in 2015, growing steadily in the areas of compliance, cyber security and data privacy. Our mission is to ensure our clients are compliant faster, so they can focus on their core business and less on the complexities of building effective and compliant infosec programs. This role is fully remote. Job Description: The Federal Cyber Security Analyst (FCSA) will be responsible for architecting, developing, and implementing solutions that help Rhymetec's clients achieve, manage and measure security metrics and compliance requirements. The role will work closely with their team to help design and deliver security and compliance objectives and have the ability to help drive foundational changes in internal cloud platforms to enhance their security posture. The ideal candidate will have a team first mentality and fit within the core values and culture at Rhymetec, along with project management experience and knowledge with customized compliance road maps for clients. This person will be responsive to both customers and team members with communications, be detail oriented, and hold a high level of autonomy to complete work on time and with quality. Responsibilities: - Prepare agendas and reference documents for meetings with clients. - Assist in building and managing cyber security programs for Rhymetec’s customers based on industry standard cyber security compliance frameworks. - Conduct meetings with clients regularly. - Configure performance monitoring alarms, security alarms, IDS/IPS in AWS, Azure, GCP, Datadog and other cloud infrastructures. - Set up supporting security applications. - Set up mobile device management applications such as Jamf, Jumpcloud, Microsoft Endpoint manager, Hexnode, etc. - Configure and maintain compliance monitoring platforms. - Conduct internal audits, risk assessments, and generate reports. - Conduct Incident Response Tabletop exercises with clients. - Conduct Business Continuity and Disaster recovery tabletop exercises with clients - Document and lead incident response process should an incident arise. - Translate CMMC, FedRAMP, GovRAMP, TX-RAMP (preferred) controls into actionable items for clients. - Conduct employee access reviews, SaaS vendor security assessments, and gap assessments. - Triage bug/vulnerability reports from security researchers. - Complete security questionnaires on behalf of clients. - Draft supporting documents for clients’ information security management systems and information security policies. - Gather and maintain evidence of compliance for various frameworks. - Lead engagements with auditors on behalf of clients. - Communicate tasks to clients’ employees and educate clients on security best practices. Qualifications: - Bachelor's Degree from an accredited university in a Technology or Cybersecurity field OR 4+ years of direct experience in listed areas. - 3+ years of work experience working with cybersecurity and regulatory compliance. - Experience in customer service and ability to develop professional relationships with customers. - Extensive knowledge of compliance, regulatory frameworks, and implementing CMMC, FedRAMP, GovRAMP, TX-RAMP, and other various federal frameworks. - Strong logical security skills, with experience in cloud security. - Understanding of cloud environments (AWS, GCP, Azure) and integrating security controls through DevOps and Infrastructure as a Service (IaaS) techniques. - Certifications are preferred. - Quarterly travel may be required. Benefits Rhymetec offers a robust employee package, including: - Employee covered medical premiums (100%) - Dental and Vision Benefits - PTO and Sick Time, including 11 paid Holidays - 401K retirement plans with company match options - Company paid Life Insurance - Annual Subscription to TalkSpace (online counseling & therapy service) - Summer Fridays! Rhymetec is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetic, disability, age, or veteran status.

New York
GE Aerospace logo

Director – Offensive Security

GE Aerospace

GE Aerospace is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law. GE Aerospace will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable).

Full TimeRemoteTeam 10,001+H1B No Sponsor

• This role leads a team that delivers traditional web application penetration testing, Defense-in-Depth assessments extending beyond the web layer, and Red Team engagements • Shape an automation-first and intelligence-driven offensive security program • Ensure offensive security services evolve from point-in-time testing toward a continuous assurance model • Hire, lead, coach, and retain an expert team; establish goals, role clarity, performance expectations, and development plans • Define and execute the offensive security strategy • Own end-to-end engagement delivery for web application penetration testing, Defense-in-Depth assessments, and Red Team operations • Manage vendor relationships supporting Red Team activities • Partner with vulnerability management, product security, engineering, and infrastructure teams to ensure findings are actionable, prioritized, tracked, and re-tested as appropriate • Define and maintain assessment methodologies, reporting standards, and measurable KPIs

United States
$152K - $220K / year
Sowelo Consulting sp. z o.o. sp. k. logo

Security Engineer

Sowelo Consulting sp. z o.o. sp. k.

IT Recruitment | RPO | Executive Search | Headhunting | On Time, On Target, On Budget

ContractRemoteTeam 11-50H1B No Sponsor

• Lead the deployment and configuration of BeyondTrust Endpoint Privilege Management (EPM) across the organization • Design, implement, and fine‑tune EPM policies, rules, and configurations for different user groups and environments • Work with Security / IAM / IT to plan and execute a phased rollout with early adopters, business teams, and then engineering • Collaborate with internal stakeholders to gather feedback on the rollout and adjust policies and settings accordingly • Create and maintain documentation which includes configuration guides, runbooks, deployment procedures, and best practices • Contribute to testing and validation of EPM policies to minimise user disruption while maintaining strong security controls • Identify opportunities to automate deployment, configuration, and ongoing management (e.g. via scripting in PowerShell, Bash, Python, etc.) • Monitor progress against agreed project timelines and milestones, escalating risks or blockers when needed • Work closely with the wider Identity & Access Management team to align EPM configuration with existing IAM standards and processes • Provide knowledge sharing and basic enablement to internal teams on how to work effectively with the new EPM solution

Poland