Senior Information Security Engineer
Senior
Ai Security
Application Security
Cloud Platforms
Cybersecurity Tools
Data Security
Enterprise Risk
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Iso 27001
Nist 800 53
Nist Cybersecurity Framework
NIST SP 800-53
Risk Governance
Risk Management
Security
Security Compliance
Security Operations
Job Description
Digital Federal Credit Union is actively seeking a Senior Information Security Engineer to fortify its risk oversight and security posture. Based in Marlborough, Massachusetts with a hybrid work arrangement, this role sits within DCU’s expansive information security program and supports independent second-line risk assessment, regulatory alignment, and industry-standard governance to strengthen resilience across people, processes, and technology. DCU, the largest credit union in New England, serves more than a million members nationwide and employs over 1,700 team members who value balance and a commitment to community.
Compensation
Salary: USD 116,500 - 140,000 per year
Location
Marlborough, MA | Hybrid work arrangement
Qualifications
- Bachelor's degree in a field relevant to the role, or an additional 4 years of relevant experience in lieu of a degree
- 4 to 6 years of relevant information security experience
Responsibilities
- Perform independent evaluations of information security risks, controls, and processes across technology ecosystems, applications, infrastructure, and third-party relationships
- Assess the design and effectiveness of security controls against established frameworks, regulatory requirements, and industry best practices
- Identify, analyze, and communicate cyber risks, vulnerabilities, control gaps, and emerging threats to risk, governance, and business stakeholders
- Support governance and oversight of security domains including identity and access management, vulnerability management, cloud security, application security, data protection, and security operations
- Conduct risk assessments for new technologies, projects, systems, and business initiatives to identify potential security and operational risks
- Challenge first-line security practices, risk decisions, control implementations, and remediation strategies in a constructive manner
- Monitor information security metrics, key risk indicators, control effectiveness, and trends to spot emerging risks and opportunities for improvement
- Participate in the development and maintenance of information security risk management policies, standards, methodologies, and governance processes
- Assist with regulatory examinations, internal audits, risk reviews, and compliance assessments by preparing analysis, documentation, and responses
- Collaborate with Technology, Information Security, Compliance, Enterprise Risk, Internal Audit, and business stakeholders to strengthen risk practices and improve control maturity
- Prepare reports and presentations that translate technical risks and control gaps into clear, business-focused insights
- Support oversight of third-party technology providers and critical vendor security risk management
- Stay informed about cybersecurity threats, regulatory developments, emerging technologies, and industry practices to assess potential impacts on the organization
Requirements
- Bachelor’s degree in a field relevant to the role, or 4 additional years of related experience in lieu of a degree
- 4–6 years of relevant experience in information security
- Knowledge of information security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or FFIEC guidance; familiarity with financial services regulatory expectations
- Understanding of cybersecurity domains with emphasis on artificial intelligence, cloud security, network security, and data protection
- Ability to enable safe use of AI technologies within a financial services setting
- Experience with Model Context Protocol governance
- Experience with Microsoft Copilot, OpenAI ChatGPT, Anthropic Claude and similar tools
- Familiarity with AI security tools such as Palo Alto Prisma AI runtime security, CrowdStrike Falcon AI Detection and Response, or equivalent
- Extensive experience securing and governing Microsoft Azure and Amazon Web Services (AWS)
- Experience with cloud security tooling such as Orca, Prisma Access Cloud, Wiz, or similar
- Strong analytical and problem-solving skills with the ability to perform objective risk assessments and collaborate with stakeholders
- Ability to advocate for security while maintaining constructive relationships with business partners
- Support for shifting security left and integrating security throughout the development lifecycle
- Excellent written and verbal communication skills, with the ability to explain technical concepts in business terms
Technologies
- NIST CSF, NIST 800-53, ISO 27001, CIS Controls, FFIEC guidance
- Model Context Protocol governance (MCP)
- AI and collaboration tools: Microsoft Copilot, OpenAI ChatGPT, Anthropic Claude
- AI security tools: Palo Alto Prisma AI runtime security (AIRS), CrowdStrike Falcon AI Detection and Response (AIDR)
- Cloud platforms: Microsoft Azure, Amazon Web Services (AWS)
- Cloud security tooling: Orca, Prisma Access Cloud, Wiz
Schedule
Monday through Friday, 8:00 AM to 5:00 PM (40 hours per week)
Typical Scope
- Apply best practices and contextual knowledge of business challenges to improve products, processes, or services
- Manage small projects or programs with manageable risk and resource needs, solving complex problems through analysis and collaboration
- Interpret policies and adapt them to evolving scenarios, exercising independent judgment with minimal supervision
About the Employer
- DCU is the largest credit union headquartered in New England, serving more than one million members across all 50 states
- The organization employs over 1,700 team members and emphasizes work-life balance and a sense of community
- DCU is an equal opportunity employer, committed to diversity, inclusion, and equity
- Applicants needing reasonable accommodations during the employment process should contact [email protected]
- Visa sponsorship is not available for this position at this time