Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr IT Security Engineer

Cornerstone Capital

Cornerstone Capital Bancorp, Inc., headquartered in Houston, is aTexas-basedfinancial services company dedicated to helping families, businesses, and communities thrive. Throughitsprimary subsidiary, Cornerstone Capital Bank, the organizationoperatesa community and business banking franchise alongside a premier national home lending, servicing, and home insuranceplatform-basedfinancial services company dedicated to helping families, businesses, and communities thrive.

Guided by a core Mission, Vision and Convictions statement,Cornerstoneoperates17full-servicebanking locations across major Texas markets andmore than 150mortgage offices nationwide.The companyhas servednearly700,000customersthrough its family of brands, including Cornerstone Home Lending, Roscoe Bank, Peoples Bank, Cornerstone Servicing, and Cornerstone Insurance. Supported by 1,600 team members,Cornerstoneis consistently recognized as a Fortune-certified Great Place to Work® and a Top Workplace.

Formed through the combination of Cornerstone Home Lending and The Roscoe State Bank, Cornerstone brings more than a century of experience and is thehighest-capitalizednew bank in Texas history.

We honor God by using our talents to make a positive difference in the lives of our Team Members, Clients, Shareholders, Communities, and the People who provide services to us.

Who we are looking for:

The Senior Security Engineer serves as a senior cybersecurity resource responsible for supporting and enhancing the organization's security program across security architecture, emerging technology and AI reviews, Identity and Access Management (IAM) governance, vulnerability management, and third-party security. Reporting directly to the Chief Information Security Officer (CISO), this role partners with technology and business stakeholders to identify, assess, mitigate, and validate cybersecurity risks and security controls while ensuring alignment with organizational security objectives and regulatory requirements.

The role also supports security assurance, control effectiveness, remediation validation, security engineering, automation, and continuous improvement initiatives designed to strengthen the organization's overall security posture. Working closely with the Head of IAM and other security and technology leaders, the Senior Security Engineer provides oversight and verification of security controls, conducts security assessments, and supports cybersecurity risk management, compliance, and resilience efforts within a highly regulated banking environment.

The ideal candidate brings strong technical expertise, sound risk-based judgment, a collaborative mindset, and the ability to translate cybersecurity requirements into practical and sustainable solutions. Experience within financial services is preferred, including familiarity with FFIEC guidance, NIST Cybersecurity Framework principles, and regulatory examination preparedness

What you’ll do:
  • Security Assurance & Risk Management – Assess security controls, identify risks and gaps, and support remediation and validation activities to promote effective and sustainable security practices.
  • Security Engineering & Automation – Leverage security technologies, engineering practices, and automation to strengthen controls, improve efficiency, and reduce reliance on manual processes.
  • Security Monitoring & Reporting – Support security metrics, reporting, and monitoring activities to provide visibility into security posture, control effectiveness, and emerging risks.
  • Incident Response & Resilience – Participate in cybersecurity incident response, investigations, exercises, lessons learned, and initiatives that strengthen organizational resilience.
  • Security Governance & Standards – Contribute to the development and maintenance of security standards, procedures, and technical guidance aligned with business objectives, regulatory expectations, and industry practices.
  • Cross-Functional Partnership – Serve as a senior security advisor and collaborate with Technology, business, Risk, Compliance, Audit, and other stakeholders to identify and address cybersecurity risks.
  • Phishing -Lead the enterprise phishing awareness program by conducting monthly phishing simulation campaigns, tracking and reporting key performance metrics, identifying user risk trends, and driving continuous improvement in employee cybersecurity awareness and resilience.
  • Security Architecture, Emerging Technology & AI Reviews
  • Serve as a trusted security advisor for enterprise technology initiatives, strategic projects, and business innovation efforts.
  • Conduct security architecture reviews for applications, infrastructure, cloud services, SaaS platforms, AI-enabled solutions, and third-party technologies.
  • Partnerwith architects, developers, engineers, project managers, and business stakeholders to identify, mitigate, and validate security requirements throughout solution design, implementation, and ongoing operation.
  • Review proposed solutions for secure authentication, authorization, encryption, data protection, logging, monitoring, resiliency, and recovery requirements.
  • Assess emerging technologies, including artificial intelligence (AI), generative AI, machine learning platforms, and AI-enabled business solutions, to ensure appropriate security controls, governance requirements, and data protection measures are established and maintained throughout the technology lifecycle.
  • Evaluate AI-related risks including unauthorized data exposure, excessive permissions, third-party AI integrations, sensitive data protection, model governance considerations, and regulatory compliance implications.
  • Provide guidance aligned with Zero Trust principles, secure-by-design methodologies, banking regulatory expectations, and industry best practices.
  • Participate in AI governance discussions and provide security recommendations for the adoption of emerging technologies.
  • Support the development, maintenance, and continuous improvement of security standards, architectural guidance, and technology control requirements.
  • Validate that key security requirements and controls are appropriately implemented and operating as intended.
  • Participate in vendor evaluations, technology assessments, and project planning activities to ensure security requirements are incorporated early in the project lifecycle.
  • Primarily support the organization's Identity and Access Management (IAM) program in partnership with the Head of IAM.
  • Provide second-line security oversight and independent verification of key cybersecurity controls, including IAM, privileged access, authentication, vulnerability management, and third-party security controls.
  • Administer and oversee identity lifecycle processes, including onboarding, transfers, role changes, and offboarding activities.
  • Support and verify role-based access controls (RBAC), privileged access controls, and segregation of duties requirements.
  • Support Privileged Access Management (PAM) solutions and privileged account governance activities.
  • Manage and support authentication technologies including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and identity federation.
  • Perform independent security control validation and testing to assess design effectiveness, implementation, and sustained operating effectiveness. Validate remediation activities end-to-end, including confirmation that changes have been implemented across affected systems, processes, and procedures.
  • Conduct periodic user access reviews and privileged access reviews.
  • Support Microsoft Entra ID, Active Directory, and related identity platforms.
  • Assist with audit requests, regulatory examinations, and control assessments related to identity and access management.
  • Support the tracking, validation, and closure of cybersecurity audit, assessment, and control findings, including validation that corrective actions address the underlying control deficiency and not solely the individual exception identified
  • Develop and maintain cybersecurity metrics, key risk indicators (KRIs), and key performance indicators (KPIs) to measure control effectiveness, remediation progress, risk exposure, and security program maturity.
  • Prepare management-level reporting on cybersecurity risks, control effectiveness, remediation status, and emerging threats.
  • Identify opportunities to improve identity governance, automation, operational efficiency, and security effectiveness.
  • Vulnerability Management & Third-Party Security
  • Lead enterprise vulnerability management activities, including identification, risk-based prioritization, remediation tracking, validation, and reporting across infrastructure, cloud, applications, and technology environments.
  • Establish and apply risk-based vulnerability prioritization using asset criticality, business impact, exploitability, threat intelligence, exposure, and the presence of compensating controls.
  • Partner with infrastructure, cloud, application, engineering, and technology teams to drive timely remediation of vulnerabilities and reduce organizational exposure.
  • Review and assess findings from vulnerability assessments, penetration tests, red team exercises, security assessments, and other technical security testing activities.
  • Monitor remediation performance, vulnerability aging, remediation SLAs, recurring findings, and risk trends; provide meaningful metrics and reporting to security leadership and governance committees.
  • Manage vulnerability-related exceptions, risk acceptances, and compensating controls, ensuring risks are appropriately documented, reviewed, and tracked through resolution.
  • Incorporate threat intelligence and emerging threat activity into vulnerability prioritization and remediation decisions, with heightened focus on actively exploited and internet-facing vulnerabilities.
  • Participate in third-party security reviews, vendor risk assessments, and ongoing security due diligence for prospective and existing vendors.
  • Evaluate the security posture, control environment, resilience, and risk management practices of third parties, with increased scrutiny for critical vendors, technology providers, and vendors that process sensitive or customer information.
  • Assess third-party security controls, technical safeguards, vulnerability management practices, incident response capabilities, data protection measures, and other cybersecurity risks.
  • Support ongoing third-party monitoring and reassessment throughout the vendor lifecycle, including onboarding, periodic reviews, significant changes, incidents, and offboarding.
  • Identify and assess third-party and technology supply-chain risks, including dependencies that may introduce material cybersecurity or operational risk.
  • Partner with Vendor Management, Procurement, Legal, Privacy, Compliance, and business stakeholders to ensure cybersecurity risks are incorporated into vendor selection, contracting, ongoing oversight, and risk decisions.
  • Support continuous improvement of vulnerability management and third-party risk management processes, including automation, workflow optimization, metrics, governance, and alignment with enterprise security objectives
What you’ll need to be successful:
  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field preferred.
  • Experience working within banking, financial services, mortgage lending, fintech, or other highly regulated industries.
  • Working knowledge of FFIEC guidance, banking regulatory expectations, and cybersecurity requirements applicable to financial institutions.
  • Familiarity with FDIC examinations, internal audits, external audits, and cybersecurity control assessments.
  • Strong understanding of the NIST Cybersecurity Framework (CSF), CIS Controls, and risk-based cybersecurity programs.
  • Familiarity with AI governance, AI risk management concepts, and the secure adoption of emerging technologies.
  • 5+ years of experience in cybersecurity, information security, or security engineering.
  • Experience supporting Identity and Access Management programs, processes, and technologies.
  • Experience conducting security architecture reviews and technical risk assessments.
  • Experience managing or supporting enterprise vulnerability management programs.
  • Experience conducting vendor security reviews and third-party security assessments.
  • Experience with Microsoft Entra ID, Active Directory, Microsoft 365 security technologies, and cloud-based platforms.
Preferred Certifications
  • CISSP
  • CISA
  • CompTIA Security+
  • ISC2 Certified in Cybersecurity (CC)
  • Microsoft SC-900 Security, Compliance, and Identity Fundamentals
  • Microsoft SC-300 Identity and Access Administrator Associate
  • Additional cybersecurity, cloud security, or identity-focused certifications preferred.

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.

  • Occasional evening and weekend work to meet deadlines.
  • Sitting for extended periods of time
  • Dexterity of hands and fingers to operate a computer keyboard, mouse, and to handle other computer components.
  • Ability to participate in training sessions, presentations, and meetings.
  • Ability to lift 30-40 lbs. This job will require picking up and moving equipment.
  • Ability to travel to other locations as needed.

While performing the duties of this job, the employee is regularly required to talk or listen. The employee frequently is required to stand; walk; use hands to finger, handle or feel; and reach with hands and arms. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions of the job. The noise level in the work environment is usually quiet to moderate.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

#J-18808-Ljbffr
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Sr IT Security Engineer in Eastern, KY vacancy
  • $175.2k

     ...support large-scale government operations by leveraging cutting-edge technology and take your career to the next level! Sr. Cyber Security Engineer Arlington, VA We deliver essential technology services to our customers in support of their missions to sustain the... 
    Senior

    NJVC

    Eastern, KY
    5 days ago
  • ## Sr. Cyber Security EngineerApply: Work From Home (Remote) US: Full time: Posted 11 Days Ago: End...  ...incentive bonus.The Sr. Cyber Security Engineer will lead the design, implementation,...  ...cybersecurity engineers, analysts, and IT personnel.* Assist teams with secure deployment... 
    Senior
    Full time
    Temporary work
    Remote work
    Work from home
    Flexible hours

    Johns Manville

    Eastern, KY
    5 days ago
  •  ...shape the future of this vital sector. About the Role You'll be the technical backbone of our security program. This is a hands-on role owning the engineering side of security across the whole platform: vulnerability management, application security, AI/LLM security... 
    Senior
    Remote work
    Flexible hours

    Procurement Sciences Inc

    Eastern, KY
    5 days ago
  • ## Sr. Security EngineerApply: Dallas: Full time: Posted Yesterday: 2026-03756**Overview:**Manages...  ...solutions.**Responsibilities:*** Engineers, implements, and advocates for effective...  ...Provides expert guidance and advice to other IT teams on security architecture, design,... 
    Senior
    Full time
    Work experience placement

    HKS

    Eastern, KY
    3 days ago
  • $214.51k

     ...world. Job Description The Senior Security Architect role is responsible for leading...  ...and have strong working relationships with IT and application development leadership....  ...Collaborate with security, architecture and engineering leadership to support business objectives... 
    Senior
    H1b

    Trinnex Inc.

    Eastern, KY
    5 days ago
  • $150k - $155k

     ...vital interests. Requisition #: pending Job Title: Senior Security Architect Location: Washington, DC - Hybrid 2-3 days...  ...This role works closely with SOC analysts, incident responders, engineering teams, and leadership to ensure the security operations environment... 
    Senior
    Monday to Friday

    Agile Defense

    Eastern, KY
    17 hours ago
  • $107.9k - $195.05k

     ...Sector at Leidos currently has an opening for a Senior Cyber Security Engineer to work at Robins AFB GA. This is an exciting opportunity to use...  ...program and Air Force mission. In this mission we provide IT and engineering expertise along with Information Assurance Services... 
    Senior

    Koitecc Solutions

    Eastern, KY
    5 days ago
  • Vir Biotechnology, Inc. is seeking a Senior IT Security & Infrastructure Engineer (Temp Staff) to join our IT team in San Francisco. This senior, hands‑on role blends infrastructure engineering with security operations to secure and optimize endpoints, cloud services, servers... 
    Senior
    Temporary work
    Work at office

    Vir Biotechnology, Inc.

    Eastern, KY
    2 days ago
  •  ...Position Description Valiant Solutions is seeking a Senior Enterprise Security Architect to join our rapidly growing and innovative cybersecurity team! The Senior Enterprise Security Architect will lead the development of security architecture guidance, standards... 
    Senior
    Contract work
    Remote work

    Valiant Solutions

    Eastern, KY
    3 days ago
  • # Senior Enterprise Security ArchitectValiant SolutionsUnited StatesFull timeRemoteUSD 160,000 – 190,100Apply by Dec 3, 2026## About...  ...Professional (CISSP-ISSAP) ISC2 CISSP Information Systems Security Engineering Professional (CISSP-ISSEP) ISC2 Systems Security Certified... 
    Senior
    Contract work
    Remote work

    NEPSE Trading

    Eastern, KY
    3 days ago
  •  ...Learn more about PPL and CDPAP Job Summary The Senior Network Security Engineer is a hands-on technical security leader responsible for ensuring...  ...audits, and partners closely with the Infrastructure team's Sr. Network Engineer, who owns administration of PPL's network and... 
    Senior
    Remote work

    NEPSE Trading

    Eastern, KY
    2 days ago
  • Sr. Security Engineer - Federal Customer (on-site 5 days per week/Chantilly, VA - TS/SCI Required If you enjoy working with new technologies, enterprise...  ...generation infrastructure to support Information Technology (IT) workloads. You will join a diverse team of DevOps Engineers... 
    Senior

    Dell

    Eastern, KY
    17 hours ago
  • Nova Southwestern University seeks a senior security architect to lead security architecture, detection engineering, and cloud/AI security initiatives. You will establish architectural standards, guide risk assessments, and work across university systems to ensure robust... 
    Senior

    Nova Southeastern University

    Eastern, KY
    17 hours ago
  • Chenega MIOS is seeking a Sr. Cyber Security Engineer in Arlington, VA to secure hardware and operating system components across consumer devices. You will implement network defense, vulnerability management, and incident response aligned with customer missions. The role... 
    Senior

    NJVC

    Eastern, KY
    17 hours ago
  • $142.2k - $213.2k

     ...are seeking cleared mid-level Software Engineers who are self‑motivated and energetic, with...  ...developing solutions to national security threats with products that may involve kernel...  ...Infrastructure Engineer Basic Qualifications for Sr. Principal Cyber Software Engineer Level... 
    Senior
    Work experience placement
    Relocation package
    Monday to Thursday
    Shift work

    Northrop Grumman

    Eastern, KY
    5 days ago
  • $140.5k - $205k

     ...grow, and make an impact. Join us! Job Description: The Senior Security Architect serves as one of the lead technical architects for...  ...Required Qualifications: 10+ years of cybersecurity, security engineering, or enterprise architecture experience. 5+ years designing or... 
    Senior
    Work at office
    Flexible hours
    Shift work
    Day shift

    Koitecc Solutions

    Eastern, KY
    17 hours ago
  • Valiant Solutions seeks a Senior Enterprise Security Architect to lead security architecture guidance, standards, and reference diagrams for on-premise and cloud platforms for a large government agency. U.S. Citizenship is required to support a federal program and the... 
    Senior
    Remote job

    Valiant Solutions

    Eastern, KY
    2 days ago
  • Newell Brands in Atlanta is seeking a Senior Network Security Engineer to lead network segmentation efforts across IT, OT, and cloud. You will design, validate, and enforce security controls, partnering with infrastructure and business teams to reduce the enterprise attack... 
    Senior

    Newell Brands

    Eastern, KY
    17 hours ago
  • Uline, Corporate Headquarters in Pleasant Prairie, WI, is seeking a Senior IT Security Engineer to protect IT Security platforms for one of the largest e-commerce sites in the U.S. You’ll design and manage security solutions and guide business decisions to keep the enterprise... 
    Senior

    Uline

    Eastern, KY
    17 hours ago
  •  ...Alkira, a Lumen Connect Solution, seeks a Principal Security Engineer to shape security strategy across cloud, infrastructure, platform, and applications. You will partner with engineering and executive leaders to design secure systems and scalable practices. The role... 
    Senior

    Alkira Australia

    Eastern, KY
    5 days ago
  • Myriad360 in the United States is seeking a Senior Security Solution Architect (Presales) to design and present advanced cybersecurity architectures for complex client environments. You will translate security requirements into concrete solutions, lead technical conversations... 
    Senior
    Remote job

    Myriad360

    Eastern, KY
    3 days ago
  • CVS Health seeks a Distinguished Engineer to act as a technical authority for AI security and related infrastructure security. The role emphasizes hands-on engineering, building reusable security patterns, reference architectures, and proof-of-concept implementations for... 
    Senior

    Koitecc Solutions

    Eastern, KY
    2 days ago
  •  ...to lead end-to-end designs for large, complex programs. The role blends hands-on architecture with strategic oversight, ensuring security, data integrity, and scalable integration across enterprise domains. You will navigate politics, mentor teams, and translate business... 
    Senior
    Remote job

    Wittij Inc.

    Eastern, KY
    2 days ago
  •  ...a Senior Technical Solution Architect for a 6+ month contract in New York, NY. The role focuses on supporting enterprise physical security and surveillance infrastructure, including Pro-Watch, Genetec Security Center, and related systems. The ideal candidate will lead... 
    Senior
    Contract work

    Intone Inc

    Eastern, KY
    2 days ago
  •  ...Our hedge fund client is seeking an experienced Senior Security Engineer to join their New York office. In this role, you will lead the firm's cybersecurity efforts, focusing on security monitoring, incident response, threat detection, and vulnerability management. Working... 
    Senior
    Work at office

    Koitecc Solutions

    Eastern, KY
    5 days ago
  •  ...Strategic Analysis, Inc. is seeking an experienced Principal Cyber Security Engineer to join our team. Experience with prior Department of Defense Science and Technology (S&T) and Research and Development (R&D) platform integration experience teams is what we are looking... 

    Koitecc Solutions

    Eastern, KY
    3 days ago
  •  ...The Senior Cyber Recovery Engineer will serve as a hands-on technical leader responsible for designing, implementing, and continuously validating the organization’s ability to recover critical systems and data following a cyber event. The role sits at the intersection... 
    Senior

    Compunnel

    Eastern, KY
    5 days ago
  •  ...works in the open, and ships at pace. The engineers on this team are the people market makers...  .... About the Role We’re growing our security team and looking for an engineer who can...  ...tooling and the operational patterns around it Strong Linux administration skills:... 
    Senior
    Remote work

    Jito Labs, Inc.

    Eastern, KY
    5 days ago
  • $200k - $260k

     ...Own the security posture: HIPAA, BAA program, SOC 2 Type II, penetration testing, vulnerability management, secure SDLC. What you...  ...layers, no bureaucracy. Direct access to clinical, security, and engineering leads. What we're looking for ~5+ years of relevant,... 
    Senior
    Full time
    Remote work

    Automate AI, LLC

    Eastern, KY
    2 days ago
  •  ...respectful culture that pushes norms to create world-class products. The Role: We're looking for a Security Engineer to join our AI Platform Security team. It is a high-ownership, low-oversight role for an application/product security generalist who has already done... 
    Senior
    Work at office
    Local area
    Shift work
    3 days per week

    ThoughtSpot

    Eastern, KY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr IT Security Engineer. Be the first to apply!