Senior Security Controls Engineer
American Credit Acceptance
Position Overview
The Senior Security Controls Engineer designs, implements, and continuously improves technical security controls that reduce risk across on‑premises, cloud, and endpoint environments. This role specializes in hardening, benchmark compliance, configuration risk reduction, compensating controls for non‑patchable vulnerabilities, and control automation at scale. The engineer partners with IT operations, platform teams, and risk/compliance to ensure controls are effective, measurable, and audit‑ready.
Key Responsibilities
- Engineer and maintain preventive and detective controls across endpoints, servers, network, identity, and cloud services (Azure/AWS).
- Lead configuration hardening initiatives using industry benchmarks (e.g., CIS) and establish secure configuration baselines for common platforms (Windows, Linux, network devices, cloud services).
- Design compensating controls for vulnerabilities that cannot be remediated through patching (e.g., configuration changes, isolation, access controls, WAF rules, EDR policy tuning, segmentation).
- Own the technical control lifecycle: control requirements → design → implementation → testing/validation → monitoring → continuous improvement.
- Develop and maintain control-as-code and automation (PowerShell/Python/Terraform/CI-CD) to deploy and enforce configurations consistently.
- Implement configuration compliance monitoring, drift detection, and remediation workflows; integrate with ticketing/ITSM for exception handling.
- Partner with Vulnerability Management to translate findings into durable mitigations (hardening, compensating controls, secure defaults) and reduce recurring exposure.
- Collaborate with SOC/IR to improve detections and containment policies aligned to threats and incidents; tune controls based on lessons learned.
- Produce audit-ready evidence: control narratives, diagrams, test results, screenshots/exports, and KPI dashboards.
- Maintain standards, procedures, and runbooks for control engineering; mentor junior engineers and provide technical leadership to cross-functional teams.
Typical Deliverables
- Secure configuration baselines and reference architectures for key platforms.
- Benchmark compliance reporting (coverage, drift, exceptions) with remediation plans.
- Compensating control designs and validation artifacts for non-patchable risk.
- Automation modules/scripts (policy-as-code) to deploy or enforce controls at scale.
- Control test plans, operational metrics, and audit evidence packages.
Required Qualifications
- 7+ years in security engineering, systems engineering, or infrastructure engineering with a strong focus on security controls and hardening.
- Hands-on expertise with Windows and Linux hardening, identity controls, and endpoint security control configuration.
- Experience implementing benchmark-based configuration standards (e.g., CIS) and managing exceptions/risk acceptances.
- Strong understanding of networking fundamentals (segmentation, firewalls, proxies, routing) and how to apply compensating controls.
- Cloud security controls experience in Azure and/or AWS (IAM, network controls, logging, security services).
- Proficiency in scripting/automation (PowerShell and/or Python); familiarity with infrastructure as code (e.g., Terraform) preferred.
- Ability to translate risk into technical control requirements and document controls for audit and compliance purposes.
- Excellent written and verbal communication; ability to work across infrastructure, application, and governance teams.
Preferred Qualifications
- Experience with configuration management and compliance platforms (e.g., Intune, Group Policy, SCCM/MECM, Ansible, Chef, Puppet).
- Experience with vulnerability scanning and exposure management tools (e.g., Tenable, Qualys, Rapid7) and mitigation engineering workflows.
- Experience tuning EDR policies and implementing detection/response guardrails (e.g., Microsoft Defender for Endpoint, SentinelOne, CrowdStrike).
- Experience with SIEM/SOAR integration for control telemetry and automated response.
- Security certifications (one or more): CISSP, GIAC (GSEC/GCED/GCIA), CCSP, AZ-500, AWS Security Specialty, or equivalent.
- Prior work in regulated industries (financial services, healthcare) with control evidence expectations (SOC 2, PCI DSS, GLBA).
Core Competencies
- Control engineering mindset: designs controls that are measurable, testable, and durable.
- Risk-based prioritization: focuses effort where likelihood and impact are highest.
- Systems thinking: understands dependencies and minimizes operational disruption.
- Automation-first: reduces manual work by codifying and scaling controls.
- Stakeholder partnership: collaborates with IT and product teams to drive adoption.
Success Measures (KPIs)
- Reduction in recurring high/critical findings attributable to configuration or control gaps.
- Benchmark compliance coverage (%) and drift rate over time across in-scope assets.
- Mean time to mitigate (MTTM) for non-patchable vulnerabilities using compensating controls.
- Control effectiveness test pass rate and audit evidence readiness (time to produce evidence).
- Automation impact: number of controls deployed/enforced via code and reduction in manual effort.
Working Conditions
This role requires the ability to work effectively with production systems and coordinate maintenance windows, change control, and emergency response activities when required. Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. EEO Statement ACA provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ACA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. California Privacy Notice As an employer of California residents, we are dedicated to protecting your privacy rights. Any personal information you provide during the application process will be used solely for permitted internal purposes and will be handled in accordance with applicable privacy laws. By applying to this position, you consent to the collection, use, and disclosure of your personal information as described in our Employee Privacy Notice.
- ...Description Position Overview The Senior Security Controls Engineer designs, implements, and continuously improves technical security controls that reduce risk across on-premises, cloud, and endpoint environments. This role specializes in hardening, benchmark compliance...SeniorFull timeLocal area
- ...Description Position Overview The Junior Security Controls Engineer supports the design, implementation, and maintenance of security controls... ...in control engineering while working under the guidance of senior engineers. Job Details Reports to Director of...SuggestedFull timeLocal area
- ...Boise Cascade Company is seeking a Physical Security Systems Specialist to manage the full life cycle of security systems including alarm and access control systems. The ideal candidate should have over 8 years of experience in installing and servicing security software...SeniorFull timeRemote work
$186.07k - $218.9k
...expected and fully supported. The Application Security org at Coinbase is hiring for a Senior Offensive Security Engineer, Offensive Security. We are seeking a highly... ...management systems (BMS), physical access control systems (PACS), IoT/home automation devices, wireless...SeniorLocal area$186.07k - $218.9k
...and alignment. Attendance is expected and fully supported. Security is a primary competency at Coinbase, and the Security Team keeps... ..., and other distributed ledger tech Partner with software engineering teams to advise on code and architecture for internal smart...SeniorContract workLocal area- ...Product Security Engineer Our vision is to transform how the world uses information to enrich life for all. Micron Technology is a world... ...(DUT) configurations; improve lab architecture by separating control systems and hardware interaction layers Document lab procedures...SeniorLocal area
$104k - $156k
...Posting Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate security controls that protect Relativity's employee endpoints and the enterprise systems they access. You will help...Remote work$143k - $243k
A leading pharmacy benefits manager is seeking a Senior Principal Actuary to provide actuarial direction and strategic consulting. This remote position demands 10 years of actuarial experience and a strong understanding of pricing strategies. The ideal candidate will excel...SeniorRemote work$184k - $230k
...mission to make the world's health data secure, accessible and actionable, we provide critical... ...lifecycle. Partnering closely with engineering teams, product leadership, and... ...compliance requirements into practical technical controls. What You Will Do Review projects...Senior$152.41k - $179.3k
...foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase Corporate Security (CorpSec) is seeking a Security Engineer to design, implement, and automate security solutions that protect corporate infrastructure, user devices,...Local area$105.1k - $164.13k
...highly technical professionals with a strong foundation in network architecture, design, and security - individuals who are ready to step up from traditional network engineering roles to take ownership of strategic, architecture-level responsibilities. Ideal candidates...Permanent employmentFull timeContract workPart timeLocal areaRemote work$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you'll collaborate with...Work at officeRemote work$150k - $250k
...need to thrive - in our offices or yours. Job Summary The Security Engineer - Google collaborates with account and specialty teams to... .../IP, VPN, VLANs), understanding of security concepts (access control, authentication, encryption), and proficiency in managing network...Work experience placementWork at officeWorldwideFlexible hours- ...The Network Security Engineer is responsible for the day-to-day operations, maintenance, and continuous improvement of perimeter security services... ...Posting Date: 5/7/2026 Due to compliance with U.S. export control laws and regulations, candidate must be a U.S. Person, which...Permanent employmentTemporary workRemote workFlexible hours
- ...high profile and challenging cloud system security work supporting the readiness of America... ...Principal Information Security Systems Engineer (ISSE) will be working with a dynamic... ...) efforts.Monitor and maintain security controls and Plans of Action & Milestones (POA&Ms...Full timeContract workPart timeFor contractorsLocal areaRemote workFlexible hours
- ...We need one operator to be the entire security and compliance program within a startup mindset company. Strategy, audit, Azure controls, customer trust. (Yes, all of it.) You report... ...10+ years across GRC, cloud security engineering, security analyst, DevSecOps, and AppSec...
- ...Performance Bonus Responsibilities: Conduct Electrical engineering services and consulting on low to medium voltage power in... ...experience with design management and project management of Power and Control system projects ~ Experience with voltage drop, harmonic...SeniorRelocation package
- ..., anywhere. EDB empowers enterprises to control risk, manage costs and scale efficiently... ...critical capabilities built in such as security, compliance controls, and observability.... ...visit Job Summary As a Staff Security Engineer at EDB, you will be a technical leader...Remote work
$100k - $172.5k
...Learn more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job Category:... ...for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote work options...Full timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week$218.03k - $256.5k
.... Coinbase Infrastructure Security (InfraSec) is at the forefront... ...role partners closely with engineering teams to design, implement, and... ...cross-functional teams and senior leaders, driving strategic decisions... ..., and maintaining security controls across multi-cloud...Local area- ...An engineering and design firm is seeking a Senior Electrical Engineer for a remote position. The successful candidate will work with major technology companies in the Data Center industry, performing design calculations, writing technical reports, and coordinating with...SeniorRemote workFlexible hours
$218.03k - $256.5k
...Coinbase, identity and access controls are foundational to... ...(IAM) program, housed within Security, is a cross-functional team that... ...landscape. This role serves as a senior technical leader within the IAM program, partnering with Engineering, IT, Platform, and business teams...For contractorsLocal area- ...information into intelligence, inspiring the world to learn, communicate and advance faster than ever. The Global Facilities Cost Control Engineer will serve as a key member of the Global Project Controls organization, supporting project controls and cost management...For contractorsWork experience placementLocal areaImmediate start
$77.79k - $106.08k
...Project Manager / Senior Project Manager / Principal Project Manager Applications... ...is responsible for directing and controlling multiple capital projects, some of which... ...Requires knowledge of Civil Engineering, surveying, design, and construction standards...SeniorFull timeLocal area$146.7k - $214.8k
...provide domain expertise and guide implementation to facilitate successful security posture in of Cisco's products. If you enjoy vulnerability research, crash analysis, reverse engineering, and researching new techniques and writing tools to automate these tasks, this...Full timeTemporary workLocal areaRemote workFlexible hours- ...safety, you'll love consulting at Parexel.Position OverviewThe Senior / Principal Regulatory Compliance Consultant serves as a high-level... ...support, and drive sustainable quality and contamination control improvements.Candidates must bring 10+ years of progressive QC...SeniorRemote workWorldwide
$144.2k - $288.4k
...Development, Standards & Secure Design Lead development and... ...autonomy boundaries, and escalation controls. Promote organization-wide... ...& Influence Influence engineering and product teams to integrate... ...AI initiatives. Advise senior leadership on AI security implications...Hourly payFull timeTemporary workLocal area$143k - $243k
...driven career? Come build the future of pharmacy with us. Senior Principal Actuary - REMOTE Job Description The Senior... ...must understand, comply with and attest to the security responsibilities and security controls unique to their job, and comply with all applicable legal...SeniorWork experience placementLocal areaRemote workVisa sponsorshipWork visa$130k - $153.9k
A cybersecurity services company is seeking a remote Security Consultant - Engineering to provide expertise on Security Incident and Event Management platforms. The ideal candidate will have over 5 years of experience in security engineering projects, with demonstrated...Remote work- ...A fintech company is looking for a professional to enhance security measures in product development. This role focuses on conducting threat modeling, conducting architecture reviews, and ensuring that security best practices are incorporated throughout the product lifecycle...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Controls Engineer. Be the first to apply!
- senior application security engineer Boise, ID
- sr information security engineer Boise, ID
- security engineer Boise, ID
- senior security operations engineer Boise, ID
- aws cloud security engineer Boise, ID
- network security engineer Boise, ID
- senior cloud security engineer Boise, ID
- IT security engineer Boise, ID
- information technology security engineer Boise, ID
- senior platform engineer Boise, ID


