EagleBank

Information Security Engineering Manager

EagleBank  •  $141k - $242k/yr  •  Silver Spring, MD (Onsite)  •  7 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We are a values driven organization putting Relationships FIRST EagleBank (NASDAQ – EGBN) is focused on being Flexible, Involved, Responsive, Strong, and Trusted By prioritizing meaningful connections with our customers, employees, and shareholders, we relentlessly deliver the most compelling, valuable service to our customers.EagleBank is committed to inclusion, equity, and respect. We celebrate diversity and intentionally seek out opportunities to learn from one another’s experience. We believe employees are essential to the building of relationships and we prioritize investing in employee growth and wellbeing. Employee involvement is fostered through resource groups, mentorship programs, community service, and scholarship opportunities for continued education. With features including maternity and parental leaves, wellness discounts, healthcare premium sharing, employer funding in your HSA account, and 100% 401(k) matching up to 4%, we pride ourselves in the ways we support our internal relationships. The minimum and maximum projected annualized salary for this position is: $141,076.00 to $241,844.00. Additional compensation may be possible based on experience and skills.

Responsibilities

The Information Security Manager is responsible for monitoring, analyzing and maintaining EagleBank's technical security engineering controls in support of EagleBank's Information Security Program. This role will be focused on security engineering of the EagleBank applications and network which includes creation and timely execution of project plans, tool installations, assisting with upgrades of EagleBank's technology environments and ensuring that appropriate external feeds and threat intelligence are integrated into the operational tools. The role executes controls to maintain the confidentiality, integrity and availability of EagleBank's information systems and infrastructure and supports the bank's operational goals.

Major duties and responsibilities:

  • Lead a team of five (5) Information Security Engineers.
  • Independently identify and propose remediations for risks related to Bank IT infrastructure.
  • Support information security projects and lead engineers, vendors, and consultants.
  • Review, analyze, and update network security tool configuration and architecture, and document, troubleshoot, and remediate issues.
  • In collaboration with the CISO, identify opportunities to mature information security engineering capabilities and processes, executing some and assigning tasks to others for execution.
  • Interfaces directly with senior members of IT Operations team to address cross-cutting issues and events.
  • Acts as backup Incident Response lead for Information Security team.
  • Work with managed service providers, network administrators, and Security Operations to resolve problems, evaluate new solutions, recommend changes, and investigate incidents.
  • Analyze reports, identify, and distribute action items or service tickets to support teams or vendors to address InfoSec engineering issues.
  • Document and submit Change Management requests on behalf of the InfoSec engineering team and present changes to Change Advisory Board when appropriate.
  • Sets weekly tasks and runs regular security engineering team meetings and one on one is with direct reports. Responsible for performance, setting annual goals including employee development and training.
  • Manage and distribute the triage and analysis of security events escalated from the Tier-2 support teams.
  • Act as Backup to the CISO.

Qualifications

Requirements:

  • Bachelor’s Degree in Arts/Sciences (BA/BS) in Computer Science or Information Systems, Information Technology or related focused technical training or in lieu 4 additional years of engineering and project management experience
  • 10 years experience in a combination of information security operations/engineering/administration with emphasis on deploying security tools and capabilities
  • 8 years experience configuring and implementing information security technologies
  • 8 years experience working in Microsoft network security environment with knowledge of Active Directory, Intune, Azure AD and Azure Sentinel, O365 / Security Center
  • 4 years experience leading a team of technical professionals
  • One or more of the following certifications (or equivalent): − CASP (CompTIA Advanced Security Practitioner) or ISC2 CISSP − EC-Council Certified Ethical Hacker (CEH) − AZ-500 Microsoft Azure Security Engineer Associate
  • Expert knowledge of security tools used for vulnerability management (Tenable Nessus, Qualys, Nexpose), privileged access management (CyberArk), Security Event Incident Management (Microsoft Sentinel), Microsoft Endpoint Security (EDR)
  • Expert knowledge of scripting languag(es) such as PowerShell, KQL
  • Expert knowledge of Microsoft Defender for Cloud
  • Expert knowledge of Active Directory (AD)
  • Expert knowledge of TCP/IP networking: networking topology, protocols and services
  • Expert knowledge of Palo Alto firewalls, Panorama and firewall operations
  • Experience with operations and optimization of Secure Web Gateway (preferably Netskope)
  • Experience with Email Security tooling (Proofpoint, Purview) and optimization
  • Experience leading tool, application, and system security assessments / evaluations
  • Experience with security elements of Intune, Conditional Access Policy implementations
  • Experience with security engineering of Linux servers
  • Strong Active Directory and Windows Group Policy (GPO) knowledge
  • Experience leading security collaboration with operations teams responsible for networking technology and protocols, including routers, switches, VPNs, email gateways

Preferences:

  • 4 years experience with AD tools for inventory, analysis and report on Active Directory structure, objects, permissions, etc
  • 4 years experience with malware analysis using sandboxes
  • 4 years security engineering/administration in the financial sector
  • One or more of the following certifications (or equivalent): − CCNA − EC-Council Certified Security Analyst (ECSA) − SC-100 Microsoft Cybersecurity Architect − ISC2 System Security Certified Practitioner (SSCP) − ISACA certifications (CRISC) − GSE GIAC Security Expert − GIAC Certifications such as GPPA, GCHI, GPEN − GSAE (GIAC Security Audit Essentials) − GWAPT (GIAC Certified Web Application Penetration Tester)
  • Experience with network auditing tools such as StealthBits, Varonis
  • Experience leading engineering support for escalations, investigations, and incident response

Don't meet all the requirements? We encourage you to still apply if you think you are the right person to join our community. We are always interested connecting with people inspired by our mission and values. If you aren't hired for this position, your resume will remain available for the next year and might be considered for future openings. Note: You can update your resume as often as needed.

EagleBank

About EagleBank

EagleBank is a local community business bank with 12 branches and 4 regional offices in Maryland, Northern Virginia and Washington, DC. The bank focuses on providing superior customer service and customized financial opportunities for the local business community that we live in and serve. EagleBank also offers a complete line of competitive personal banking products and services.

Our mission is to be the most trusted, experienced and client-centric bank across the Washington, DC region and beyond. We do this through our Relationships FIRST philosophy, putting our customers, communities, employees, and shareholders at the forefront of everything we do, delivering the most compelling service and value.

Member FDIC | Equal Housing Lender

Industry
Finance & Insurance
Company Size
501-1,000 employees
Headquarters
Bethesda, Maryland
Year Founded
1998
Social Media