Senior Security Engineer, Information Technology

NISA Investment Advisors, LLC
  • St. Louis, Missouri
    3 days ago

    Job Description

    Overview:

    NISA Investment Advisors, LLC (NISA) partners with world-leading organizations to design, develop, and manage highly customized, risk-controlled investment strategies across fixed income, equities, and derivatives. With $483 billion assets under management ($299 billion in physical assets and $184 billion in derivatives notional value), NISA actively manages risk for institutional investors, providing clarity to complicated challenges and stability in ever-evolving markets. At NISA, we foster a culture that supports both personal and professional growth, providing opportunities to learn from experienced professionals while contributing meaningful work from the outset. We seek candidates who demonstrate strong quantitative and analytical skills, intellectual curiosity, and a collaborative mindset to join our growing teams.

    Responsibilities:

    As Senior Security Engineer on NISA's Cybersecurity team within the Technology Operations Group, you are a senior individual contributor who engineers and operates security controls across identity and access management (IAM), privileged access management (PAM), cloud, artificial intelligence (AI), security operations and vulnerability management, partnering with the Deputy CISO and IT engineering.

    • Identity and access management: Engineer and operate identity platforms (Entra ID, Active Directory, SSO), enforcing phishing-resistant multifactor authentication (MFA) and conditional access; automate joiner/mover/leaver and access reviews; govern non-human identities; respond to identity-based threats
    • Privileged access management: Administer the PAM platform (vaulting, rotation, session recording); drive least privilege and just-in-time elevation across servers, databases, network, cloud and SaaS; implement tiered administration; centralize secrets management
    • Cloud security: Enforce AWS and Azure guardrails (landing zones, identity, segmentation, encryption and key management); operate cloud posture and workload protection tooling; embed policy-as-code in infrastructure as code (IaC) and CI/CD pipelines; secure Microsoft 365 and SaaS
    • AI security and governance: Pilot and build guardrails for approved AI tooling and firmwide AI adoption; assess AI systems and vendors for prompt injection, data leakage and excessive agent permissions (NIST AI RMF, OWASP LLM Top 10); enforce least privilege and logging for AI agents; monitor unapproved AI use; use AI-assisted engineering with human review of production-bound output
    • Security operations and incident response: Engineer and tune SIEM/SOAR, endpoint detection and response (EDR) and logging for detections mapped to MITRE ATT&CK; advance automation-first detection and response; lead incident response, forensics and root-cause analysis; maintain playbooks, run tabletop exercises and threat hunt
    • Vulnerability management: Operate scanning across network, container, cloud, application and endpoint environments; prioritize remediation by exploitability and asset criticality; conduct assessments and partner on penetration testing; maintain secure configuration and patch baselines
    • Security architecture and data protection: Apply zero trust, defense-in-depth and secure-by-design principles to new systems; engineer network and email security (segmentation, remote access, DNS filtering, DMARC); support data loss prevention, encryption and PKI; partner on secure development and threat modeling
    • Governance, risk and compliance: Operate controls aligned with NIST CSF, SOC 2 and applicable regulations; support client and vendor due diligence; produce security metrics; maintain policies and standards
    • Resilience and leadership: Support disaster recovery testing and security awareness; mentor junior engineers; maintain runbooks and architecture diagrams; participate in on-call rotation; perform other duties as assigned
    Qualifications:
    • Bachelor's degree in computer science, cybersecurity or a related field, or equivalent experience
    • 7+ years of IT or security experience, including 5+ years of hands-on security engineering
    • Hands-on enterprise IAM and PAM engineering (e.g., Entra ID, Okta, CyberArk, BeyondTrust)
    • Hands-on experience securing AWS and/or Azure and engineering SIEM/SOAR and EDR platforms
    • Proficiency in security automation and IaC (e.g., Python, PowerShell, Terraform)
    • Strong command of core security concepts across all domains (least privilege, zero trust, cryptography, network security, risk management, secure development) and frameworks such as NIST CSF, SOC 2 and MITRE ATT&CK
    • Demonstrated mentorship and ability to explain technical risk to nontechnical stakeholders

    Preferred

    • AI security, financial services or Microsoft 365 security (Defender, Purview) experience
    • CISSP, CCSP, AWS Security – Specialty, AZ-500, SC-300 or GIAC certification

     

    NISA’s culture encourages collaboration and innovation. We seek self-motivated, intellectually curious individuals willing to push themselves and others in an environment that celebrates fresh thinking. We equip employees with the resources needed to excel, and we encourage personal development. NISA is dedicated to internally cultivating and rewarding talent. Employees at NISA are provided with a wide range of benefits, including health, dental, vision and life insurance options, paid time off, a competitive retirement plan, onsite cafeteria, fitness center, a health and wellness program, and an educational assistance program.

    NISA is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. 

    Numbers & Facts

    LocationSt. Louis, Missouri

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Artificial Intelligence (AI)unmatched
    • Artificial Intelligence (AI) Agentsunmatched
    • Asset Managementunmatched
    • Authenticationunmatched
    • Automationunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Centralized Operations/Managementunmatched
    • Channel Strategiesunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Cryptographyunmatched
    • Customer Support/Serviceunmatched
    • DNS (Domain Name System)unmatched
    • Defense in Depthunmatched
    • Derivativesunmatched
    • Disaster Recoveryunmatched
    • Due Diligenceunmatched
    • Email Securityunmatched
    • Financial Servicesunmatched
    • Fixed Income Investmentsunmatched
    • Forensic Scienceunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Injectionsunmatched
    • Internet Securityunmatched
    • Investment Servicesunmatched
    • Just in Time (JIT)unmatched
    • Leadershipunmatched
    • Loss Preventionunmatched
    • Machine Toolunmatched
    • Mentoringunmatched
    • Metricsunmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Network Securityunmatched
    • On Callunmatched
    • Operations Managementunmatched
    • Penetration Testingunmatched
    • Phishingunmatched
    • Protective Servicesunmatched
    • Public Key Infrastructure (PKI)unmatched
    • Python Programming/Scripting Languageunmatched
    • Quantitative Analysisunmatched
    • Regulationsunmatched
    • Remote Accessunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • Root Cause Analysisunmatched
    • Security Architectureunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Single Sign-On (SSO)unmatched
    • Software Patchesunmatched
    • Software as a Service (SaaS)unmatched
    • Systems Administration/Managementunmatched
    • Systems Analysisunmatched
    • Team Playerunmatched
    • Technical Operationsunmatched
    • Threat Modelingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder