The Principal Engineer III reports within the Information Security organization and is responsible for ensuring that our operational designs, processes, procedures and technology are deployed in manner that meet cyber security standards. This role is critical in ensuring the security, compliance, and resilience of our Azure & AWS-hosted infrastructure and services. The ideal candidate will be a strategic thinker and technical leader, capable of both guiding secure cloud architecture and diving into technical implementations. They will develop and enforce cloud security baselines, guardrails, and automation for threat detection and response. Lead threat modeling reviews, security risk assessments, and cloud configuration reviews across the cloud environments. The Principal Engineer III will represent Information Security during business project initiation, technology architecture, design and lifecycle management of the Bank's technology and security infrastructure providing oversight, guidance, security consulting and evaluation of security posture. This position requires a subject matter expert who will provide thought leadership and collaborate with various stakeholders across the Western Alliance enterprise. Evaluate proposed systems, networks, and software designs for security risks. Recommend mitigations and resolve integration issues to ensure secure implementation within existing infrastructure. Develop, manage, and communicate a comprehensive enterprise-wide cloud secure by design strategy, aligning with organizational goals and stakeholder expectations. Lead cybersecurity risk assessments, drive mitigation efforts, manage incident response planning, and collaborate with cross-functional teams to support secure design decisions across the organization. Developing strategies for operational security, including security of data and Azure and AWS services and workloads. Responding swiftly to any security incidents and providing thorough post-event analyses. Staying updated with the latest security trends, threats, and control measures Maintaining compliance with legal and regulatory requirements pertaining to information security, privacy, and data protection. Engage with business and IT project teams to enforce security standards, offer solutions to applicable security risks and ensure resiliency is built into new project or applications design, engineering, and implementations. Engage with the IT Risk Committee(s) to review and opine on requested exceptions and risk acceptance rationale. Actively drive security, data privacy, business continuity and disaster recovery resiliency goals in project and product deployments as part of project teams and Architectural Standard Board. Provide oversight, review and approval of technology readiness checklist as a member of the Technical Review Board. Perform annual Swift and Fedline self-assessment and attestation processes according to industry requirements. Contributes to the continual development of information security policies and standards. Supports team in the management of security measures and controls over existing operating systems including configuration management, and CIS Standards. Contribute to the development and refinement of key risk indicators and metrics to measure the effectiveness of the cyber security program.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level