Search jobs > Salt Lake City, UT > Information security

Information Security Engineer (AppSec)

Deseret Mutual Benefit Administrators
Salt Lake City, UT, USA
Full-time
Quick Apply

DMBA provides a variety of benefits including health, life, and retirement to employees of the Church of Jesus Christ of Latter-day Saints and its affiliates.

DMBA began operations in 1970 and is now in its 54th year of supporting the Church of Jesus Christ of Latter-day Saints and its mission.

Position Summary :

DMBA is looking for an Information Security Engineer to join the Information Security Team. The Information Security Team reports to the Chief Technology Officer and is responsible for the Information security program.

This technical operations role will support various development, cloud, and red team projects to safeguard sensitive business information.

Responsibilities :

  • Help define and implement a comprehensive application security program to protect the confidentiality, integrity, and availability of company assets
  • Establish reuseable policy and procedures
  • Serve as an authority on application security with development and operations teams
  • Evaluate company attack surface to detect misconfigurations, vulnerabilities, or weaknesses requiring mitigation
  • Partner with development teams to perform various code, credential, and SCA scans
  • Design, implement, and automate reasonable controls in cloud CI / CD environments
  • Support the creation and implementation of a red team function and partner with security operations to test detection capabilities and weaknesses
  • Help define the scope for annual and periodic penetration assessments
  • Actively participate in architectural discussions with other engineers and support staff on various information security topics such as ZTNA, observability, API security, and emergent technologies (AI / ML, etc.)
  • Participate in the incident response process to support the identification, eradication, and recovery of systems.
  • Create architecture and application documentation
  • Help define procedures to formalize and mature application security
  • Support various security projects and participate in solution selection and enhancements
  • Be an active participant in building the information security program by evaluating and suggesting new solutions and ideas and championing the information security program

Qualifications and Experience :

  • 4-year Bachelor's degree or equivalent experience
  • 4-7 years of IT and information security experience
  • 2-3 years of development experience
  • Strong understanding of information security best practices and security frameworks (NIST CSF, ISO 27001, ISO27005, CIS Controls, HITRUST, etc.

as they pertain to application security

  • Working knowledge of the OWASP top 10
  • Deep knowledge of databases, common operating systems (Windows / Linux), networking, application, and cloud environments
  • CASE, CEH, AWS, or equivalent information security training and expertise
  • Experience with HIPAA, DOL Information security best practices, international, federal, and state privacy laws
  • Experience with C#, .NET, and JavaScript
  • Developing, hardening, and securing APIs

Other Qualifications :

  • Ability to work with various IT and Business teams to address sensitive topics and risk
  • Strong management and business communication skills
  • Deep technical understanding and ability to apply it to complex technical and business solutions
  • Expertise in project management and prioritization
  • Highly motivated team player with a desire to improve the information security program
  • Work in a hybrid remote work and office work environment

What We Offer :

  • Competitive pay
  • Rich medical, vision and dental benefits with low premiums (we are the #1 health plan in Utah!)
  • Rich retirement planning; including 401(k) company match, 8% Retirement Plus Plan (we just give you free money for retirement), life insurance, and full service Financial Planners onsite at no cost
  • Generous paid leave plan that starts accruing your first day, your birthday off, additional sick leave and 11 paid holidays
  • World class wellness program with health coaching, ability to earn 3 additional days off a year, fun activities and an onsite gym.
  • Tuition reimbursement
  • Career development through company sponsored programs and over 5000 on-demand online training courses.

Job Posted by ApplicantPro

14 days ago
Related jobs
Promoted
Slalom Consulting
Salt Lake City, Utah

Collaborate with IT and security teams to ensure compliance with security policies. Experience as a Microsoft Security Engineer or similar role. Proficiency in Microsoft security technologies and tools, including Purview Information Protection, DLP, data lifecycle management, records management, and...

Promoted
Deloitte
Salt Lake City, Utah

The Information System Security Engineer (ISSE) will be responsible for creating and maintaining RMF artifacts and shall implement security controls, patch vulnerabilities on network devices, and resolve system security engineering concerns to ensure cyber compliance and readiness for a Government F...

Deseret Mutual Benefit Administrators
Salt Lake City, Utah

DMBA is looking for an Information Security Engineer to join the Information Security Team. The Information Security Team reports to the Chief Technology Officer and is responsible for the Information security program. Actively participate in architectural discussions with other engineers and suppor...

Promoted
Deloitte
Salt Lake City, Utah

The Information System Security Engineer (ISSE) will be responsible for creating and maintaining RMF artifacts and shall implement security controls, patch vulnerabilities on network devices, and resolve system security engineering concerns to ensure cyber compliance and readiness for a Government F...

L3Harris Technologies
Salt Lake City, Utah

Lead, Information Security Systems Engineer - NGJ. L3Harris’ Communication Systems segment is currently seeking a Lead, Information Security Systems Engineer to join our team. As a Lead, Information Security Systems Engineer at L3Harris Technologies, you will be involved in the cryptography that ena...

GDIT
Salt Lake City, Utah

The Information System Security Engineer (ISSE) is primarily responsible for conducting information system security engineering activities with a focus on lifecycle of current systems and future requirement scoping. The ISSE employs best practices when implementing security requirements within an in...

L3Harris Technologies
Salt Lake City, Utah

Lead, Information Security Systems Engineer. L3Harris’ Communication Systems segment is currently seeking a Lead, Information Security Systems Engineer to join our team. As a Lead, Information Security Systems Engineer at L3Harris Technologies, you will be involved in the cryptography that enables c...

NICE
Sandy, Utah

At least 1-2 years of experience in information security, with a focus on hands-on security engineering and operations. We are seeking a skilled Information Security Engineer to join our team. The Information Security Engineer will collaborate closely with cross-functional teams to ensure the confid...

L3Harris Technologies
Salt Lake City, Utah

As a Specialist, Information Security Systems Engineer at L3Harris Technologies, you will be involved in the cryptography that enables communication capabilities for the warfighter. Other security or technical certifications: CISA, CISM, CEH, CPT, MCSE, CCNA, Red Hat, Network+, SANS GIAC, Security+,...

Promoted
Northrop Grumman
Magna, Utah

Northrop Grumman Space Systems - Propulsion Systems is seeking a *Principal Industrial Security Analyst (Level 3) or Senior Principal Industrial Security Analyst (Level 4)* who will function as the Facility Security Officer (FSO experience) with oversight and responsibility for DoD classified progra...