We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior Security Engineer, Information Technology

NISA Investment Advisors, LLC
life insurance, paid time off, retirement plan
Oct 06, 2026

Senior Security Engineer, Information Technology


Overview

NISA Investment Advisors, LLC (NISA) partners with world-leading organizations to design, develop, and manage highly customized, risk-controlled investment strategies across fixed income, equities, and derivatives. With $483 billion assets under management ($299 billion in physical assets and $184 billion in derivatives notional value), NISA actively manages risk for institutional investors, providing clarity to complicated challenges and stability in ever-evolving markets. At NISA, we foster a culture that supports both personal and professional growth, providing opportunities to learn from experienced professionals while contributing meaningful work from the outset. We seek candidates who demonstrate strong quantitative and analytical skills, intellectual curiosity, and a collaborative mindset to join our growing teams.



Responsibilities

As Senior Security Engineer on NISA's Cybersecurity team within the Technology Operations Group, you are a senior individual contributor who engineers and operates security controls across identity and access management (IAM), privileged access management (PAM), cloud, artificial intelligence (AI), security operations and vulnerability management, partnering with the Deputy CISO and IT engineering.

    Identity and access management: Engineer and operate identity platforms (Entra ID, Active Directory, SSO), enforcing phishing-resistant multifactor authentication (MFA) and conditional access; automate joiner/mover/leaver and access reviews; govern non-human identities; respond to identity-based threats
  • Privileged access management: Administer the PAM platform (vaulting, rotation, session recording); drive least privilege and just-in-time elevation across servers, databases, network, cloud and SaaS; implement tiered administration; centralize secrets management
  • Cloud security: Enforce AWS and Azure guardrails (landing zones, identity, segmentation, encryption and key management); operate cloud posture and workload protection tooling; embed policy-as-code in infrastructure as code (IaC) and CI/CD pipelines; secure Microsoft 365 and SaaS
  • AI security and governance: Pilot and build guardrails for approved AI tooling and firmwide AI adoption; assess AI systems and vendors for prompt injection, data leakage and excessive agent permissions (NIST AI RMF, OWASP LLM Top 10); enforce least privilege and logging for AI agents; monitor unapproved AI use; use AI-assisted engineering with human review of production-bound output
  • Security operations and incident response: Engineer and tune SIEM/SOAR, endpoint detection and response (EDR) and logging for detections mapped to MITRE ATT&CK; advance automation-first detection and response; lead incident response, forensics and root-cause analysis; maintain playbooks, run tabletop exercises and threat hunt
  • Vulnerability management: Operate scanning across network, container, cloud, application and endpoint environments; prioritize remediation by exploitability and asset criticality; conduct assessments and partner on penetration testing; maintain secure configuration and patch baselines
  • Security architecture and data protection: Apply zero trust, defense-in-depth and secure-by-design principles to new systems; engineer network and email security (segmentation, remote access, DNS filtering, DMARC); support data loss prevention, encryption and PKI; partner on secure development and threat modeling
  • Governance, risk and compliance: Operate controls aligned with NIST CSF, SOC 2 and applicable regulations; support client and vendor due diligence; produce security metrics; maintain policies and standards
  • Resilience and leadership: Support disaster recovery testing and security awareness; mentor junior engineers; maintain runbooks and architecture diagrams; participate in on-call rotation; perform other duties as assigned


Qualifications

  • Bachelor's degree in computer science, cybersecurity or a related field, or equivalent experience
  • 7+ years of IT or security experience, including 5+ years of hands-on security engineering
  • Hands-on enterprise IAM and PAM engineering (e.g., Entra ID, Okta, CyberArk, BeyondTrust)
  • Hands-on experience securing AWS and/or Azure and engineering SIEM/SOAR and EDR platforms
  • Proficiency in security automation and IaC (e.g., Python, PowerShell, Terraform)
  • Strong command of core security concepts across all domains (least privilege, zero trust, cryptography, network security, risk management, secure development) and frameworks such as NIST CSF, SOC 2 and MITRE ATT&CK
  • Demonstrated mentorship and ability to explain technical risk to nontechnical stakeholders

Preferred

  • AI security, financial services or Microsoft 365 security (Defender, Purview) experience
  • CISSP, CCSP, AWS Security - Specialty, AZ-500, SC-300 or GIAC certification

NISA's culture encourages collaboration and innovation. We seek self-motivated, intellectually curious individuals willing to push themselves and others in an environment that celebrates fresh thinking. We equip employees with the resources needed to excel, and we encourage personal development. NISA is dedicated to internally cultivating and rewarding talent. Employees at NISA are provided with a wide range of benefits, including health, dental, vision and life insurance options, paid time off, a competitive retirement plan, onsite cafeteria, fitness center, a health and wellness program, and an educational assistance program.

NISA is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Applied = 0

(web-9db6c7984-whzc5)