- Company Name
- Zempler Bank
- Job Title
- Information Security Engineer
- Job Description
-
**Job title:** Information Security Engineer
**Role Summary:**
Design, implement and maintain information security controls to ensure PCI‑DSS, NIST‑CSF, or equivalent compliance. Support incident response, vulnerability management, change governance, and risk mitigation for a digital‑banking environment.
**Expectations:**
- Hybrid working model; one onsite day per month at London Bridge.
- 24/7 incident support (average once per month).
- Deliver training, documentation, and reporting to the CISO and security team.
- Operate within established governance and repeatable change processes.
**Key Responsibilities:**
- Maintain and evolve the organization’s security control framework and asset lifecycle.
- Manage patching, vulnerability remediation, and configuration hardening for Windows, AD, Office 365, and related services.
- Configure SIEM monitoring, respond to alerts, and conduct post‑incident reviews.
- Produce and maintain security documentation: architecture diagrams, configuration repositories, and knowledge‑base articles.
- Support change management, ensuring all security enhancements undergo controlled release and rollback procedures.
- Report ticket status, metrics, and risk register updates to leadership.
- Conduct horizon scanning for emerging threats, technologies, and regulatory changes.
- Identify and elevate security risks, contributing to the Enterprise Risk Management framework.
**Required Skills:**
- Proven experience in an information security team.
- Hands‑on with LogRhythm SIEM, McAfee, firewalls, Office 365 compliance tools, CASB.
- PCI‑DSS or NIST‑CSF/ISO 27001 implementation experience.
- Windows Server (2012/2016) security, AD, GPO, Certificate Services, Office 365, and Windows 10 hardening.
- Scripting/automation (PowerShell, Python, etc.).
- Network, storage, backup, firewall, virtualization, VDI, monitoring, alerting, and IAM fundamentals.
- Strong verbal and written communication; ability to deliver training.
**Required Education & Certifications:**
- CISSP, MCSE, ITIL, or equivalent professional security certification (preferred).
- Degree in Computer Science, Information Security, or related field (preferred but not mandatory if certifications and experience satisfy).