• United States
  • Fully Remote
  • Full-Time

Cybersecurity Engineer

Job Description

Sigil Partners is seeking an experienced Cybersecurity Engineer to design, implement, and support security controls that protect financial systems, cloud environments, applications, networks, and sensitive data. This individual will collaborate with technology, engineering, risk, compliance, and business stakeholders to reduce security risk and strengthen the organization’s overall security posture.

The ideal candidate will bring strong cybersecurity and engineering fundamentals, experience securing production environments, and the ability to translate security requirements into scalable technical solutions. Experience with cloud security, identity and access management, security automation, vulnerability management, and financial-services compliance is highly desirable.

Responsibilities

  • Design, implement, test, and maintain security controls across cloud, network, endpoint, application, identity, and data environments
  • Assess system architectures and technical designs to identify security risks and recommend appropriate controls
  • Support vulnerability identification, prioritization, remediation, and reporting
  • Configure and maintain security technologies such as SIEM, EDR, DLP, firewalls, secure web gateways, vulnerability scanners, and cloud-security platforms
  • Develop security automation, detection logic, monitoring capabilities, and incident-response workflows
  • Investigate security alerts, anomalous activity, potential incidents, and control failures
  • Collaborate with engineering and DevOps teams to integrate security into software-development and cloud-delivery processes
  • Support identity and access management, privileged-access controls, multifactor authentication, and zero-trust initiatives
  • Perform security reviews of applications, infrastructure, third-party integrations, and technology vendors
  • Develop and maintain security standards, procedures, technical documentation, and control evidence
  • Support audits, risk assessments, regulatory examinations, and compliance initiatives
  • Track security metrics, control effectiveness, remediation activities, and emerging threats
  • Participate in incident response, threat modeling, tabletop exercises, and post-incident reviews
  • Evaluate emerging security technologies and recommend improvements based on risk and business requirements

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline
  • 3+ years of professional cybersecurity, security-engineering, or information-security experience
  • Experience securing cloud, network, endpoint, application, or identity environments
  • Hands-on experience with AWS, Microsoft Azure, or Google Cloud security controls
  • Familiarity with SIEM, EDR, vulnerability-management, IAM, DLP, firewall, and security-monitoring technologies
  • Understanding of network security, authentication, encryption, access control, secure configuration, and defense-in-depth principles
  • Knowledge of cybersecurity frameworks and standards such as NIST CSF, NIST 800-53, CIS Controls, or ISO 27001
  • Experience with vulnerability assessment, incident investigation, risk remediation, and security-control testing
  • Familiarity with scripting or automation using Python, PowerShell, Bash, or similar technologies
  • Strong analytical, troubleshooting, documentation, and communication skills
  • Ability to work effectively with engineering, compliance, audit, risk, and business teams
  • Ability to manage sensitive information and exercise sound professional judgment

Preferred Qualifications

  • Experience working in banking, payments, insurance, investment management, fintech, or another regulated financial-services environment
  • Familiarity with financial-services requirements such as GLBA, FFIEC guidance, PCI DSS, SOX, NYDFS Cybersecurity Regulation, or related standards
  • Experience with cloud-security posture management, cloud-native security tools, or infrastructure-as-code scanning
  • Familiarity with application security, DevSecOps, secure software-development practices, and CI/CD security
  • Experience with security orchestration, automation, and response technologies
  • Knowledge of container, Kubernetes, API, database, and data-protection security
  • Experience with threat modeling, penetration-testing coordination, or adversary-simulation exercises
  • Certifications such as CISSP, CCSP, GIAC, Security+, CISM, or cloud-security certifications
  • Experience supporting regulatory examinations, internal audits, or external security assessments
Back to vacancies

Built for Critical hires. Ready when you are.

Ready when you are