Wellabe logo

Information Security Engineer 3 - Hybrid- Des Moines, Iowa

Hiring from
United States
Work type
Hybrid
Posted
Sep 30, 2026
Is this job info correct?

Wellabe is looking for an Information Security Engineer 3 to join our team. The Information Security Engineer 3 provides senior-level security engineering expertise for the architecture, design, implementation, operation, and continuous improvement of security technologies and controls that protect the confidentiality, integrity, and availability of company systems and data.

This position provides senior technical expertise in security architecture, cloud security, vulnerability and exposure management, incident response, data protection, security monitoring oversight, and emerging technology risk assessment. The role partners with technology teams, Identity and Access Management, business stakeholders, managed security service providers, and leadership to reduce security risk while enabling business objectives.

Be successful in this role

Someone in this role will:

  • Security Architecture and Engineering
    • Architects, implements, maintains, and improves information security controls and countermeasures.
    • Conducts security architecture reviews for systems, applications, cloud services, integrations, and technology initiatives.
    • Reviews proposed technologies, software platforms, vendor solutions, integrations, and cloud services to identify security risks and recommend appropriate safeguards before implementation.
    • Evaluates technical designs and recommends controls based on company policies, technical standards, regulatory obligations, risk, and business objectives.
    • Develops security baselines, technical standards, implementation guidance, and secure configuration requirements.
    • Provides senior technical expertise and security consultation to project teams, engineers, architects, system owners, and business stakeholders.
  • Cloud Security
    • Provides senior technical expertise for the design, implementation, and assessment of security controls supporting Microsoft Azure, Microsoft 365, software-as-a-service platforms, and other approved cloud services.
    • Assesses cloud resources, storage, networking, applications, identities, integrations, and service configurations for security risk.
    • Develops and maintains cloud security baselines and configuration standards.
    • Identifies cloud security exposures and partners with technology owners to develop practical remediation or risk-reduction plans.
    • Reviews encryption, public access, logging, privileged access, network connectivity, and data protection requirements for cloud services.
    • Provides technical guidance for cloud security posture management and continuous improvement activities.
  • Identity Security
    • Partners with the Identity and Access Management team to support secure authentication, authorization, privileged access, and identity governance initiatives.
    • Applies an understanding of Microsoft Entra ID, multifactor authentication, Conditional Access policy concepts, risk-based access controls, privileged access, and Zero Trust principles when assessing security designs and incidents.
    • Assesses security risks associated with user accounts, service accounts, application identities, machine identities, credentials, and third-party access.
    • Provides security guidance and architectural recommendations without performing routine user provisioning, access fulfillment, or Identity and Access Management administration.
    • Supports investigations involving credential compromise, unauthorized access, suspicious authentication activity, and identity-based threats.
  • Security Monitoring and Detection Oversight
    • Partners with managed security service providers and security operations partners to support monitoring, detection, investigation, and response activities.
    • Provides senior technical expertise for escalated alerts, investigations, threat analysis, and response activities requiring internal security engineering support.
    • Develops and improves detection capabilities, alerting logic, dashboards, queries, reporting, and monitoring coverage.
    • Provides technical guidance for improving monitoring effectiveness, detection coverage, escalation quality, and security visibility.
    • Identifies gaps in logging, telemetry, data quality, and visibility and coordinates improvements with appropriate technology teams.
    • Assesses emerging threats and recommends updates to monitoring, detection, and defensive controls.
  • Incident Response
    • Provides senior technical expertise for escalated security events, investigations, and incident response activities.
    • Leads, supports, or provides technical expertise for investigation, containment, remediation, recovery, and post-incident review activities associated with significant security incidents.
    • Investigates unauthorized access, malicious activity, credential compromise, policy breaches, and potential data exposure.
    • Coordinates response activities with managed security service providers, technology teams, leadership, legal and privacy partners, cyber insurance providers, and third-party responders as appropriate.
    • Documents technical findings, contributing factors, corrective actions, and recommended improvements.
    • Develops and maintains incident response procedures, technical playbooks, and investigation methods.
  • Vulnerability and Exposure Management
    • Identifies, evaluates, prioritizes, and communicates vulnerabilities and security exposures affecting company systems, applications, cloud services, and data.
    • Uses business context, asset criticality, data classification, exploitability, external exposure, and compensating controls to help prioritize risk reduction.
    • Provides technical expertise and recommendations to system owners regarding remediation plans, compensating controls, and risk-reduction strategies.
    • Validates remediation activities and provides technical input for exception or risk acceptance decisions.
    • Supports vulnerability scanning, penetration testing, attack-surface reviews, control validation, and security assessments.
    • Develops reporting that communicates material exposures, remediation progress, aging, and recurring control weaknesses.
  • Application Security and DevSecOps
    • Partners with application development, infrastructure, and architecture teams to integrate security into the system development lifecycle.
    • Reviews application architecture, authentication, authorization, data handling, interfaces, application programming interfaces, and third-party components.
    • Supports secure code analysis, dependency review, secrets detection, application testing, and remediation processes.
    • Identifies opportunities to automate security checks within development and deployment workflows.
    • Provides practical technical guidance for application and software supply-chain risks.
  • Data Protection and Privacy
    • Provides technical expertise for the design, implementation, and assessment of controls related to data classification, encryption, retention, information protection, and data loss prevention.
    • Evaluates how regulated, confidential, and sensitive information is collected, stored, processed, transmitted, shared, and disposed of.
    • Partners with Information Privacy, Legal, Compliance, business owners, and technology teams to address data protection requirements.
    • Assesses security controls for information subject to HIPAA and other applicable legal, contractual, and regulatory obligations.
    • Supports investigations involving potential unauthorized disclosure or exposure of sensitive information.
  • Security Automation
    • Provides technical expertise in developing and maintaining scripts, integrations, workflows, queries, and automation that improve security monitoring, investigation, reporting, and remediation.
    • Uses appropriate scripting, query, application programming interface, source control, and orchestration technologies to improve operational efficiency.
    • Automates repeatable security processes where practical while maintaining appropriate testing, documentation, approval, and change controls.
    • Supports the integration of security checks into infrastructure-as-code and deployment processes when appropriate.
  • Security Governance, Risk, and Compliance
    • Analyzes changes in the threat, technology, regulatory, and compliance environments and evaluates their effect on organizational risk.
    • Contributes technical expertise to the development and maintenance of information security policies, standards, procedures, baselines, and guidelines.
    • Provides technical evidence and support for audits, regulatory examinations, security assessments, and control reviews.
    • Performs security risk and control assessments and recommends practical risk-treatment options.
    • Provides technical expertise supporting third-party technology, vendor security, and architecture reviews.
    • Communicates technical risks, control options, compensating safeguards, and residual risk to technical and nontechnical audiences.
  • Security Service Management
    • Provides technical oversight for managed security service providers and security technology partners.
    • Reviews monitoring effectiveness, escalation quality, service performance, detection coverage, and investigation outcomes.
    • Collaborates with providers to improve monitoring capabilities, response playbooks, detection logic, and incident handling processes.
    • Provides technical guidance to help ensure outsourced security services meet business and security requirements.
  • Artificial Intelligence and Emerging Technology Security
    • Provides technical expertise in assessing risks associated with artificial intelligence, generative artificial intelligence, automation, and emerging technologies.
    • Reviews proposed use cases, integrations, data flows, access models, and vendor capabilities for security concerns.
    • Recommends safeguards addressing sensitive data exposure, access control, logging, third-party access, and misuse risks.
    • Partners with privacy, legal, technology, and governance stakeholders to support secure and responsible adoption of emerging technologies.
  • Communication and Collaboration
    • Communicates technical risks, findings, and recommendations clearly to technical and nontechnical audiences.
    • Builds collaborative relationships across Information Security, Information Technology, business departments, and third-party providers.
    • Leads or contributes to complex security initiatives involving multiple teams and stakeholders.
    • Creates clear technical documentation, architecture diagrams, standards, procedures, investigation records, and leadership updates.
    • Provides technical mentoring and guidance to other security professionals.

Qualifications

  • Advanced knowledge of security architecture and engineering principles, cloud security concepts, vulnerability and exposure management, incident response, and data protection controls.
  • Strong knowledge of Microsoft Azure and Microsoft 365 security capabilities and experience with enterprise security monitoring, endpoint protection, cloud security posture management, and vulnerability management platforms.
  • Strong understanding of Microsoft Entra ID, multifactor authentication, Conditional Access policy concepts, privileged access, identity-related threats, and Zero Trust principles.
  • Working knowledge of application security, secure development practices, software dependencies, security automation, scripting, application programming interfaces, and infrastructure-as-code concepts.
  • Working knowledge of security and risk frameworks and the legal, contractual, privacy, and regulatory requirements applicable to regulated organizations.
  • Ability to analyze complex technical information, identify material risk, prioritize work, and recommend practical safeguards that account for security, operational, and business needs.
  • Ability to independently lead or contribute senior technical expertise to security initiatives and incident response activities.
  • Ability to communicate complex security concepts in clear language and produce accurate, defensible technical documentation.
  • Ability to collaborate across teams without assuming operational ownership of systems managed by other departments.
  • Ability to exercise sound judgment, manage competing priorities, and appropriately handle confidential information.
  • Bachelor's degree in information security, cybersecurity, computer
  • science, information systems, engineering, or a related field. A combination of education and relevant work experience may be accepted in lieu of a degree.
  • Preferred Certifications:
    • Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), a relevant Microsoft security certification, a GIAC certification, CompTIA Security+ or SecurityX, or a comparable security or cloud certification.
  • 7+ years of progressive experience in information security, security engineering, cloud security, infrastructure security, security operations, or a related technical discipline.
  • Demonstrated experience designing, implementing, operating, or assessing enterprise security controls.
  • Demonstrated experience providing senior technical leadership for complex security initiatives or investigations.
  • Experience with cloud security, vulnerability management, security monitoring, endpoint security, data protection, application security, or related security technologies.
  • Experience working with managed security service providers is preferred.
  • Experience in insurance, healthcare, financial services, or another regulated industry is preferred.
  • Experience with several of the following is preferred. Equivalent technologies and transferable experience may be considered:
    • Microsoft Azure and Microsoft 365 security capabilities, including Microsoft Defender, Microsoft Sentinel, Microsoft Purview, and Microsoft Entra ID.
    • Application control and allowlisting platforms, such as ThreatLocker or equivalent technologies.
    • Network segmentation and microsegmentation platforms, such as Illumio or equivalent technologies.
    • Endpoint detection and response and extended detection and response platforms.
    • Endpoint security technologies, including host firewalls, device control, exploit protection, and endpoint policy enforcement.
    • Security information and event management, security orchestration, and managed detection and response technologies.
    • Cloud security posture management and cloud workload protection platforms.
    • Vulnerability and exposure management platforms.
    • Data protection, data loss prevention, information protection, and encryption technologies.
    • Email, web, collaboration, and cloud application security technologies.
    • PowerShell, Kusto Query Language, application programming interfaces, security orchestration, source control, deployment pipelines, and infrastructure as code.
    • Application security, dependency analysis, secrets detection, and software supply-chain security tools.

Benefits

  • Hybrid availability
  • 401(k) with company match
  • Health insurance
  • Paid time off, holidays
  • Volunteer time off
  • Lifestyle Spending Account (LSA)
  • Paternity leave

Growth opportunities

We believe each of us has potential to grow and adapt with our business. We take your career as seriously as you do. Helping you develop your skills and talents leads to opportunities — not only for you, but also for our company. That’s why we provide:

  • LinkedIn Learning Premium access
  • CliftonStrengths® assessment and coaching
  • On-site and virtual workshops and cohorts featuring world-class content from FranklinCovey, Crucial Learning, Gallup, and more
  • Free world-class insurance acumen courses through AHIP and LOMA
  • Reimbursement and bonus opportunities for professional designations and certifications, including a tuition reimbursement program
  • Opportunities to take part in Wellabe's mentorship programs

About Wellabe

Since 1929, Wellabe has been finding solutions to help our customers protect their health and financial well-being. And we’re committed to fostering an internal culture of inclusivity, well-being, and development so each of our team members can succeed. Learn more about Wellabe’s culture of betterment by visiting wellabe.com/culture.

Wellabe is full of smart, caring, hard-working people with a broad range of talents who understand collaboration is key. We bring our best selves every day, to connect with others to solve problems, spark innovation, and bring ideas to life. Meet the team and learn what makes Wellabe a great place to work by visiting wellabe.com/news/employee-spotlights.

Our core values:

  • Be dedicated: Show unwavering commitment by proactively taking initiative, setting clear goals, and managing time effectively.
  • Be trustworthy: Take accountability for actions, navigate difficult conversations with integrity, and build strong relationships through consistent, honest behavior.
  • Be determined: Demonstrate enthusiasm and a relentless drive to overcome obstacles and achieve goals.
  • Be collaborative: Foster teamwork by being self-aware, actively listening, and effectively communicating across all levels.
  • Be open: Embrace diversity and new ideas to create an inclusive environment.
  • Be generous: Embody generosity and compassion by serving a greater purpose and helping others.
  • Be better: Commit to continuous improvement and adapt effectively to change.
  • Be well: Prioritize physical and mental health, manage stress, and demonstrate emotional intelligence.

Similar jobs

Apply for this job