Security Engineer 2
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Oct 2, 2026
SCHEDULE : Full-time; Exempt . Typical hours are Monday-Friday (8:00 am – 5:00 pm) LOCATION: Hills Bank Campus / Hybrid Remote Option BENEFITS: Our employees are our most valuable assets, so we invest in them with a comprehensive and competitive benefits package. Our philosophy of taking care of the customer extends to taking care of our employees so that they, in turn, can take good care of themselves and their families. Join Hills Bank and let us surprise you with even more perks! SCOPE: The Security Engineer 2 is a senior security practitioner responsible for engineering, operating, and continuously improving the Bank's cybersecurity controls. The role combines hands-on security operations, incident response, detection engineering, vulnerability management, identity and access security, endpoint and network protection, cloud security, data protection, automation, and security architecture. This position serves as a Tier 2 and Tier 3 escalation resource and translates threat, risk, compliance, and audit requirements into practical control improvements. The Security Engineer 2 provides clear, risk-based recommendations to technical teams and leadership, mentors junior staff, and may lead security workstreams, technical evaluations, and response activities. ACCOUNTABILITIES: Engineer, operate, and continuously improve enterprise security capabilities across SIEM, XDR/EDR, endpoint, network, identity, email, cloud, data protection, vulnerability management, and privileged access platforms. Monitor, investigate, and respond to security incidents by assessing scope and impact, preserving evidence, and coordinating containment, eradication, recovery, and stakeholder communication. Serve as a Tier 2 and Tier 3 escalation resource and participate in assigned on-call response for time sensitive security events. Develop, tune, and automate detection and response capabilities, including security analytics, alerts, queries, enrichment, evidence collection, response workflows, and reporting to improve coverage, accuracy, and operational efficiency. Document incidents and lessons learned, and use exercises and after-action reviews to improve response procedures and plans. Lead vulnerability and exposure management activities, including assessment, risk-based prioritization, remediation coordination, exception management, retesting, and validation across technology environments. Conduct security architecture and design reviews for projects, technology changes, products, cloud services, and vendor integrations. Define and document practical security requirements, risks, and control recommendations aligned with business needs and risk tolerance. Apply zero trust, least privilege, and strong authentication principles to control access to systems, applications, and data. Use defense in depth and secure-by-design practices to embed effective controls throughout the technology lifecycle. Implement network, system, and application segmentation to reduce exposure, restrict unauthorized access, and limit the impact of security events. Incorporate resilience and recovery requirements into new and existing environments to support continuity and timely restoration following a disruption. Develop and maintain secure configuration standards and hardening baselines across endpoints, servers, networks, cloud services, applications, and security tools. Assess and improve security controls, posture management, and logging in Microsoft 365, Azure, and other approved cloud and software-as-a-service environments. Integrate security platforms with asset management, identity, ticketing, and change management processes to enable coordinated visibility, efficient investigations and response, and effective security lifecycle management. Support data classification, encryption, data loss prevention, retention, and secure information management, partnering with business and control owners to implement data protection requirements. Support penetration testing, control validation, and other authorized security testing. Analyze results and recommend corrective actions. Perform security risk assessments, control testing, and compliance reviews. Collect evidence for regulatory examinations, audits, and independent assessments. Provide technical input to third-party risk reviews, contracts, solution assessments, and supply chain security evaluations. Develop, deliver, or support security awareness training for Bank employees on relevant threats, policies, controls, and secure practices. Use programming languages such as PowerShell, Python, KQL, and other approved methods to automate repeatable security engineering and operational work. Communicate security posture, material findings, residual risk, remediation status, trends, metrics, and prioritized recommendations to technical teams and leadership. Evaluate security technologies and services through requirements analysis, proof of concepts, risk assessments, total cost analysis, implementation planning, and operational supportability reviews. Maintain accurate security procedures, playbooks, standards, technical documentation, inventories, records, and operational metrics. Support third-party security reviews and security awareness activities within assigned areas of responsibility. Review artificial intelligence use cases for security, data protection, access, monitoring, and oversight requirements. Mentor junior staff, share technical knowledge, and lead assigned security workstreams and response activities. Contribute technical expertise to security strategy, architecture roadmaps, investment priorities, and continuous improvement initiatives. Perform other duties as assigned. EDUCATION AND SPECIAL REQUIREMENTS/PREFERENCES: Bachelor's degree in cybersecurity, information technology, computer science, engineering, or a related field is preferred. An equivalent combination of education, relevant experience, and industry certifications may be considered. Five or more years of progressive information technology experience, including at least two years of hands-on cybersecurity engineering or operations and demonstrated experience investigating security events and administering enterprise security controls. Working knowledge of Windows and Linux, networking, identity and access management, endpoint security, cloud security, audit/logging, vulnerability management, and incident response. Enterprise security technology experience such as Microsoft Defender XDR, Sentinel, Entra ID, Intune, Purview, Azure security, firewalls, vulnerability management platforms, network monitoring, and privileged access tools. Ability to use PowerShell, Python, Kusto Query Language, APIs, regular expressions, or similar scripting and query technologies. Knowledge of recognized frameworks such as NIST CSF, CIS Controls, MITRE ATT&CK, and financial services regulatory guidance are preferred. Relevant role-aligned certifications are preferred, along with excellent analytical, troubleshooting, documentation, presentation, and interpersonal skills. EQUAL OPPORTUNITY EMPLOYER/VETERANS/DISABILITY Full Job Description Apply now How would you like to verify your identity? Continue with phone Verify with a one-time text code Continue with email Verify with a one-time code Powered by iSolved Talent Acquisition Resources E-Verify Participation Poster (English & Spanish)