Cornerstone Capital Bank Logo

Cornerstone Capital Bank

Sr IT Security Engineer

Posted 2 Hours Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
The Senior IT Security Engineer strengthens cybersecurity across architecture reviews, AI and emerging technology assessments, IAM governance, vulnerability management, third-party risk, security assurance, incident response, phishing simulations, automation, and regulatory compliance. The role validates security controls, supports remediation, develops risk metrics and reporting, oversees identity platforms, and partners with technology, business, audit, compliance, procurement, and vendors in a regulated banking environment.
The summary above was generated by AI

 

Cornerstone Capital Bancorp, Inc., headquartered in Houston, is a Texas-based financial services company dedicated to helping families, businesses, and communities thrive. Through its primary subsidiary, Cornerstone Capital Bank, the organization operates a community and business banking franchise alongside a premier national home lending, servicing, and home insurance platform-based financial services company dedicated to helping families, businesses, and communities thrive. 

Guided by a core Mission, Vision and Convictions statement, Cornerstone operates 17 full-service banking locations across major Texas markets and more than 150 mortgage offices nationwide.  The company has served nearly 700,000 customers through its family of brands, including Cornerstone Home Lending, Roscoe Bank, Peoples Bank, Cornerstone Servicing, and Cornerstone Insurance. Supported by 1,600 team members, Cornerstone is consistently recognized as a Fortune-certified Great Place to Work® and a Top Workplace.  

Formed through the combination of Cornerstone Home Lending and The Roscoe State Bank, Cornerstone brings more than a century of experience and is the highest-capitalized new bank in Texas history. 

We honor God by using our talents to make a positive difference in the lives of our Team Members, Clients, Shareholders, Communities, and the People who provide services to us.

 

Who we are looking for:

The Senior Security Engineer serves as a senior cybersecurity resource responsible for supporting and enhancing the organization's security program across security architecture, emerging technology and AI reviews, Identity and Access Management (IAM) governance, vulnerability management, and third-party security. Reporting directly to the Chief Information Security Officer (CISO), this role partners with technology and business stakeholders to identify, assess, mitigate, and validate cybersecurity risks and security controls while ensuring alignment with organizational security objectives and regulatory requirements. 

The role also supports security assurance, control effectiveness, remediation validation, security engineering, automation, and continuous improvement initiatives designed to strengthen the organization's overall security posture. Working closely with the Head of IAM and other security and technology leaders, the Senior Security Engineer provides oversight and verification of security controls, conducts security assessments, and supports cybersecurity risk management, compliance, and resilience efforts within a highly regulated banking environment. 

The ideal candidate brings strong technical expertise, sound risk-based judgment, a collaborative mindset, and the ability to translate cybersecurity requirements into practical and sustainable solutions. Experience within financial services is preferred, including familiarity with FFIEC guidance, NIST Cybersecurity Framework principles, and regulatory examination preparedness 

 

What you'll do:

    • General Responsibilities & Expectations
    • Security Assurance & Risk Management – Assess security controls, identify risks and gaps, and support remediation and validation activities to promote effective and sustainable security practices.  
    • Security Engineering & Automation – Leverage security technologies, engineering practices, and automation to strengthen controls, improve efficiency, and reduce reliance on manual processes.  
    • Security Monitoring & Reporting – Support security metrics, reporting, and monitoring activities to provide visibility into security posture, control effectiveness, and emerging risks.  
    • Incident Response & Resilience – Participate in cybersecurity incident response, investigations, exercises, lessons learned, and initiatives that strengthen organizational resilience.  
    • Security Governance & Standards – Contribute to the development and maintenance of security standards, procedures, and technical guidance aligned with business objectives, regulatory expectations, and industry practices.  
    • Cross-Functional Partnership – Serve as a senior security advisor and collaborate with Technology, business, Risk, Compliance, Audit, and other stakeholders to identify and address cybersecurity risks. 
    • Phishing - Lead the enterprise phishing awareness program by conducting monthly phishing simulation campaigns, tracking and reporting key performance metrics, identifying user risk trends, and driving continuous improvement in employee cybersecurity awareness and resilience. 

    • Security Architecture, Emerging Technology & AI Reviews
    • Serve as a trusted security advisor for enterprise technology initiatives, strategic projects, and business innovation efforts. 
    • Conduct security architecture reviews for applications, infrastructure, cloud services, SaaS platforms, AI-enabled solutions, and third-party technologies. 
    • Partner with architects, developers, engineers, project managers, and business stakeholders to identify, mitigate, and validate security requirements throughout solution design, implementation, and ongoing operation. 
    • Review proposed solutions for secure authentication, authorization, encryption, data protection, logging, monitoring, resiliency, and recovery requirements. 
    • Assess emerging technologies, including artificial intelligence (AI), generative AI, machine learning platforms, and AI-enabled business solutions, to ensure appropriate security controls, governance requirements, and data protection measures are established and maintained throughout the technology lifecycle. 
    • Evaluate AI-related risks including unauthorized data exposure, excessive permissions, third-party AI integrations, sensitive data protection, model governance considerations, and regulatory compliance implications. 
    • Provide guidance aligned with Zero Trust principles, secure-by-design methodologies, banking regulatory expectations, and industry best practices. 
    • Participate in AI governance discussions and provide security recommendations for the adoption of emerging technologies. 
    • Support the development, maintenance, and continuous improvement of security standards, architectural guidance, and technology control requirements. 
    • Validate that key security requirements and controls are appropriately implemented and operating as intended. 
    • Participate in vendor evaluations, technology assessments, and project planning activities to ensure security requirements are incorporated early in the project lifecycle. 

    • IAM – Governance, Oversight & Verification
    • Primarily support the organization's Identity and Access Management (IAM) program in partnership with the Head of IAM. 
    • Provide second-line security oversight and independent verification of key cybersecurity controls, including IAM, privileged access, authentication, vulnerability management, and third-party security controls. 
    • Administer and oversee identity lifecycle processes, including onboarding, transfers, role changes, and offboarding activities. 
    • Support and verify role-based access controls (RBAC), privileged access controls, and segregation of duties requirements. 
    • Support Privileged Access Management (PAM) solutions and privileged account governance activities. 
    • Manage and support authentication technologies including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and identity federation. 
    • Perform independent security control validation and testing to assess design effectiveness, implementation, and sustained operating effectiveness. Validate remediation activities end-to-end, including confirmation that changes have been implemented across affected systems, processes, and procedures. 
    • Conduct periodic user access reviews and privileged access reviews. 
    • Support Microsoft Entra ID, Active Directory, and related identity platforms. 
    • Assist with audit requests, regulatory examinations, and control assessments related to identity and access management. 
    • Support the tracking, validation, and closure of cybersecurity audit, assessment, and control findings, including validation that corrective actions address the underlying control deficiency and not solely the individual exception identified 
    • Develop and maintain cybersecurity metrics, key risk indicators (KRIs), and key performance indicators (KPIs) to measure control effectiveness, remediation progress, risk exposure, and security program maturity. 
    • Prepare management-level reporting on cybersecurity risks, control effectiveness, remediation status, and emerging threats. 
    • Identify opportunities to improve identity governance, automation, operational efficiency, and security effectiveness. 

    • Vulnerability Management & Third-Party Security
    • Lead enterprise vulnerability management activities, including identification, risk-based prioritization, remediation tracking, validation, and reporting across infrastructure, cloud, applications, and technology environments. 
    • Establish and apply risk-based vulnerability prioritization using asset criticality, business impact, exploitability, threat intelligence, exposure, and the presence of compensating controls. 
    • Partner with infrastructure, cloud, application, engineering, and technology teams to drive timely remediation of vulnerabilities and reduce organizational exposure. 
    • Review and assess findings from vulnerability assessments, penetration tests, red team exercises, security assessments, and other technical security testing activities. 
    • Monitor remediation performance, vulnerability aging, remediation SLAs, recurring findings, and risk trends; provide meaningful metrics and reporting to security leadership and governance committees. 
    • Manage vulnerability-related exceptions, risk acceptances, and compensating controls, ensuring risks are appropriately documented, reviewed, and tracked through resolution. 
    • Incorporate threat intelligence and emerging threat activity into vulnerability prioritization and remediation decisions, with heightened focus on actively exploited and internet-facing vulnerabilities. 
    • Participate in third-party security reviews, vendor risk assessments, and ongoing security due diligence for prospective and existing vendors. 
    • Evaluate the security posture, control environment, resilience, and risk management practices of third parties, with increased scrutiny for critical vendors, technology providers, and vendors that process sensitive or customer information. 
    • Assess third-party security controls, technical safeguards, vulnerability management practices, incident response capabilities, data protection measures, and other cybersecurity risks. 
    • Support ongoing third-party monitoring and reassessment throughout the vendor lifecycle, including onboarding, periodic reviews, significant changes, incidents, and offboarding. 
    • Identify and assess third-party and technology supply-chain risks, including dependencies that may introduce material cybersecurity or operational risk. 
    • Partner with Vendor Management, Procurement, Legal, Privacy, Compliance, and business stakeholders to ensure cybersecurity risks are incorporated into vendor selection, contracting, ongoing oversight, and risk decisions. 
    • Support continuous improvement of vulnerability management and third-party risk management processes, including automation, workflow optimization, metrics, governance, and alignment with enterprise security objectives 

     

    What you’ll need to be successful: 

    • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field preferred.   
    • Experience working within banking, financial services, mortgage lending, fintech, or other highly regulated industries. 
    • Working knowledge of FFIEC guidance, banking regulatory expectations, and cybersecurity requirements applicable to financial institutions. 
    • Familiarity with FDIC examinations, internal audits, external audits, and cybersecurity control assessments. 
    • Strong understanding of the NIST Cybersecurity Framework (CSF), CIS Controls, and risk-based cybersecurity programs. 
    • Familiarity with AI governance, AI risk management concepts, and the secure adoption of emerging technologies. 
    • 5+ years of experience in cybersecurity, information security, or security engineering. 
    • Experience supporting Identity and Access Management programs, processes, and technologies. 
    • Experience conducting security architecture reviews and technical risk assessments. 
    • Experience managing or supporting enterprise vulnerability management programs. 
    • Experience conducting vendor security reviews and third-party security assessments. 
    • Experience with Microsoft Entra ID, Active Directory, Microsoft 365 security technologies, and cloud-based platforms. 

     

    Preferred Certifications  

    • CISSP  
    • CISA 
    • CompTIA Security+ 
    • ISC2 Certified in Cybersecurity (CC) 
    • Microsoft SC-900 Security, Compliance, and Identity Fundamentals 
    • Microsoft AZ-900 Azure Fundamentals 
    • Microsoft SC-300 Identity and Access Administrator Associate 
    • Additional cybersecurity, cloud security, or identity-focused certifications preferred. 

     

     Physical demands:

    The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.   

    • Occasional evening and weekend work to meet deadlines.   
    • Sitting for extended periods of time   
    • Dexterity of hands and fingers to operate a computer keyboard, mouse, and to handle other computer components.   
    • Ability to participate in training sessions, presentations, and meetings.   
    • Ability to lift 30-40 lbs.  This job will require picking up and moving equipment.    
    • Ability to travel to other locations as needed.   

    While performing the duties of this job, the employee is regularly required to talk or listen. The employee frequently is required to stand; walk; use hands to finger, handle or feel; and reach with hands and arms.  Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions of the job. The noise level in the work environment is usually quiet to moderate.   

    Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
    This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

    Cornerstone Capital Bank Centennial, Colorado, USA Office

    6025 S. Quebec Street, Suite 110, Centennial, United States, 80111

    Cornerstone Capital Bank Colorado Springs, Colorado, USA Office

    1730 Chapel Hills Drive, Suite 100, Colorado Springs, United States, 80920

    Cornerstone Capital Bank Delta, Colorado, USA Office

    102 Grand Avenue, Suite B, Delta, United States, 81416

    Cornerstone Capital Bank Denver, Colorado, USA Office

    50 South Steele Street, Suite 765, Denver, United States, 80209

    Cornerstone Capital Bank Englewood, Colorado, USA Office

    385 Inverness Parkway, Suite 380, Englewood, United States, 80112

    Cornerstone Capital Bank Fort Collins, Colorado, USA Office

    3538 John F. Kennedy Parkway, Suite 1, Fort Collins, United States, 80525

    Cornerstone Capital Bank Glenwood Springs, Colorado, USA Office

    817 Colorado Avenue, Suite 102, Glenwood Springs, United States, 81601

    Cornerstone Capital Bank Greeley, Colorado, USA Office

    6500 West 29th Street, Suite 230, Greeley, United States, 80634

    Cornerstone Capital Bank Greenwood Village, Colorado, USA Office

    5340 S. Quebec Street, Suite 375N, Greenwood Village, United States, 80111

    Cornerstone Capital Bank Lakewood, Colorado, USA Office

    390 Union Blvd, Suite 320, Lakewood, United States, 80228

    Cornerstone Capital Bank Longmont, Colorado, USA Office

    1925 Pike Road, Suite 201, Longmont, United States, 80501

    Cornerstone Capital Bank Loveland, Colorado, USA Office

    2975 Ginnala Drive, Suite 200, Loveland, United States, 80538

    Cornerstone Capital Bank Montrose, Colorado, USA Office

    301 E. Main Street, Montrose, United States, 81401

    Cornerstone Capital Bank Pueblo, Colorado, USA Office

    503 N. Main Street, Suite 6, Pueblo, United States, 81003

    Cornerstone Capital Bank Rifle, Colorado, USA Office

    829 Railroad Avenue, Suite A, Rifle, United States, 81650

    Cornerstone Capital Bank Steamboat Springs, Colorado, USA Office

    326 Oak Street, Steamboat Springs, United States, 80487

    Similar Jobs

    22 Days Ago
    Remote
    United States
    Senior level
    Senior level
    Healthtech • Software
    Owns the company-wide IT and cybersecurity program, including SOC 2 compliance, cloud security, penetration-test remediation, business continuity testing, endpoint management, access controls, onboarding and offboarding, AI security governance, vendor reviews, security training, incident response, and employee IT support. The role partners with engineering, HR, Finance, leadership, auditors, and healthcare customers while managing security across AWS, Heroku, Cloudflare, Google Workspace, GitHub, and related tools.
    Top Skills: 2FaAWSClaudeCloudflareCspmEdrGitGoogle WorkspaceGrcHerokuIamMcp ServersMdmRipplingSIEMSoc 2SsoVantaXdr
    23 Days Ago
    Remote
    Michigan, USA
    121K-191K Annually
    Senior level
    121K-191K Annually
    Senior level
    eCommerce • Retail • Sales
    Lead application security initiatives across the SDLC: perform threat modeling, secure design reviews, remediation guidance, third-party pen test management, develop security tooling, advise leadership on risks, mentor teammates, and improve application security maturity and training.
    Top Skills: C#C++Client-ServerCloud InfrastructureContainerizationDatabasesJavaMicroservicesNative MobileOwasp Top 10Penetration TestingSingle Page Applications
    18 Minutes Ago
    Remote
    United States
    180K-240K Annually
    Entry level
    180K-240K Annually
    Entry level
    Fintech • Financial Services
    Architects and develops AI-powered systems, tools, agents, backend services, APIs, and experimentation frameworks using foundational AI models. Integrates AI capabilities with microservices, AWS, Snowflake, and complex data systems while ensuring scalability, reliability, and maintainability. Translates business problems into technical solutions, prototypes AI applications, collaborates with product and engineering teams, evaluates emerging AI technologies, and documents system designs and integration patterns.
    Top Skills: APIsAWSAws BedrockClaudeContainer OrchestrationGoHugging FaceLangchainMicroservicesOpenaiPythonRubySnowflakeVector Databases

    What you need to know about the Colorado Tech Scene

    With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

    Key Facts About Colorado Tech

    • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
    • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
    • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
    • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
    • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
    • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account