Senior Level Information Security Engineer Jobs
Senior level information security engineer jobs place experienced professionals in charge of security architecture decisions, risk strategy, and the cross-functional teams and programs that execute them. Roles are concentrated across Technology & Software, Insurance, and Electronics & Hardware, with a mix of on-site, remote, and hybrid settings, and employers like Ryder System, SentiLink, and MTSI hiring at this level now.
Find JobsOverview
Showing 5 of 80+ Senior Level Information Security Engineer jobs











INTRODUCTION
Stellantis Financial Services (SFS) is the new captive finance company for one of the world's leading automakers and a mobility provider with iconic brands including Abarth, Alfa Romeo, Chrysler, Citroën, Dodge, DS Automobiles, Fiat, Jeep®, Lancia, Maserati, Opel, Peugeot, Ram, Vauxhall, Free2move and Leasys. Our exciting growth provides opportunities to advance your career as we successfully lead products and services from a small to midsize company in just a few years. Join our world class team and culture and contribute to our core mission which is enhancing our customer's experience.
Position Summary
The Director of Risk Management and Information Security supports the Chief Risk Officer in building, maintaining, and continuously enhancing the bank's Enterprise Risk Management (ERM) framework. This role serves as a key advisor and subject matter expert across risk disciplines including credit risk, operational risk, compliance risk, liquidity risk, market risk, and strategic risk, leading risk identification, assessment, monitoring, and reporting activities across the organization to help ensure risks are managed within the bank's risk appetite and in conformance with applicable regulatory requirements. Additionally, this role will serve as the bank's designated Information Security Officer, responsible for developing, implementing, and overseeing the bank's information security program in accordance with GLBA Safeguards requirements and applicable regulatory guidance. The role works closely with first-line business units, Finance, Compliance, Legal, Internal Audit, and senior leadership to foster a strong risk culture and provide actionable risk intelligence that supports sound decision-making across the bank, with strong potential for growth as the risk function expands.
Essential Duties And Responsibilities
- Support the Chief Risk Officer (CRO) in maintaining and evolving the bank's Enterprise Risk Management (ERM) framework, including risk governance, risk appetite, policies, taxonomy, and overall Risk function continuity.
- Serve as a strategic partner to the CRO, representing the Risk function at management and Board-level governance committees while acting as a risk subject matter expert who provides effective challenge and trusted advisory support to first-line business partners in accordance with the bank's three-lines-of-defense model.
- Develop, maintain, and present comprehensive risk reporting to senior management, the Board of Directors, and applicable Board committees (e.g., Risk Committee, Audit Committee), including key risk indicators (KRIs), risk appetite metrics, and emerging and external risk assessments informed by regulatory developments, industry trends, peer bank benchmarking, and macroeconomic conditions.
- Lead and coordinate the bank's risk and control self-assessment (RCSA) process across all business lines, including consumer lending, small business lending, deposits, and operations, ensuring risks are identified, rated, and mapped to controls.
- Oversee second-line credit risk management activities, including review of credit policy exceptions, portfolio concentration analysis, loan-level risk monitoring, and coordination with the credit and underwriting teams on risk-related matters for consumer and small business portfolios.
- Manage the bank's second-line operational risk program, including incident and loss event tracking, root cause analysis, operational risk appetite monitoring, and coordination on business continuity and third-party risk management activities.
- Serve as the bank's designated Information Security Officer (ISO), responsible for the enterprise information security program and second-line cybersecurity risk oversight, including governance, cybersecurity risk assessments, security awareness training, cyber incident response coordination, threat and vulnerability escalation, regulatory readiness, framework alignment (e.g., NIST Cybersecurity Framework), and periodic reporting to senior management and the Board regarding program effectiveness and material cyber risks.
- Partner with Compliance and Legal to monitor and assess regulatory and compliance risk, including tracking regulatory changes, supporting exam management, ensuring timely remediation of regulatory findings, audit observations and interacting with examiners as needed.
- Support the bank's model risk management, stress testing, scenario analysis, and capital adequacy assessment activities, including model inventory governance and validation oversight, performance monitoring, and collaboration with Finance on capital planning, while serving as the primary liaison for independent consultants and third parties engaged for model validation, independent testing, or specialized risk assessments.
- Conduct new product and initiative risk reviews, evaluating inherent risks associated with proposed products, services, geographies, or process changes, and providing risk-based recommendations prior to approval and launch.
- Perform other duties as assigned by the Chief Risk Officer in support of the bank's risk management objectives and strategic plan.
Qualifications And Competencies Required
- Minimum seven (7) years of progressive risk management experience in the financial services industry, with a strong preference for experience at a bank or bank holding company.
- Minimum three (3) years of information security, cybersecurity, or technology risk experience at a regulated financial institution; prior experience serving as, or directly supporting, an Information Security Officer or CISO strongly preferred.
- Demonstrated experience in two or more of the following risk disciplines: credit risk, operational risk, compliance/regulatory risk, model risk, or enterprise risk management.
- Experience with consumer lending products (e.g., auto loans, personal loans, credit cards) and/or small business lending, including understanding of associated credit risk and regulatory requirements (e.g., ECOA, TILA, FCRA, CRA).
- Prior experience working directly with bank regulators, including supporting regulatory examinations and responding to supervisory findings.
- Experience developing and presenting risk reports, dashboards, and committee materials to senior management and Board-level audiences.
Education
- Bachelor's degree in Finance, Accounting, Economics, Business Administration, Mathematics, or a related field
Overtime required – N/A
Travel 0-10% - as required on an as needed basis.
- Must have reliable transportation and live within a commutable distance to one of the following cities: Salt Lake City, UT.
Qualifications Preferred
- Master's degree (MBA, MS in Finance, or MS in Risk Management) preferred.
- Relevant professional certification(s) such as Certified Risk Manager (CRM), Financial Risk Manager (FRM), Professional Risk Manager (PRM), CIA/CPA, or information security certifications such as CISSP, CISM, or CRISC.
- Experience building or contributing to the development and growth of risk management frameworks, policies, governance structures, and supporting infrastructure within a growing organization is preferred.
- Prior experience supporting or leading capital adequacy assessments or stress testing programs at a community or mid-size bank.
- Experience with captive auto finance, indirect lending, or related auto financial services products, and familiarity with auto-related consumer lending risk dynamics and market trends.
- Familiarity with digital banking risk considerations as the bank continues to grow its product and distribution footprint.
Physical Demands
Work Environment
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. The noise level in the work environment is usually moderate.
Work Schedule
- This position requires the ability to work various times to accommodate business needs. Typically, between the hours of 8AM-6PM Monday through Friday and on weekends as needed.
Stellantis Financial Services, Inc (SFS) is an equal opportunity employer and is committed to providing its employees with an environment that is free of harassment, discrimination, and intimidation. It is the policy of SFS to comply with all applicable employment laws and regulations and to provide equal opportunity for all qualified persons and to not discriminate against any employee or applicant for employment because of race, color, religion, sex, age, national origin, disability, pregnancy, sexual orientation, veteran status, gender identity or expression, change of sex, and/or transgender status or any protected status.
Candidates must possess authorization to work in the United States. This policy applies to recruitment and placement, promotion, training, transfer, retention, rate of pay and all other terms and conditions of employment. Employment and promotion decisions will be based solely on merit, ability, achievement, experience, conduct and other legitimate business reasons.
See All 80 Senior Level Information Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsSenior Level Information Security Engineer Job Market
Who's Hiring
- Ryder System19

- SentiLink5

- MTSI3

- AMERICAN SYSTEMS3

- Apple2

Top Industries Hiring
- Technology & Software
- Insurance
- Electronics & Hardware
- Education
- Aerospace & Defense
Senior Level Information Security Engineer Jobs: Frequently Asked Questions
How do I get a senior level information security engineer job?
Employers at this level look for professionals who have owned security outcomes end to end, not just contributed to them. Demonstrating that you have led threat modeling, architected security controls, or driven incident response across an organization gives you a clear edge. Certifications like CISSP or CISM reinforce your credibility, but a portfolio of decisions you owned and the results they produced is what sets candidates apart.
Which companies hire senior level information security engineers?
Companies hiring senior level information security engineers right now include Ryder System, SentiLink, and MTSI, based on current listings on Migrate Mate as of September 2026. Hiring at this level comes from large enterprises with mature security programs, federal contractors, and technology companies building or scaling dedicated security functions.
Are there remote senior level information security engineer jobs?
Yes, though availability varies by employer and role scope. About 43% of senior level information security engineer openings are remote or hybrid as of September 2026, reflecting the strong demand for experienced security professionals across distributed organizations. Roles requiring hands-on infrastructure access or government clearance are more likely to require on-site presence.
What makes an information security engineer role senior level?
A senior level information security engineer role is defined by ownership and scope. You are expected to set security direction for systems or programs, evaluate and resolve complex threats independently, and mentor junior engineers rather than receive mentorship. These roles involve cross-functional influence, accountability for security outcomes across the organization, and technical depth that goes well beyond implementing solutions others have designed.
Which industries hire the most senior level information security engineers?
Senior level information security engineer roles concentrate in Technology & Software, Insurance, and Electronics & Hardware, based on current listings on Migrate Mate as of September 2026. These sectors drive demand because they operate under strict regulatory requirements, manage sensitive data at scale, or maintain critical infrastructure that requires experienced security leadership to protect.