Logo
Patelco Credit Union

Senior Information Security Engineer

Patelco Credit Union, Dublin, California, United States, 94568

Save Job

About Patelco Credit Union Patelco Credit Union is a not-for-profit credit union with a purpose to build financial health and wellbeing for our members. Since 1936, Patelco has grown from $500 in assets to over $9 billion in assets and is the 7th largest credit union in California with branches throughout Northern California. We are here for our members throughout all their stages of life. Meeting them with the products and services to help them plan purposefully for their futures and to secure our life-long partnership as their trusted financial advocate. As one team, we are all committed to delivering service, empowering financial literacy, creating products, and providing new technology for our members. We believe that work should be rewarding, challenging, and enjoyable. We're dedicated to creating a positive and supportive culture where our team members can thrive. If you're looking to use your skills and knowledge to make a difference in our members' lives, Patelco could be the perfect fit for you. Overview Patelco's Sr. Information Security Engineer (Detection Engineering) will be leading the design, tuning and optimization of the Credit Union's detection stack, helpful for safeguarding our networks and member data. This role is deeply technical and cross-functional, responsible for designing, implementing, and ensuring control effectiveness of system security, information security controls, and processes to protect Patelco data, infrastructure and applications. You will be responsible for care and feeding of detection platforms ( e.g. EDR, NDR), SIEM engineering , and SOAR automation . You will apply Threat Intelligence, Security Architecture, and adversary simulation knowledge to mature our detection capabilities in alignment with the NIST CSF. Responsibilities Essential Duties Own the engineering and tuning of endpoint detection & response, network detection & response platforms Drive advancement and growth of detection and automation initiatives Build, test, and deploy behavioral detections solutions aligned to MITRE ATT&CK TTPs Continuously improve detection efficacy using business context and real-world feedback Engineer and optimize detection pipelines in SIEM Author comprehensive runbooks, write automation scripts, and build SOAR capabilities to improve response times Build and maintain enrichment workflows and automated response playbooks using SOAR Create, maintain and manage a library of automated playbooks to address new threats and tactics employed by attackers Ensure telemetry normalization, parsing and alert fidelity across data sources Operationalize threat intelligence into actionable detection rules, dashboards, and response workflows. Lead red/blue teaming efforts to test detections against real-world scenarios. Integrate external and internal threat feeds to strengthen signal correlation Apply STRIDE & DREAD methodologies to model risks associated with applications, systems and emerging threats Recommend and document compensating controls for identified risks Partner closely with Security Operations, Governance Risk & Compliance (GRC), and wider Engineering teams to enhance detection coverage Document information security design and architecture Mentor and cross-train staff members in the areas of subject matter expertise Provide engineering support to Technology Operations implementing industry standard benchmarks and evaluation activities Other duties as assigned Functional Competencies Strong knowledge of the Cyber Threat landscape and ability to articulate and incorporate understanding of major threat categories, motivations and intent of adversaries Demonstrated knowledge and practical application of MITRE ATT&CK Experience in at least one programming language (Python, Go, C, C++) or deep expertise using low-code automation tools or SOAR Platforms Experience building and scaling observability solutions Experience with Adversary emulation, continuous detection improvement and operational excellence Must be able to collaborate with other teams Clear verbal and written communication will be required Qualifications 5 + years Information Security 3+ years focused on Detection Engineering, including EDR, NDR, SIEM, SOAR tooling Demonstrated knowledge and practical application of MITRE ATT&CK, STRIDE & DREAD models Strong scripting skills (Python, YAML etc.) and experience with data parsing and log normalization Industry certifications such as CISSP , GCTI, GCIA, GDSA or equivalent preferred Physical Activites/Requirements Sitting requirements - Prolonged periods of sitting at a desk and working on a computer. Role is based in Dublin, HQ Patelco Credit Union is an EO Employer - M/ F/ Veteran/ Disability Target Base Pay $132,197/year to $165,255/year Compensation at Patelco Please note that the salary information is a general guideline only. Patelco Credit Union considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as market and business considerations when extending an offer. We offer a competitive total rewards package including a wide range of medical, dental, vision, financial, and other benefits. We Offer Physical Health: Exceptional Medical, Dental, Vision, and Life Insurance benefits Onsite fitness center at HQ and rewards for completing wellness related activities Financial Health: Competitive compensation packages with bonus opportunity 401(k) with 3% Safe Harbor and 5% employer match Discounts on loan products Tuition reimbursement Emotional Health: Employee Assistance Program (EAP) PTO for part-time and full-time positions Paid holidays Personal Development: On-the-job training and skills development Internal transfer opportunities for career growth Volunteer work Flexible work arrangements available for specific positions Patelco Credit Union is an Equal Opportunity Employer including individuals with disabilities and protected veterans 5 + years Information Security 3+ years focused on Detection Engineering, including EDR, NDR, SIEM, SOAR tooling Demonstrated knowledge and practical application of MITRE ATT&CK, STRIDE & DREAD models Strong scripting skills (Python, YAML etc.) and experience with data parsing and log normalization Industry certifications such as CISSP , GCTI, GCIA, GDSA or equivalent preferred Physical Activites/Requirements Sitting requirements - Prolonged periods of sitting at a desk and working on a computer. Role is based in Dublin, HQ Patelco Credit Union is an EO Employer - M/ F/ Veteran/ Disability Essential Duties Own the engineering and tuning of endpoint detection & response, network detection & response platforms Drive advancement and growth of detection and automation initiatives Build, test, and deploy behavioral detections solutions aligned to MITRE ATT&CK TTPs Continuously improve detection efficacy using business context and real-world feedback Engineer and optimize detection pipelines in SIEM Author comprehensive runbooks, write automation scripts, and build SOAR capabilities to improve response times Build and maintain enrichment workflows and automated response playbooks using SOAR Create, maintain and manage a library of automated playbooks to address new threats and tactics employed by attackers Ensure telemetry normalization, parsing and alert fidelity across data sources Operationalize threat intelligence into actionable detection rules, dashboards, and response workflows. Lead red/blue teaming efforts to test detections against real-world scenarios. Integrate external and internal threat feeds to strengthen signal correlation Apply STRIDE & DREAD methodologies to model risks associated with applications, systems and emerging threats Recommend and document compensating controls for identified risks Partner closely with Security Operations, Governance Risk & Compliance (GRC), and wider Engineering teams to enhance detection coverage Document information security design and architecture Mentor and cross-train staff members in the areas of subject matter expertise Provide engineering support to Technology Operations implementing industry standard benchmarks and evaluation activities Other duties as assigned Functional Competencies Strong knowledge of the Cyber Threat landscape and ability to articulate and incorporate understanding of major threat categories, motivations and intent of adversaries Demonstrated knowledge and practical application of MITRE ATT&CK Experience in at least one programming language (Python, Go, C, C++) or deep expertise using low-code automation tools or SOAR Platforms Experience building and scaling observability solutions Experience with Adversary emulation, continuous detection improvement and operational excellence Must be able to collaborate with other teams Clear verbal and written communication will be required #J-18808-Ljbffr