This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Security Risk & Controls Engineer in United States.
This role offers an exciting opportunity to lead and maintain the health of a dynamic enterprise security program. The Security Risk & Controls Engineer will design, implement, and automate risk controls across cloud, identity, network, endpoint, data, and application domains. This position blends hands-on technical expertise with governance, risk, and compliance rigor, partnering with cross-functional teams to translate regulatory and business requirements into durable, auditable controls. The ideal candidate thrives in a fast-paced environment, values automation and continuous improvement, and contributes to building a proactive, measurable security culture.
- Accountabilities
- Define, document, and maintain an enterprise control library aligned with regulatory frameworks (FFIEC IT Examination Handbooks, GLBA, SOX, PCI-DSS).
- Collaborate with technical control owners to implement automated, policy-aligned processes and “policy as code” guardrails.
- Manage the Security Program Calendar, ensuring cyclical and continuous controls occur on schedule, and track KRIs/KPIs for performance and compliance.
- Plan and execute internal control testing, continuous monitoring, and automated evidence collection across cloud, identity, network, endpoint, data, and application domains.
- Perform targeted cyber/IT risk assessments and recommend compensating controls, track remediation, and update baselines to prevent recurrence.
- Prepare for regulatory examinations, internal audits, and partner due diligence, producing defensible narratives, control maps, and evidence packages.
- Maintain operational documentation, dashboards, and reporting to promote control excellence and continuous improvement.
- Requirements
- 8+ years of experience in cybersecurity risk, governance, compliance, security operations, or risk engineering; financial services experience preferred.
- Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, or related field; equivalent experience considered.
- Hands-on experience with automation of control testing and evidence collection using APIs, Python, TypeScript, Bash, PowerShell, or similar.
- Familiarity with Azure/Microsoft 365/Entra, Okta, Windows/Linux, networks, CI/CD, vulnerability management, EDR, SIEM, and data protection.
- Strong knowledge of regulatory frameworks including FFIEC IT Examination Handbooks, NIST CSF, NIST SP 800-53, GLBA, SOX, and PCI DSS.
- Experience with GRC platforms and workflow/ticketing systems.
- Excellent written and verbal communication skills, with ability to influence cross-functional teams and present to management and auditors.
- Certifications preferred: CRISC, CISA, CISSP, CISM, CCSK/CCSP, AZ-500, or comparable.
- Bias for automation, measurable outcomes, and ability to thrive in fast-moving, high-accountability settings.
- Benefits
- Comprehensive medical, dental, and vision coverage.
- Life insurance and long/short-term disability protection.
- Flexible Spending Accounts (FSA) and Health Savings Accounts (HSA) with employer contributions.
- 401(k) retirement plan with company match.
- Paid time off and 11 paid holidays per year.
- Supplemental benefits including Hospital Indemnity, Accident Insurance, and Critical Illness coverage.
- Remote work flexibility and opportunities for professional growth.
Why Apply Through Jobgether?
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1