Cybersecurity Engineer

Posted 25 Days Ago
Be an Early Applicant
Winston-Salem, NC, USA
In-Office
Mid level
Fintech • Financial Services
The Role
The Cybersecurity Engineer will support incident response and monitoring for threats, triaging alerts, investigating suspicious activities, and developing response playbooks while coordinating with internal teams and external partners to enhance cybersecurity measures.
Summary Generated by Built In

Description

Role Accountability

Our culture is built on teamwork, integrity, and a shared commitment to delivering a trusted member experience. In this role, you will support the Credit Union’s cybersecurity operations with a primary focus on incident response by monitoring for threats, triaging alerts, investigating suspicious activity, coordinating containment and remediation, and partnering with internal teams and our managed detection and response (MDR) provider to reduce risk and improve resilience.

Specific Accountabilities

  • Monitor security tooling (e.g., SIEM, EDR, email/web security, firewall/VPN logs) and triage alerts to determine scope, severity, and required response actions.
  • Investigate suspicious activity by analyzing logs and telemetry, correlating events across systems, and documenting findings in tickets and incident records.
  • Execute incident response actions (containment, eradication, and recovery) in partnership with IT and application teams, including isolating hosts, blocking indicators, and supporting remediation.
  • Collect and preserve incident evidence (logs, timelines, indicators) and support forensic activities as needed while maintaining chain-of-custody expectations.
  • Develop, maintain, and improve incident response playbooks and procedures; participate in tabletop exercises and post-incident reviews to drive corrective actions.
  • Tune detections and reduce false positives by partnering with tool owners; recommend improvements to alert logic, correlation rules, and response automation.
  • Support vulnerability response by validating exposure, tracking remediation, and coordinating patching or mitigating controls for critical findings.
  • Coordinate with internal teams and external partners (including our managed detection and response (MDR) provider, technology vendors, and law enforcement as directed) during investigations and response activities.
  • Implement and validate security changes that support incident response outcomes (e.g., blocks, access adjustments, segmentation changes) and follow through on hardening items identified during investigations.
  • Participate in an incident response on-call rotation (as required), provide timely escalation and status updates to stakeholders, and support incident communications aligned to severity and business impact.
  • Leverage frameworks such as MITRE ATT&CK and perform light threat hunting (hypothesis-driven investigations) to proactively identify malicious activity and validate control effectiveness.
  • Stay current on the threat landscape, attacker techniques, and incident response best practices; recommend process and control improvements based on lessons learned.

Requirements

Knowledge, Skills and Abilities

  • Strong problem solving and analytical skills; must possess the ability to make quick decisions and use good judgment during incident response.
  • Strong verbal and written communication skills; can clearly and confidently communicate information security concepts to all areas of the business.
  • Highly adaptable to a constantly changing business and technology environment.
  • Familiarity with regulatory and legal security standards and requirements relevant to financial services/credit unions such as GLBA, NCUA, FFIEC guidance, PCI DSS, and Sarbanes-Oxley (as applicable).
  • Hands-on knowledge of incident response practices (triage, investigation, containment/eradication, recovery) and the ability to follow and improve playbooks and procedures.
  • Ability to analyze security telemetry (Windows/Linux logs, firewall/VPN logs, DNS, proxy, authentication logs) to identify indicators of compromise and suspicious behavior.
  • Experience with security monitoring and detection tools (e.g., SIEM queries/dashboards, endpoint detection and response) and familiarity with alert tuning and correlation concepts.
  • Knowledge of Identity and Access Management concepts (MFA, privileged access management) and common investigation points for authentication-related incidents.
  • Familiarity with data protection controls (e.g., DLP) and how to investigate and respond to potential data exposure events.
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk) and how incidents impact business risk.
  • Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity. 
  • Knowledge of cyber threats and vulnerabilities. 
  • Knowledge of specific operational impacts of cybersecurity lapses. 
  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). 
  • Knowledge of network traffic analysis concepts (tools, methodologies, processes), including basic packet capture/analysis and web filtering technologies.
  • Knowledge of what constitutes a network attack and the relationship to both threats and vulnerabilities. 
  • Working knowledge of networking fundamentals used in investigations (TCP/IP, DNS, HTTP/S, routing, VPN concepts) and common attacker techniques in enterprise environments.

Education and Experience

  • Bachelor’s degree in Information Systems, Information Technology, Management Information Systems, Computer Science, Computer Engineering, or related field. 
  • 3-5 years of experience in information security, SOC operations, or incident response, including hands-on investigation and response to security events.
  • Professional certifications preferred: Security+, CySA+, GCIH/GCIA (or similar), or CISSP/CCSP (a plus).

Skills Required

  • Bachelor's degree in Information Systems, IT, Computer Science or related field
  • 3-5 years of experience in information security, SOC operations, or incident response
  • Experience with security monitoring and detection tools
  • Professional certifications preferred (e.g., Security+, CySA+, GCIH, CISSP)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
425 Employees
Year Founded: 1967

What We Do

Allegacy Financial is a comprehensive banking and financial partner offering personal, small business, commercial, and wealth management services, focused on building lifelong relationships and helping North Carolinians thrive.

Similar Jobs

Aprio Logo Aprio

Cybersecurity Engineer

Professional Services
In-Office or Remote
11 Locations
1856 Employees
80K-90K Annually

Aprio Logo Aprio

Cybersecurity Engineer

Professional Services
In-Office or Remote
12 Locations
1856 Employees
100K-125K Annually

Allegacy Financial Logo Allegacy Financial

Cybersecurity Engineer

Fintech • Financial Services
In-Office
Winston-Salem, NC, USA
425 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Sales Engineer

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office or Remote
7 Locations
85422 Employees
175K-412K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account