About this role
At Affinity Plus every employee understands how their work affects our members experience and we strive to provide an experience that can't be found anywhere else. Great service starts with great employees and that is why we focus on providing not only the best place our members will ever bank but the best place our employees will ever work. Between our one of a kind culture, incredible benefits, and work/life balance; we believe you will feel the Affinity Plus difference.
Position Summary The Information Security Engineer plays a key role in protecting Affinity Plus Federal Credit Union from cybersecurity threats by designing, implementing, managing, and continuously improving the technologies and controls that support the Information Security Program. This position is responsible for maintaining and enhancing security infrastructure, supporting threat detection and response capabilities, conducting security assessments, and collaborating with internal teams and external partners to strengthen the organization's security posture. The role serves as a technical subject matter expert and helps ensure security systems, processes, and defenses are effective against current and emerging threats while supporting the confidentiality, integrity, and availability of corporate data and resources.
Duties & Responsibilities Security Engineering & Infrastructure Management • Serve as a key resource in the evaluation, selection, implementation, configuration, and ongoing management of information security tools, technologies, and platforms. • Maintain, support, and optimize the security infrastructure and technologies utilized by the Information Security Program. • Collaborate with technology teams to ensure security solutions are effectively integrated, configured, and maintained across the enterprise. • Evaluate existing security controls and recommend enhancements to improve operational effectiveness, efficiency, and security posture. • Lead the implementation and lifecycle management of security technologies, ensuring solutions remain current, supported, and aligned with organizational needs.
Threat Management, Detection & Response • Collaborate with Information Security team members to develop, maintain, and continuously enhance Security Information and Event Management (SIEM) capabilities and detection strategies. • Coordinate with threat intelligence sharing organizations and security partners to facilitate the collection, analysis, and sharing of relevant threat intelligence. • Conduct threat intelligence, threat hunting, and reconnaissance activities to identify emerging threats, assess risks, and improve organizational preparedness and response capabilities. • Monitor and evaluate threat intelligence information to identify potential impacts to the organization and recommend appropriate mitigation strategies. • Act as a technical resource during the investigation, analysis, and response to security events and incidents. • Develop and maintain detection use cases, correlation rules, alerts, and dashboards to improve visibility into potential security threats and suspicious activity.
Vulnerability Management & Security Assessments • Ensure internal and external vulnerability assessments, attack surface reviews, scans, and security testing activities are conducted regularly. • Analyze assessment results and collaborate with stakeholders to prioritize remediation efforts and reduce organizational risk. • Partner with third-party security providers and internal teams to support penetration tests, security assessments, tabletop exercises, audits, and related testing activities. • Validate remediation efforts and verify identified vulnerabilities have been appropriately addressed.
Security Strategy, Governance & Continuous Improvement • Assist in the development, implementation, maintenance, and communication of enterprise-wide information security strategies, standards, procedures, and policies. • Provide technical expertise and recommendations to support strategic security initiatives and program enhancements. • Research emerging technologies, security trends, vulnerabilities, and threat landscapes to support the continuous improvement of the Information Security Program. • Collaborate with Information Technology, business stakeholders, and security partners to strengthen organizational cybersecurity capabilities.
Security Consulting & Collaboration • Serve as a technical subject matter expert for information security technologies, controls, and best practices. • Partner with internal teams to provide security guidance and recommendations for projects, operational initiatives, and technology implementations. • Support awareness and education efforts by sharing technical security knowledge and best practices with stakeholders across the organization. • Build and maintain productive relationships with internal teams, vendors, industry groups, and external security partners. • Other duties as assigned
Minimum Qualifications and Skills Required Knowledge • 3+ years of experience in an Information Security role. • Intermediate experience in Network Administration/Architecture, Security Framework Usage, SIEM Usage. • Extensive experience in a range of threat intel/recon tools, including propriety and open source models. • Strong understanding of security theories including Defense-In-Depth, Cyber KillChain, Assumed Breach, Zero Trust. • Ability to initiate, react to, and take direction on specific course or response, action, and mitigation that is heavily dependent and individualized to the security situation.
Qualifications and Skills Decision Making/Problem Solving/Advising • Ability to analyze information to solve issues and make informed, sound decisions, within established policies and procedures • Skilled in assessing needs, offering solutions, and building trust through effective consultation. • Ability to recognize operational inefficiencies and identify improvement opportunities
Collaboration/Building Relationships • Proven ability to build and maintain positive working relationships with members and internal stakeholders by demonstrating professionalism, reliability, and responsiveness in daily interactions. • Ability to collaborate effectively within and across teams.
Accountability • Ability to take accountability of responsibilities, commitments, and outcomes.
Communication • Strong ability to communicate clearly, effectively and professionally.
Learning • Ability to actively pursue opportunities to expand knowledge and skills; applying learning to improve performance. • Willingness to learn new skills, processes, and technologies with support and training.
Adaptability • Demonstrated adaptability and willingness to take on new responsibilities. • Demonstrated ability to show resilience and adaptability in the face of challenges or changes. • Technology Experience • Intermediate computer and technology skills and knowledge, with the ability to navigate between multiple systems with ease.
Other Skills • Time Management skills and the ability to prioritize workload based on department and member needs. • Ability to complete tasks with accuracy and thoroughness. • Demonstrated reliability, integrity, and ability to maintain confidentiality.
Preferred • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Math, or similar field. • Certification in CISSP, GCTI, CTIA, CASP+ or equivalent.
Location and Work Environment This role is: Virtual First - Requires reliable internet access and home office setup. Onsite work will be required throughout the year for training, team meetings and events; typically in or near St. Paul, MN. Applicants should live in Minnesota or Wisconsin or within a reasonable commuting distance to the metro area.
Physical Requirements • Sitting 90-95% and standing 5-10%. • Working at a computer 98% of the day. • Repetitive movements, including but not limited to typing, mousing, phones, etc. • May require to lift, carry, push or pull up to 30 pounds. • Bending, twisting, kneeling, stooping, or crouching on occasion.
Requires onsite presence based on coordination of work with other employees and/or departments. May require travel to attend on-site meetings/events for collaboration, connection, project work, All-Employee Day, etc.
Required Work Schedule Standard Monday through Friday business hours with a willingness to work a flexible schedule as needed. Consistent and reliable attendance is a required essential function of this role to meet the needs of the department/team and organization.
Compensation
This position has a starting pay range of $92,700 — $120,500 annually.
In alignment with our commitment to pay transparency, we are providing a good-faith estimate of the pay range for this position. This range reflects what we anticipate offering a successful candidate based on factors such as the role's responsibilities, required qualifications, and relevant experience. The actual pay may vary depending on the selected candidate's skills, experience, and other qualifications.
Total Rewards
Affinity Plus offers a comprehensive Total Rewards package that goes beyond base pay. In partnership with the State of MN Employer Group, Affinity Plus provides low-cost medical, dental and vision insurance coverage options. Additionally, Affinity Plus frontloads all sick time hours and a portion of vacation hours for all new employees, offers a variety of paid leave options, a monthly wellness benefit, and immediate 401K matching up to 5%. Our Total Rewards philosophy is designed to support your well-being and growth while fostering a fair and inclusive workplace.
Disclaimer
Applicants may be subject to a background and credit check. Employees in this position must be able to satisfactorily perform the essential functions of the position. If requested, Affinity Plus Federal Credit Union will make every effort to provide reasonable accommodations to enable employees with disabilities to perform the position's essential job duties. As markets change and the Organization grows, job descriptions may change over time as requirements and employee skill levels evolve. With this understanding, Affinity Plus Federal Credit Union retains the right to change or assign other duties to this position.
Application Deadline
Affinity Plus Federal Credit Union accepts applications on a rolling basis.