2229 Information Security Engineer IV
Job Description
Job Description
For more than three decades, Strategic Data Systems (SDS) has been a software consultancy firm specializing in strategy, technology, and business transformation for Fortune 100 companies, mid-sized firms, and startups. At SDS, we empower our development teams to address our clients’ critical business challenges by leveraging cutting edge technologies. If you seek a workplace where your contributions are truly appreciated, then SDS is the company for you. Join us today to work alongside fellow development specialists and become a crucial part of our dynamic and cohesive community.
Job Title: Information Security Engineer IV
Location: REMOTE EST/CST
Years of Experience: 5-20
TOP SKILLS:
Must Have
- Experience with vulnerability triage, validation, and prioritization.
- Must be able to communicate ideas both verbally and in writing to management, business and IT sponsors, and technical resources in language that is appropriate for each group.
- Strong understanding of application security principles, secure development practices, and common vulnerabilities (e.g., OWASP Top 10).
Nice To Have
- Ability to review and understand source code to validate vulnerabilities.
- Experience with vulnerability management or tracking platforms (e.g., ticketing systems, dashboards).
- Familiarity with vulnerability scanning tools and outputs (e.g., SAST, SCA, DAST).
What You’ll Do
The Information Security Engineer (ISE) will support the Enterprise Vulnerability Management (EVM) Application Security team’s day-to-day operations, with a primary focus on vulnerability intake, triage, and validation activities. This role is responsible for reviewing and triaging submissions to the Bank’s Vulnerability Disclosure Program (VDP) and Bug Bounty Program (BBP), as well as evaluating False Positive Review Requests submitted by application teams. This role requires assessing the validity and security impact of reported vulnerabilities, ensuring accurate tracking and coordination of remediation ownership, and supporting remediation efforts through the Bank’s centralized vulnerability management processes.
Job Description
GENERAL FUNCTION:
The Information Security Engineer (ISE) will be responsible for supporting the operational processes of the Enterprise Vulnerability Management Application Security program. This role includes reviewing, validating, and triaging vulnerability submissions from the Bank’s Vulnerability Disclosure and Bug Bounty Programs, as well as evaluating internally generated findings requiring false positive determination. The ISE ensures valid vulnerabilities are accurately assessed, prioritized, assigned to the appropriate remediation owners, and tracked within centralized systems. The role requires strong application security knowledge, sound judgment in assessing exploitability and business impact, and effective communication with application and engineering teams.
Responsible and accountable for risk by openly exchanging ideas and opinions, elevating concerns, and personally following policies and procedures as defined. Accountable for always doing the right thing for customers and colleagues and ensuring that actions and behaviors drive a positive customer experience. While operating within the Bank's risk appetite, achieves results by consistently identifying, assessing, managing, monitoring, and reporting risks of all types.
ESSENTIAL DUTIES & RESPONSIBILITIES:
· VDP & Bug Bounty Triage
o Review and triage vulnerability submissions from external researchers.
o Validate technical accuracy, exploitability, and business impact.
o Assess severity and impact in alignment with established scoring models and program standards.
o De-duplicate and disposition invalid or non-actionable submissions.
o Classify vulnerabilities using established taxonomy.
o Identify and assign remediation owners using established processes.
o Support vulnerability tracking within centralized tools.
· False Positive Review & Validation
o Evaluate false positive requests from application teams.
o Analyze scanner findings (SAST/SCA) and perform source code review as needed to validate findings.
o Determine validity and provide evidence-based disposition with rationale.
· Operational Support
o Contribute to continuous improvement of triage standards, playbooks, and procedures.
o Maintain awareness of common application security vulnerabilities and emerging threats.
· Risk & Compliance Support
o Ensure vulnerability handling aligns with internal policies, standards, and regulatory expectations.
o Maintain defensible documentation and provide supporting evidence for audit, regulatory, and internal review requirements.
o Escalate high-risk or time-sensitive vulnerabilities as appropriate.
· Stakeholder Communication
o Communicate findings, impact, and remediation guidance clearly.
o Partner with application and engineering teams to enable timely remediation.
MINIMUM KNOWLEDGE, SKILLS & ABILITIES REQUIRED:
· Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent practical experience.
· 3–5 years of related experience in information security, application security, or vulnerability management.
· Strong understanding of application security principles, secure development practices, and common vulnerabilities (e.g., OWASP Top 10).
· Experience with vulnerability triage, validation, and prioritization.
· Familiarity with vulnerability scanning tools and outputs (e.g., SAST, SCA, DAST).
· Ability to review and understand source code to validate vulnerabilities.
· Strong analytical skills to assess exploitability and business risk.
· Experience with vulnerability management or tracking platforms (e.g., ticketing systems, dashboards).
· Strong attention to detail and ability to make defensible decisions.
· Must be able to communicate ideas both verbally and in writing to management, business and IT sponsors, and technical resources in language that is appropriate for each group.
· Previous experience working with distributed or offshore teams desired.
· Financial industry experience is a plus.
What You’ll Get
SDS, Inc. provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state, and local laws.
- Competitive base salary
- Medical, dental, and vision insurance coverage
- Optional life and disability insurance provided
- 401(k) with a company match and optional profit sharing
- Paid vacation time
- Paid Bench time
- Training allowance offering
- You’ll be eligible to earn referral bonuses!
Recommended Jobs
Fleet Mechanic
We’re on the Moo-ve with new opportunities!! And you know, if it’s Borden, it’s got to be good! At Borden Dairy, we’ve embraced the “Glass Half Full” mindset since 1857. Guided by our beloved masco…
Material Handler
About Us: Columbus, Ohio's premier custom solutions steel fabrication company offers full-service product development and manufacturing capabilities. A woman-owned small business delivering qualit…
Truck Sales-New Philadelphia
B2B SALES PRO – TRUCKS & EQUIPMENT Base Salary + Commission $100K+ First-Year Potential If you know how to hunt, build relationships, and close—this territory is yours. We’re a premier tr…
Bartender
Job Description Job Description Welcome to Five Star Parks & Attractions, where work is fun, growth is real, and every day makes an impact. Five Star isn’t just a rating or a name; we’re a t…
FOH/BOH Restaurant Team Member
FOH & BOH staff are needed immediately! Come join City Barbeque in serving and creating happiness with America’s best BBQ, while living by 4 core values: Safety First. Treat others with inte…
JP Scaffolder - Kearl Lake
Soogadin Field Services is hiring Journeyperson Scaffolders at Kearl Lake! We are currently looking for experienced, hard-working, and motivated Journeyperson Scaffolders for Projects at Kearl La…
Child Care Assistant Teacher
Job Description Job Description 14.00 - 18.00 Center: Mt. Healthy OH Job Type: Full-Time Hours: (730-430, 800- 500, 900-600 pm) No evenings or weekends! Build your career in the ear…
In-Center Tutor
Tutor/Teacher - URGENT We are looking for several tutors for our Gahanna/New Albany Location. You'll be part of a team of professional educators working with elementary, middle, and/or high school…
Direct Support Professional (DSP)
Job Description Job Description Description: Supervises and performs meaningful training to individual employees during production time and down time Completes all required documentation, e…
CNC Lathe/Mill Machinist
We have one job opening for a full time CNC Lathe/Mill machinist to work in our manufacturing department requiring the following abilities: #You must have demonstrable experience. #You must be abl…