Information Security Engineer
Farmers & Merchants Bank of Long BeachAbout the role
Job Summary
The Information Security Engineer is a hands-on technical professional responsible for implementing, engineering, and continuously optimizing information security controls across the Bank's technology environment. Operating with a high degree of autonomy, this role focuses on designing, deploying, and operationalizing security solutions that protect the organization while supporting business objectives, regulatory requirements, and evolving threat landscapes.
Working closely with the Chief Information Security Officer (CISO), Information Security Architect, and cross-functional IT stakeholders, the Information Security Engineer translates security requirements into effective technical controls and solutions. The position plays a key role in strengthening the Bank's security posture through risk assessments, security architecture enhancements, control validation, and continuous improvement initiatives.
This role requires a strong balance of operational excellence and strategic thinking. The successful candidate will proactively identify security gaps, develop automation opportunities, enhance detection and response capabilities, and drive security maturity across the organization. Participation in after-hours support for critical security incidents and production issues may be required.
Key Responsibilities
- Engineer, implement, and maintain information security controls across on-premises and cloud environments, including Microsoft Azure and Microsoft 365.
- Translate security requirements, policies, and architectural designs into scalable, operationally effective security solutions.
- Configure, manage, and optimize security technologies, including firewalls, web application firewalls (WAF), intrusion detection and prevention systems (IDS/IPS), endpoint protection platforms, and Security Information and Event Management (SIEM) solutions.
- Monitor and respond to escalated security events and alerts; perform incident investigation, containment, remediation, and post-incident analysis.
- Develop and maintain automation solutions using scripting and programming languages such as Python and PowerShell to improve detection, response, reporting, and operational efficiency.
- Conduct vulnerability assessments, validate security control effectiveness, and support remediation efforts to reduce organizational risk.
- Analyze system logs, security telemetry, and network traffic to identify malicious activity, attack patterns, and emerging threats.
- Collaborate with Information Technology teams, vendors, and security leadership to implement, enhance, and maintain security capabilities.
- Support security architecture initiatives by providing technical expertise and implementation guidance.
- Assist with risk assessments and provide recommendations to strengthen the Bank’s overall security posture.
- Provide technical guidance and mentorship to Information Security Analysts and contribute to the ongoing development of team capabilities.
- Maintain accurate and complete documentation, including system configurations, operational procedures, incident records, and technical standards.
- Adhere to established change management, operational, and security procedures.
- Stay informed of emerging cybersecurity threats, vulnerabilities, technologies, and industry best practices.
Key Responsibilities – On-Call Support
- Participate in an on-call rotation to support security incidents, critical alerts, and production issues.
- Ensure timely response, investigation, escalation, and resolution in accordance with established service level expectations.
- Provide after-hours support for critical security events, operational issues, and emergency situations.
- Remain available to assist with high-priority incidents outside scheduled on-call periods when business need or risk severity warrants.
Compliance Responsibilities
- Comply with all applicable federal and state banking regulations, internal policies, and security standards.
- Support compliance efforts related to:
- Bank Secrecy Act (BSA)
- Anti-Money Laundering (AML)
- Office of Foreign Assets Control (OFAC)
- Customer Identification Program (CIP)
- Financial Elder Abuse reporting requirements
- Information security and data privacy regulations
- Support internal audits, external audits, and regulatory examinations by providing technical evidence, documentation, and subject matter expertise.
- Ensure security controls, processes, and monitoring activities align with regulatory expectations, industry standards, and organizational policies.
- Assist in validating the effectiveness of security controls through testing, reviews, and
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s