Jobs and Careers
CA

AVP, Information Security Engineer

Cathay Bank
Rancho Cucamonga, United Statesfull_timeVerifiedPosted 9 May 2025
💰 $120,000/yr($100,000/yr$120,000/yr)

About the role

People Drive Our Success


Are you enthusiastic, highly motivated, and have a strong work ethic? If yes, come join our team! At Cathay Bank – we strive to provide a caring culture that supports your aspirations and success. We believe people are our most valuable asset and we proudly foster growth and development empowering you to achieve your professional goals. We have thrived for 60 years and persevered through many economic cycles due to our team members’ drive and optimism. Together we can make a difference in the financial future of our communities.


Apply today!


What our team members are saying:


Video Clip 1

Video Clip 2

Video Clip 3


Learn more about us at cathaybank.com


GENERAL SUMMARY
This position is responsible for designing, implementing, and supporting the Bank’s Information Security infrastructure and protecting its data and assets in accordance with established Information Security and Bank policies, published regulations and industry best practices.
Responsibilities include performing risk assessments of the Bank’s network, applications, and endpoint activity, and manage security projects to implement security controls or tools to mitigate cyber risk, ensuring that the Bank’s network and data are secure in accordance with Bank, IT, and IS policies.


ESSENTIAL FUNCTIONS
• Participate in Business and Information Technology projects to recommend security controls and solutions applicable. Provide recommendations for security infrastructure, developing security plans and standards.
• Manage trade-offs and determine cost-benefits between new tools to be implemented to the current security stack, and improve existing tools by reconfiguring, repurposing, or training. Identify and evaluate opportunities for process improvement.
• Maintain strong technical security skills that follow the current market trends to work on both cloud and on-prem based solutions.
• Serve as Subject Matter Expert (SME) across technical information security domains.
• Identify and assess vulnerabilities and risks to enterprise applications infrastructure and data. Develop and implement technical solutions to counter vulnerabilities and risks.
• Track current and emerging security threats, design and implement security solutions to mitigate them.
• Propose scope, design, and supervise the execution of the penetration test program to reach defined objectives.
• Review and propose improvements to email, endpoint and network security.
• Implement the enterprise data loss prevention program by identifying and proposing controls on data loss channels.
• Ensure that security systems and tools such as firewalls, web filtering, EDR, XDR, NAC for adequate coverage and periodically reassess configurations and security controls for improvements.
• Maintain information security systems and tools such as CASB, DLP, MDM and WAF and periodically review configurations.
• Establish, plan, and manage overall program and goals for the system security requirements and baseline configurations.
• Participate in efforts to remediate audit and regulatory findings and recommendations related to Information Security.
• Define and implement solutions to meet compliance requirements, including but not limited to: Sarbanes-Oxley, Payment card industry standards, and state and federal regulations.

REQUIRED QUALIFICATIONS
Education: College degree in Information Technology or Information Security or equivalent.
Certification: Requires one or more of the following certifications CISSP, CISM, CRISC, CISA, Security+, EnCE, CEH, OSCP, GIAC. Splunk and Microsoft certifications preferred.
Experience:
• 5+ years experience in Information Security Operations or Information Security Risk Management, preferably in the financial services industry.
• 3+ years experience in Security Engineering or Security Architecture role operating and/or implementing SIEM, EDR/XDR, NAC, IDS/IPS, WAF, IAM, FW, AD, EntraID and AVs.
• Proven experience in securing and implementing policies for Cloud Technologies (M365, Azure, AWS) and the Microsoft (E5) technology stack including Microsoft Defender, Microsoft Intune or similar.
• Experience defining and/or reviewing firewall rules and IDS/IPS topology and configurations.
• Experience in defining or participating in penetration tests and/or attack simulation exercises and implementing remediation plans.
• Strong understanding of networking, communication, and secure email protocols (TCP/IP, UDP, SSL/TLS, IPSEC, SPF, DKIM, DMARC, DNSSEC, etc.)
• Experience configuring and managing a Security Information and Event Management (SIEM) platform is highly preferred.
• Governance or oversight of a third-party risk management program experience prefer

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Cathay Bank

View company profile →