Jobs and Careers
CO

Security Risk & Controls Engineer

Coastal Community Bank
United States, United Statesfull_timeVerifiedPosted 20 Nov 2025

About the role

Description

ABOUT US 

  

Coastal is at the forefront of modern banking, combining strong financial infrastructure with cutting-edge Banking-as-a-Service (BaaS) and fintech enablement strategies. We support not only individuals with their personal banking needs; we also empower businesses by integrating modern banking technology that drives growth, flexibility, and innovation.


At Coastal, we think and move like entrepreneurs; focused on impact, speed, and continuous improvement. We believe in working smart, collaborating deeply, and building solutions that unlock real potential. If you're someone who thrives in a fast-moving environment, loves solving complex problems, and wants to help shape the future of banking, we’d love to meet you.


Check out our video here!

Requirements

OVERVIEW 


The Cybersecurity Risk & Controls Engineer owns the day-to-day health of Coastal’s Security Program. You will define and maintain our enterprise control baseline aligned to the CRI Profile and FFIEC IT Examination Handbooks, work with control owners to implement automated and policy-aligned control processes, drive the Security Program Calendar to ensure time-bound and cyclical controls occur on schedule, perform and automate internal control testing, and drive continuous control monitoring across cloud, identity, network, endpoint, data, and application domains. This role blends hands-on technical capability with classic GRC rigor. You’ll partner with Security Engineering, IT, Business Lines, Risk, Internal Audit, and Compliance to translate regulatory expectations into auditable, automated, and durable controls that reduce risk and enable the business. 


RESPONSIBILITIES TO INCLUDE 

  • Control Baseline & Governance 
  • Define, document, and maintain the enterprise control library mapped to the CRI Profile and FFIEC IT Examination Handbooks, aligning with GLBA, SOX, and PCI-DSS where applicable. 
  • Author and maintain control narratives, RACI, evidence requirements, testing procedures, and control objectives. Manage associated control versioning and approvals. 
  • Work with technical control owners to implement processes and automations appropriately aligned to written controls, policies, and standards. 
  • Security Program Operations 
  • Own the Security Program Calendar to ensure cyclical controls occur on schedule (e.g., user access reviews, network security reviews, vulnerability & configuration scanning, DR/BCP tests, incident response tabletop exercises, vendor re-assessments, policy reviews). 
  • Track status, remove blockers, and escalate risk of slippage for proper operation of both cyclical/scheduled and continuously operating controls. Maintain related reporting and KRIs/KPIs (on-time completion, pass rate, repeat findings). 
  • Capture and curate complete, audit-ready evidence with chain of custody using an automation-first approach. 
  • Internal Control Testing, Continuous Monitoring, & Automation 
  • Plan and execute Test of Design (TOD) and Test of Operating Effectiveness (TOE): walkthroughs, sampling, re-performance, and result documentation with clear workpapers. 
  • Partner with Security Engineering and IT to embed “policy as code” and guardrails (e.g., identity, configuration, network segmentation, logging/monitoring). Own implementation of policy-as-code and other proactive automations wherever possible. 
  • Automate evidence collection and control testing via APIs/queries/scripts (e.g., Azure/Microsoft 365/Entra, Okta, Intune, GitHub, CI/CD, endpoint protection, vulnerability management, ticketing/GRC platforms). 
  • Implement quality checks for completeness, accuracy, and timeliness of evidence. 
  • Risk Assessment & Issues Management 
  • Perform targeted cyber/IT risk assessments (technology changes, third parties, products) and recommend compensating controls with clear residual-risk statements. 
  • Log, track, and validate remediation of issues and control gaps. Verify sustainable fixes and prevent recurrences by updating baselines, standards, and automation. 
  • Regulatory Exams, Audits & Reviews 
  • Coordinate, prepare, and run responses to Internal Audit activities, regulatory examinations, independent audits, and customer/partner due diligence. 
  • Produce concise, defensible narratives, control maps, and evidence packages. Coordinate requests and brief stakeholders. 
  • Metrics, Reporting & Enablement 
  • Publish program health dashboards, KRIs/KPIs, and control maturity assessments to Enterprise Risk Management and management and risk committees. 
  • Coach control owners on expectations, testing methods, and evide

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Coastal Community Bank

View company profile →