About the Company At Credit.com, we believe that everyone deserves the opportunity to build and protect their credit—and with it, their financial future. Our mission is to empower consumers with the tools, insights, and technology to make informed financial decisions. We’re dedicated to creating intuitive, AI-powered products that simplify credit management and help millions of people achieve financial well-being. About the Role We’re looking for a Staff Information Security Engineer to join our Information Security team. In this role, you’ll lead the design, deployment, and management of advanced security solutions, contributing to daily operations and long-term strategic initiatives. You’ll drive improvements in technology, processes, and documentation to help mature the company’s overall security posture. The ideal candidate is a skilled security engineer or architect with deep technical expertise, strong communication skills, and a passion for protecting data and infrastructure. You’ll work cross-functionally to ensure compliance with frameworks such as PCI-DSS, SOC 2, and other regulatory standards. We’re looking for a team player with a robust background in security engineering/architecture who can translate complex technical details into clear, business-friendly insights. This is a hybrid role (3/2) in downtown Salt Lake City, UT or CA remote. What You'll Do • Monitor and respond to security issues across client workstations, servers, cloud platforms, applications, and infrastructure. • Investigate and remediate security alerts, incidents, vulnerabilities, and control gaps. • Ensure compliance with internal policies and external regulatory and compliance frameworks to maintain a culture of security within the organization. • Recommend, develop, implement, and maintain IT cloud security controls and best practices. • Configure, monitor, and audit AWS, Azure, and Entra environments, including IAM, Microsoft 365, EC2/S3/Serverless functions, containers/Kubernetes clusters, and software-defined infrastructure. • Evaluate new cloud and automation technologies, including AI/ML, to enable the business to adopt these in a secure and sustainable manner. • Install, configure, and maintain security control measures and security software to protect systems and information infrastructure - including firewalls, WAFs, endpoint protection (EDR), vulnerability management, data loss prevention (DLP), security event (SEIM), and data encryption programs. • Stay current on IT security trends, standards, and news; regularly document and research relevant industry trends and control enhancements to make recommendations to management. • Research and document lessons learned from recent public security breaches - assessing the damage they cause and any related control enhancements that can be made in our environment. • Manage, configure, and administer Credit.com’s Vulnerability Management solutions to scan, document, and track vulnerabilities discovered on company systems and cloud resources. • In concert with the company’s security operation center (SOC) provider, investigate, respond, remediate, and document relevant information related to security alerts and events. • Assist to develop and deploy security awareness efforts, including training, phishing campaigns, and user education as part of the company’s security awareness program. • Investigate anomalies and assist in managing the company’s IAM systems. • Contribute to compliance efforts (PCI-DSS, SOC 2, etc.) through documentation, evidence gathering, and project tasks. • Advise related teams on cloud, container, API, and application security (SAST/DAST). • Work with internal teams to perform tests and uncover network and system vulnerabilities. • Track, report, and advise on risk metrics (KPIs, KRIs) for compliance and risk management programs. • Serve on the incident response team (IRT) as required to participate in incident response, tabletop exercises, and policy improvement efforts. Must Have Qualifications • 10+ years of hands-on experience in information technology/security with a focus on information security engineering or architecture. • Bachelor's degree in Information Security, Computer Science, or a related technical field (may supplement experience). • 3+ years of experience in security engineering, operations, or architecture within AWS, Azure, or GCP cloud platforms. • Documented history in advising and executing security architecture design and assessments. • Familiarity with designing and implementing secure enterprise networks. • Technical expertise in related network security technologies, to include: Next Generation Firewalls (NGFWs), web application firewalls (WAFs) web proxies, NAC, IDS/IPS, FPC, FIN, VPNs, SDWAN, and related tools. • Significant experience with SIEM, SOC, and related security information logging, event, and alerting technologies. • A strong curiosity, initiative, persistence, and willingness to experiment, grow, innovate, adopt new technologies, and to provide solutions to diverse technical challenges. Preferred Qualifications • Knowledge of Threat Hunting and Threat Intelligence processes and best practices preferred. • Experience with hardening network devices, servers, endpoints, containers, and cloud resources preferred. • Experience with AWS, Azure, or GCP – including IAM, containers, serverless, storage, secure virtual networking, and related cloud infrastructure security toolsets used in AWS, Azure, or GCP preferred. • Experience with programming languages and code security analysis (SAST, DAST) preferred. • Experience with AI, ML, LLMs, SOAR, and other automation technologies - coupled with a strong desire to implement cutting-edge technology to deliver groundbreaking services to our customers preferred. • Strong Project Management experience preferred. What You’ll Get • A mission-driven company where your work directly improves financial outcomes for real people. • A collaborative team culture that values initiative, autonomy, and curiosity. • Competitive compensation, bonus potential, and comprehensive benefits including company HSA contributions, 401(k) match and paid parental leave. • Hybrid 3/2 schedule in our downtown Salt Lake City office or CA remote. Credit.com is an Equal Opportunity Employer.
Job Type
Fulltime role
Skills required
Azure
Location
Salt Lake City, Utah
Salary
$135,000 - $150,000
Date Posted
May 21, 2025
Credit.com is seeking a Staff Information Security Engineer to enhance their security posture through advanced security solutions and compliance initiatives. This hybrid role requires extensive experience in information security engineering, particularly within cloud environments.