About this role
Rockland Trust is a full-service commercial bank and financial services company committed to helping our neighbors reach their financial goals. Founded in 1907 and headquartered in Massachusetts, we proudly serve individuals, families, and businesses throughout New England with a strong emphasis on personal relationships, local decision making, and community impact.
With a broad range of banking, wealth management, and investment solutions, Rockland Trust combines the resources of a growing financial institution with the personalized service of a community bank. Our long-standing philosophy, Where Each Relationship Matters®, guides how we work with our customers, colleagues, and communities every day.
At Rockland Trust, our employees are at the heart of our success. We foster a collaborative, inclusive, and values driven culture that encourages professional growth, innovation, and work life balance. We are deeply committed to community involvement, financial education, and creating a workplace where individuals can build meaningful, long-term careers.
Rockland Trust is hiring a Senior Security Engineer . Reporting to the Manager of Security Engineering, this role will lead the design, implementation, and continuous improvement of security solutions that protect the Bank's data, systems, applications, and cloud environments.
This role requires expertise across multiple security domains, including network security, endpoint protection, security monitoring, threat detection and response, identity and access management, privileged access management, cloud security, data protection, email security, and Zero Trust architectures. The Senior Security Engineer will lead strategic security initiatives, enhance the organization's security posture, and support Security Operations Center (SOC) functions through advanced monitoring, threat hunting, incident response, and security automation.
This position requires the ability to be on call and available 24x7 as needed to support the organization during security incidents, critical upgrades, or other time-sensitive issues, ensuring continuous protection of the organization's systems, applications, and data.
The Senior Security Engineer collaborates closely with Network Engineering, Infrastructure, Cloud Operations, Security Operations, Application Development, Risk, and Compliance teams to identify risks, implement security controls, and drive enterprise-wide security initiatives. This role also serves as a mentor and technical leader for junior team members.
MAJOR ACCOUNTABILITIES / CRITICAL RESPONSIBILITIES
Security Architecture & Engineering
- Provide technical leadership for the design, deployment, and lifecycle management of enterprise security technologies.
- Develop and maintain secure architectures for on-premises, cloud, and hybrid environments utilizing Zero Trust principles.
- Design, implement, and maintain next-generation network security controls, secure remote access solutions, and cloud-delivered security services.
- Develop and maintain secure configurations for security platforms, firewalls, security monitoring tools, identity services, and access controls.
- Design and implement network segmentation and micro-segmentation strategies to limit lateral movement and reduce organizational risk.
- Partner with infrastructure and application teams to ensure secure system and application architectures.
Threat Detection, Security Operations & Incident Response
- Act as a senior technical resource for security incident response efforts, threat containment, remediation, and post-incident reviews.
- Partner with SOC personnel to improve threat detection, monitoring, alerting, and response capabilities.
- Develop and maintain SIEM use cases, correlation rules, dashboards, security metrics, and automated response workflows.
- Conduct proactive threat hunting activities leveraging endpoint, network, cloud, and security telemetry sources.
- Support and enhance endpoint detection and response (EDR/XDR) capabilities across the enterprise.
- Lead investigations related to malware, phishing, insider threats, unauthorized access, and advanced persistent threats.
Identity, Privileged Access & Zero Trust
- Lead the implementation and ongoing management of identity security, identity governance, and privileged access management controls.
- Ensure least-privilege access principles are implemented across critical systems and applications.
- Support Zero Trust initiatives focused on identity-centric security, continuous verification, and secure access controls.
- Review and enhance authentication, authorization, and privileged account management processes.
Cloud, Data & Endpoint Security
- Lead implementation and management of cloud security solutions supporting hybrid and multi-cloud environments.
- Oversee endpoint security technologies, ensuring effective prevention, detection, and response capabilities.
- Implement and maintain controls that protect sensitive data across endpoints, networks, cloud platforms, collaboration platforms, and file-sharing solutions.
- Support data classification, data loss prevention (DLP), insider risk management, and data governance initiatives.
- Monitor and secure managed file transfer and business-critical data exchange platforms.
Email Security & Information Protection
- Oversee email security controls designed to protect against phishing, business email compromise, malware, spoofing, and other messaging threats.
- Enhance the organization's information protection capabilities through advanced threat prevention and data security controls.
- Collaborate with business units to improve user awareness and reduce human-centered security risks.
Vulnerability Management & Risk Mitigation
- Lead vulnerability management and remediation programs across infrastructure, applications, endpoints, cloud platforms, and security devices.
- Conduct security risk assessments and architectural reviews to identify gaps and recommend mitigation strategies.
- Collaborate with stakeholders to prioritize remediation efforts based on business impact and risk.
- Validate the effectiveness of implemented security controls through testing, assessment, and continuous improvement activities.
Collaboration & Leadership
- Partner with Network, Infrastructure, Cloud, Security Operations, and Application teams to design and implement secure solutions.
- Serve as a technical mentor for junior security engineers and analysts.
- Provide guidance regarding security architecture, incident response, threat detection, and security best practices.
- Support audits, regulatory reviews, and compliance initiatives.
QUALIFICATIONS / REQUIREMENTS
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related field, or equivalent experience.
- Minimum of 8 years of progressive experience in information security, including at least 4 years in a senior engineering, lead engineering, or security architect role.
- Demonstrated expertise across network security, cloud security, endpoint security, identity security, privileged access management, data protection, and threat detection technologies.
- Hands-on experience administering and supporting SIEM, EDR/XDR, security monitoring, and SOC technologies.
- Strong knowledge of Zero Trust security principles and enterprise security architecture frameworks.
- Experience designing and implementing network segmentation or micro-segmentation solutions within enterprise environments.
- Experience securing cloud-based applications, infrastructure, and SaaS environments.
- Expertise with privileged access management, identity governance, Active Directory, authentication services, and access control technologies.
- Strong understanding of email security, data protection, DLP, insider risk management, and information governance concepts.
- Proven experience leading major security incidents, investigations, and remediation efforts.
- Strong knowledge of security frameworks and standards such as NIST and CIS Controls.
- Excellent communication, documentation, leadership, and stakeholder management skills.
- Relevant certifications such as CISSP, CISM, CCSP, or equivalent are strongly preferred.
ADDITIONAL SKILLS
Security Platforms: CrowdStrike Falcon, CyberArk PAM, Proofpoint, Netskope, Qualys VMDR, Palo Alto Networks, Microsoft Defender Suite
Security Operations: SIEM, SOC Operations, Threat Hunting, Incident Response, Detection Engineering, Security Monitoring, SOAR, EDR/XDR
Identity & Access Security: Active Directory, Microsoft Entra ID, Identity Governance (IGA), Privileged Access Management (PAM), MFA, SSO, Conditional Access, Zero Trust
Cloud & Data Security: Azure Security, Microsoft 365 Security, CASB, SSE, ZTNA, DLP, Information Protection, Data Classification, Data Access Governance, Insider Risk Management, Hybrid Cloud Security
Network Security: Network Segmentation, Micro-Segmentation, IDS/IPS, VPN Technologies, Secure Remote Access, Firewall Management
Governance & Risk: NIST Cybersecurity Framework, CIS Controls, Vulnerability Management, Security Architecture Reviews, Risk Assessments, Compliance Support
Leadership & Professional Skills: Technical Leadership, Cross-Functional Collaboration, Project Leadership, Technical Mentoring, Process Improvement, Strategic Planning, Technical Documentation
Benefits & Culture
Our goal is to offer our colleagues the most generous benefits package possible. We provide a comprehensive suite of benefits designed to support your health, financial security, and overall, well-being. Benefits include competitive compensation with performance-based incentive awards, health, and dental insurance, a 401(k) and DC retirement plan, LTD and life insurance, paid vacation, day care reimbursement, tuition assistance for undergraduate and graduate programs, an award-winning wellness program, and much more!
At Rockland Trust, you’ll find a respectful and inclusive environment where everyone has the opportunity to succeed. We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Pay Transparency
Compensation for this role will be based on a variety of factors, including skills, experience, education, and internal equity. The salary range posted reflects the company’s good faith estimate of the range for this position at the time of posting. Actual compensation may vary. In addition to base salary, certain positions may be eligible for additional compensation, including commissions, incentive awards, or stipends.
Accessibility & Accommodations
We are committed to providing reasonable accommodation to enable individuals with disabilities to perform the essential functions of their roles.