SR Information Security Engineer - IS-Mod - 80651
The Senior Information Security Engineer is a senior-level technical position responsible for leading complex security engineering initiatives and providing advanced expertise across multiple information security domains. The position operates with significant autonomy, serves as a technical authority, and is accountable for designing, implementing, and optimizing security solutions that address enterprise risk, regulatory requirements, and business objectives.
Depending on the area of focus, the Senior Information Security Engineer may lead Secure Software Development Lifecycle (SSDLC) initiatives focused on enabling security across software development and delivery pipelines or advancing security practices for agentic and AI-assisted software development. Examples of such activities include the following:
- Serves as a technical subject matter expert, collaborating across Information Security and IT to translate security requirements into practical and scalable solutions. Provide adoption guidance for developers.
- Design and maintain representative development environments and CI/CD pipelines to evaluate, validate, and demonstrate application security tools and controls.
- Design and maintain representative agentic development workflows to test and validate security controls.
- Research emerging agentic and AI-assisted development practices and associated security risks and controls.
- Evaluate security technologies and capabilities for risks introduced by agentic and AI-assisted software development.
Bachelor’s degree in applicable field plus five (5) years of relevant experience. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.
Master’s degree in applicable field plus four (4) years of relevant experience preferred. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.
One or more of the following certifications (or equivalent) are required at time of hire: CISSP, CISM, GSEC, OSCP.
Preferred Qualifications
- Strong software, systems, platform, or security engineering experience supporting modern application development and delivery environments.
- Strong understanding of SSDLC and application security practices, with experience translating security requirements into technical solutions and guidance.
- Experience with CI/CD pipelines, build processes, cloud or container technologies, and application security controls such as SAST, SCA, and software supply chain security.
- Experience with AI-assisted and agentic software development technologies and workflows, including associated application security risks and controls.
- Strong technical leadership, communication, and collaboration skills across security and technology teams.
This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.