Information Security Engineer II
2 days ago
Join our team - and take the next step in achieving a fulfilling career
What We Do
At CardWorks, we aim to help people connect with possibility and opportunity using our financial servicing expertise. Building meaningful, long-term relationships with consumers, our employees, and our clients is what matters most.
Who We Are
CardWorks, Inc. is a diversified consumer finance service provider and parent company of CardWorks Servicing, LLC, Merrick Bank and Carson Smithfield, LLC.
CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans. We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees.
Merrick Bank is an FDIC-insured Utah Industrial Loan Bank. Merrick operates three main business lines: credit cards, recreational lending, and merchant services.
Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management.
Position Summary:
We are seeking a skilled and motivated Application Security Engineer to join our team. This role involves safeguarding our software applications and development processes against security threats. The ideal candidate will work closely with developers, DevOps, and IT teams to identify vulnerabilities, implement security best practices, and ensure compliance with industry standards.
Essential Functions:
Key Application Security Engineer Responsibilities Include:
- Collaboration & Training: Work closely with development and DevOps teams to ensure security best practice and the SDLC policies are followed during all stages of the Coding pipelines. Deliver training and awareness sessions on application security for developers and stakeholders.
- Code & Architectural Reviews: Conduct in-depth reviews of application code to identify and address security vulnerabilities. Analyze application architecture to ensure robust security design and alignment with best practices. Collaborate with architects and engineering teams to incorporate secure design principles into software systems.
- Automation and Integration Development: Direct the development of tools, scripts, and frameworks to enhance testing processes and reporting, integrating security checks within continuous integration (CI) workflows.
- Tool Management: Implement and manage security tools like Web Application Firewalls (WAFs), vulnerability scanners, AST tools, and dependency checkers.
- Manual and Automated Web Application Testing: Perform manual and automated testing of web applications to identify vulnerabilities such as authentication flaws, session management issues, business logic errors and common web application vulnerabilities. Validate findings from automated tools by replicating issues manually to confirm exploitability and severity.
- Reporting and Communication: Produce detailed, actionable reports tailored to technical and non-technical audiences. Effectively communicate with cross-functional stakeholders, including executive leadership, on vulnerability management and remediation strategies.
- Stay Informed on Emerging Threats: Keep updated on the latest security threats, vulnerabilities, and attack methodologies, integrating new knowledge and techniques into Application Security testing and overall security practices.
- Team Development and Cross-Training: Foster cross-training across security functions, ensuring team members are well-rounded in Security Monitoring & Response, Security Control Engineering, and Security Risk Management.
- Security Program Compliance and Reporting: Ensure all activities comply with the Bank's internal control policies, industry regulations, and legal requirements. Maintain transparent communication regarding policy noncompliance, potential violations, and operational risks.
- Bachelor's degree in computer science, Cybersecurity, Information Security, or a related field. Equivalent experience will also be considered.
- 3-5 years of experience in application security, software development, or a related field.
- Experience with secure coding practices and tools (e.g., Burp Suite, OWASP ZAP, SAST, SCA, DAST, WAF)
- Technical Expertise: Proficiency in programming languages (e.g., C#, Python, JavaScript, PowerShell, Bash).
- Web Application Testing Tool Proficiency: Expert in industry-standard security tools (e.g., Burp Suite, OWASP ZAP) and frameworks for assessing vulnerabilities.
- Cloud and Application Security Knowledge: Experience with web application frameworks, APIs, microservices, and major cloud environments (AWS, Azure, GCP), as well as familiarity with secure SDLC and DevSecOps practices.
- Regulatory Knowledge: Familiarity with compliance requirements for regulated industries, especially banking, including FDIC regulations.
- Leadership and Problem-Solving: Strong decision-making, project management, and problem-solving skills. Able to motivate and guide teams effectively under pressure and tight deadlines.
- Communication and Collaboration: Skilled in communicating complex security issues to diverse audiences, building partnerships across technical and executive teams.
- Cybersecurity Passion and Insight: Demonstrates a proactive approach to cybersecurity, staying updated on industry trends, threats, and emerging hacking techniques.
Our Employee Value Proposition
- Competitive Pay, including a Bonus Target or Variable Pay Incentive Program
- Benefits Package -Medical, Dental, and Vision (plus much more)
- 401(k) Plan with Company Match
- Short- & Long-Term Disability
- Wellness Programs
- Group Life and AD&D Insurance
- Paid Vacation, Sick Days and bank Holidays
- Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition
We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.
We are an equal opportunity employer, and we evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status or any other legally protected characteristic. We will conduct a thorough background check for all hires in compliance with applicable.
-
Engineer I
2 months ago
South Jordan, United States Merrick Bank Full timeMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right thing, putting the customer...
-
Information Security Specialist
2 weeks ago
South Jordan, Utah, United States Merrick Bank Full timeAbout Merrick BankMerrick Bank is a leading financial institution, committed to delivering exceptional customer experiences. We are seeking a highly skilled Senior Security Engineer to join our team.This role requires a strong understanding of security concepts, defense-in-depth strategies, and security tools. The ideal candidate will have 6+ years of...
-
South Jordan, Utah, United States Merrick Bank Full timeAbout the RoleWe are looking for a talented Offensive Security Engineer I to join our team at Merrick Bank. This role offers the opportunity to work on various aspects of information security, including application and development security, application penetration testing capabilities, and cloud infrastructure/platform security.Key Responsibilities:Red Team...
-
Chief Information Security Officer
2 weeks ago
South Jordan, Utah, United States Merrick Bank Full timeAbout the RoleWe are seeking an experienced Cybersecurity Engineer Lead to join our team at Merrick Bank. This is a challenging and rewarding role that will require you to lead the development of advanced security solutions, collaborate with cross-functional teams, and stay up-to-date on the latest security threats and technologies.The estimated salary for...
-
Offensive Security Engineer Specialist
2 weeks ago
South Jordan, Utah, United States Merrick Bank Full timeJob SummaryMerrick Bank is seeking a highly skilled Offensive Security Engineer I to join our team. As an essential member of our security operations, you will be responsible for operating, monitoring, and improving information security processes and systems that protect the bank's data, customers, and computer systems from business disruption, data/identity...
-
Senior Offensive Security Engineer
1 month ago
South Jordan, United States Merrick Bank Full timePosition Summary:The Senior Offensive Security Engineer operates, monitors, and improves information security processes and systems that protect the Bank’s data, customers, and computer systems from business disruption, data/identity compromise, cyber fraud, and regulatory criticism. This role focuses on application and development security, application...
-
Sr. Engineer, Security Monitoring
2 months ago
South Jordan, United States Merrick Bank Full timeMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right thing, putting the customer...
-
Sr. Offensive Security Engineer, Security Monitoring
2 months ago
South Jordan, United States Merrick Bank Full timeMerrick Bank employees share in our mission to delight our customers and empower underserved consumers to achieve their credit goals. In return, we delight our associates; ensuring they are noticed, heard, appreciated and understand the importance of their role(s). For over 20 years, our Guiding Principles of; doing the right thing, putting the customer...
-
Sr. Engineer, Security Monitoring
2 days ago
South Jordan, United States Merrick Bank Full timeJoin our team - and take the next step in achieving a fulfilling career! What We Do At CardWorks, we aim to help people connect with possibility and opportunity using our financial servicing expertise. Building meaningful, long-term relationships with consumers, our employees, and our clients is what matters most. Who We Are CardWorks, Inc. is a diversified...
-
OEM Project Engineer II
2 weeks ago
South Jordan, United States Merit Medical Full timeWhy Merit? At Merit Medical, our mission is to create innovative medical devices that improve lives. Our goal is to hire and develop people who want to build something special through hard work, team effort, and commitment. Together, we are making a difference in the lives of patients around the world. WORK SHIFT DAY (United States of America) SUMMARY OF...
-
Cybersecurity Engineer
2 weeks ago
South Jordan, Utah, United States Merrick Bank Full timeAbout Merrick BankMerrick Bank is a leading provider of financial services, dedicated to helping underserved consumers achieve their credit goals. Our mission is to delight our customers and empower them to succeed.The ideal candidate will have 6+ years of experience in cybersecurity engineering, with a strong background in security monitoring and incident...
-
Security Assurance Lead
2 weeks ago
South Jordan, Utah, United States Merrick Bank Full timeJob SummaryWe are seeking a highly skilled Senior Security Engineer to join our team at Merrick Bank. This role requires a strong background in cybersecurity engineering, with a focus on security monitoring and incident response.The ideal candidate will have 6+ years of experience in cybersecurity engineering, with a strong understanding of security...
-
South Jordan, Utah, United States Merrick Bank Full timeJob OverviewThis exciting role at Merrick Bank requires an exceptional Senior Offensive Security Engineer to protect our data, customers, and computer systems from cyber threats. The successful candidate will be responsible for operating, monitoring, and improving information security processes and systems.About the RoleThe Senior Offensive Security Engineer...
-
Network Security Systems Manager
2 weeks ago
South Jordan, Utah, United States Creative Financial Staffing Full timeIT Network and Security Engineer Job SummaryWe are seeking a talented IT Network and Security Engineer to join our team in Hartford, CT. The successful candidate will have a strong background in network security systems and excellent knowledge of network segmentation/traffic and SD-WAN.Key ResponsibilitiesThe IT Network and Security Engineer will be...
-
Data Engineering Lead
2 weeks ago
South Jordan, Utah, United States Creative Financial Staffing Full timeJob Overview:We are seeking an experienced Data Engineering Lead to join our team at Creative Financial Staffing. This is a challenging role for someone who wants to lead the development of data engineering solutions on AWS.The successful candidate will be responsible for designing and implementing data lakes, data warehouses, and cloud-based solutions on...
-
Product Development Engineer
2 weeks ago
South Jordan, Utah, United States Merit Medical Full timeWe are seeking a highly skilled Product Development Engineer to join our team at Merit Medical. As an OEM Project Engineer II, you will play a critical role in providing product marketing and analysis support, as well as special project management. Your primary responsibility will be to gather new standard OEM product ideas, evaluate their potential and...
-
Azure Cloud Systems Engineer
2 weeks ago
South Jordan, Utah, United States Creative Financial Staffing Full timeAbout Our TeamWe are a well-established forward-thinking financial services organization that is revolutionizing the industry through cutting-edge technology. Our leadership team is dedicated to employee success by embracing innovation, fostering creativity, and striving for excellence in all endeavors.Job SummaryWe are seeking a talented Cloud Engineer to...
-
Information Security Strategist
4 weeks ago
South Burlington, Vermont, United States The University of Vermont Health Network Full timeAt The University of Vermont Health Network, we are seeking an experienced Information Security Strategist to join our team. This role offers a competitive salary of $115,000 per year.About the RoleThe successful candidate will be responsible for developing, implementing, maintaining, and facilitating key functions of UVMHN's IT Risk and Resilience Program,...
-
Information Technology Strategist
2 weeks ago
South Jordan, Utah, United States Creative Financial Staffing Full timeAbout the Job:Creative Financial Staffing is seeking a skilled Information Technology Strategist to join our team as a Senior Solutions Architect. This is a great opportunity for an experienced professional to lead the design and development of end-to-end solutions that meet business requirements.Responsibilities:Serves as a subject matter expert for...
-
Senior Security Engineer
4 weeks ago
South Boston, United States Merlin Labs Full timeAbout Merlin: Merlin is a venture-backed aerospace startup building a non-human pilot to enable both reduced crew and uncrewed flight. Backed by some of the worlds leading investors, Merlin is scaling alongside our customers to begin leveraging autonomy today to solve some of aviations biggest challenges. About you: You are an experienced professional with a...