Title: Security Services Senior Engineer
US
Join a dynamic team at the pulse of global markets, where we deliver innovative software and service solutions for essential financial reporting and capital markets transactions. At DFIN, we are a values-driven organization that empowers you to build a fulfilling career while bringing your authentic self to work every day. Our “Win as One” mentality ensures that our team’s success is directly linked to Client, Shareholder and Employee Satisfaction.
Summary:
Plan, engineer, maintain, and continuously improve security platforms necessary to secure and monitor the global DFIN enterprise. Provide subject matter expertise for security technology initiatives across cloud, endpoint, identity, network, SaaS, data protection, vulnerability/exposure management, logging, detection, and automation capabilities. Partner with internal technology teams, business stakeholders, and external vendors to deliver secure, scalable, and resilient services that reduce cyber risk, improve operational reliability, and protect Company and Customer information. Provide engineering and operational support for security infrastructure, proactively identify security vulnerabilities and mitigation opportunities, and help advance DFIN security architecture, Zero Trust, and compliance objectives. Deliver an ideal customer experience by executing with quality, sound judgment, ownership, and strong security market awareness.
Support Responsibilities:
- Identify changes needed in security architecture, platform design, integrations, configurations, and operational processes necessary to achieve technology and security organization goals, taking into account operational impact and stakeholder needs.
- Configure, troubleshoot, optimize, and maintain security platforms across enterprise, cloud, endpoint, network, identity, and SaaS environments with a focus on reliable, supportable service delivery.
- Perform monitoring, periodic reporting, health checks, control reviews, and follow-up activities to ensure security systems are operational, effective, resilient, and aligned with applicable policies, standards, and compliance expectations.
- Analyze system performance, alert quality, coverage, data ingestion, and capacity trends; develop tuning recommendations that improve reliability, reduce noise, support capacity management, and improve measurable security outcomes.
- Manage effective issue identification and resolution processes. Serve as a senior escalation point for security engineering and operations issues with a focus on clear communication, root-cause determination, timely remediation, vendor accountability, and quality outcomes.
- Perform capacity planning and develop KPIs/KRIs for assigned security platforms, including availability, coverage, alert quality, agent health, ingestion quality, vulnerability/exposure trends, and service performance.
- Support security monitoring and protection of endpoints, workloads, identities, networks, cloud services, SaaS applications, and data transfer mechanisms in alignment with DFIN governance and compliance policies.
- Create, maintain, and improve documentation for security platforms, architecture diagrams, support processes, standard operating procedures, runbooks, configuration standards, and engineering decision records that help others understand, operate, and improve assigned services.
- Perform 24x7x365 advanced tier 1-3 support, including troubleshooting, off-hour maintenance activities, problem resolution, incident support, and on-call rotation while ensuring all activities adhere to DFIN Change Management policy.
- Provide timely, thoughtful communication during escalations, incidents, and maintenance activities, including risks, decisions, ownership, and next steps.
- Perform other related duties and participate in special projects as assigned.
Engineering Responsibilities
- Conduct high-level and low-level designs for security infrastructure, security tooling, cloud security, identity, endpoint, logging, detection, vulnerability/exposure management, and automation projects.
- Partner with technology, product, infrastructure, cloud, application, identity, architecture, compliance, and operations teams to design secure, practical, and supportable solutions.
- Design and develop security solutions and security requirements based on business, technology, compliance, and risk needs; make recommendations on security platform investments, integrations, and service improvements with clear rationale and practical implementation considerations.
- Evaluate new technologies, develop proofs of concept, document technical findings, and recommend future strategy to leadership based on risk reduction, operational fit, scalability, total cost of ownership, integration value, and long-term supportability.
- Influence security architecture standards, security platform roadmaps, and technical strategy through engineering expertise, operational experience, and evaluation of emerging technologies.
- Develop solutions to ensure security telemetry is collected, normalized, stored, filtered, analyzed, and properly monitored/alerted across SIEM, data lake, cloud-native, endpoint, identity, network, and application sources.
- Engineer and maintain automation for repeatable security tasks, including scripting, API integrations, deployment workflows, configuration management, platform health validation, and metrics reporting.
- Act as the service owner for assigned security platforms, ensuring lifecycle management, operational health, roadmap planning, adoption, supportability, and continual service improvement.
- Use metrics, lessons learned, and stakeholder feedback to identify practical improvements that increase coverage, reliability, and security maturity over time.
- Develop and deliver cross-training activities for operations, security engineering, architecture, and other technology teams to improve shared understanding and reduce operational dependency.
- Mentor and guide engineers through technical coaching, knowledge sharing, peer reviews, and collaborative problem solving to strengthen team capability and effectiveness.
- Participate in and encourage a knowledge-sharing environment both within and outside the department.
- Develop and maintain strong working knowledge of internal security infrastructure, operations, platforms, processes, and devices.
Skills
• Maintain subject matter expertise in security technologies, threat trends, vendor solutions, and engineering best practices to effectively support partner engagements and technical decision-making.
• Lead complex security initiatives independently from analysis and design through implementation, adoption, operational transition, and ongoing support.
• Leverage expertise in cloud and identity security across Azure and AWS, including security controls, posture management, Microsoft Entra ID, privileged access, conditional access, MFA, and access governance.
• Manage endpoint and risk reduction programs, including EDR/XDR, endpoint hardening, vulnerability and exposure management, cloud security posture management (CSPM), and attack surface reduction.
• Design and optimize security monitoring capabilities, including SIEM, log management, detection engineering, alert tuning, security telemetry, network security controls, firewall/WAF technologies, DNS, routing, and remote access solutions.
• Apply modern security engineering practices through automation, scripting (PowerShell, Python, Bash), APIs, container technologies (Docker, Kubernetes), Infrastructure as Code, DevSecOps, AI security considerations, and strong analytical, troubleshooting, communication, and collaboration skills.
Qualifications:
Technologies:
- Minimum of 2 years working knowledge of a major scripting or automation language such as PowerShell, Python, Bash, Perl, or comparable tools.
- Minimum of 2 years working knowledge of network management, security monitoring, troubleshooting, and observability tools.
- Working knowledge of Microsoft 365/O365, Visio, G-suite/Google Workspace, Lucidchart, or comparable productivity and diagramming tools.
- Minimum of 2 years working knowledge of public cloud (Azure, AWS), SaaS products, private cloud, or hybrid enterprise environments.
- Working knowledge of endpoint security, identity security, SIEM/logging, vulnerability management, cloud security, and network security technologies.
- Demonstrated ability to document technical designs, operational support procedures, metrics, risks, decisions, and executive-ready summaries.
- Excellent written and verbal communication skills, including the ability to explain risks, tradeoffs, recommendations, and progress clearly.
- Travel required (+/-5%).
Additional Qualifications
Work Experience Required:
- Minimum 5 to 7 years relevant work experience in security engineering, security operations engineering, infrastructure security, cloud security, identity security, endpoint security, network security, or related technology roles.
- Experience serving as a technical escalation point, platform owner, or senior engineer responsible for implementation, support, stakeholder coordination, and continuous improvement of enterprise security services is preferred.
Education and Certification:
- Bachelor’s degree in related technical or business areas is preferred; equivalent relevant experience may be considered.
- CISSP, CCSP, CISM, GIAC, Microsoft, AWS, Azure, Kubernetes, networking, cloud security, or other relevant certification preferred.
It is the policy of Donnelley Financial Solutions to select, place, and manage all its employees without discrimination based on race, color, national origin, gender, age, religion, actual or perceived disability, veteran status, actual or perceived sexual orientation, genetic information or any other protected status.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access jobs.dfinsolutions.com as a result of your disability. You can request a reasonable accommodation by sending an email to talentacquisition@dfinsolutions.com.
At DFIN, protecting your identity is a top priority. Please be aware of scammers impersonating DFIN recruiters. DFIN recruiters will never request personal information via email or text. You will only receive a text from us if you've already been in contact. All automated messages will come from talentacquisition@dfinsolutions.com. If you ever have doubts about the legitimacy of any communication from us, please do not hesitate to reach out for verification via talentacquisition@dfinsolutions.com (this email is for general TA questions and is not used for updates on your application status). #BI-Remote
Job Segment:
Cloud, Technology
