Lead, Security Engineer V&CM
π’ Common Securitization Solutions Β· all Common Securitization Solutions jobs
π United States
π° USD 156,500 - 181,000 / annual
π
Posted 2026-08-18 Β· via Himalayas
π· Infosec,Vulnerability-Management,Security-Engineering,Cloud-Security,Compliance-Management,Lead-Security-Engineer,Security-Engineering-Lead,Lead-Cybersecurity-Engineer,Security-Lead,Security-Architecture-Lead
Apply on original site βOVERVIEW
The Company
U.S. Financial Technology (U.S. FinTech) is seeking an experienced Lead, Security Engineer Vulnerability and Configuration Management to join our team of talented professionals. This is a full-time remote opportunity.
U.S. FinTech built and operates the largest and most advanced mortgage securitization platform in the world, supporting the Uniform Mortgage-Backed Security (UMBS) of Fannie Mae and Freddie Mac.
Supporting 70% of the mortgage-backed securities in the market, U.S. FinTech provides best-in-class single-family issuance, bond administration, disclosure, and tax services. We support a broad portfolio of products for our clients with full lifecycle management.
Our market-leading, cloud-based, end-to-end platform executes transactions on an extraordinary scale which has bolstered liquidity in the secondary mortgage market, one of the largest and most important financial markets in the world. Our unique approach to securitization combines the best minds in financial services with the know-how, flexibility, and innovation of leading technologists.
RESPONSIBILITIES
Job Information
The Lead Vulnerability and Compliance Analyst main responsibilities would be to act as a Subject Matter Expert for all programs within the VCM space. This would include conducting comprehensive vulnerability assessments using tools such as Wiz and Tenable. Leverage strong analytical and problem-solving skills to identify weaknesses in US FinTechβs IT Infrastructure. Communicate findings effectively, via reports/meetings to prioritize vulnerability remediation. Utilize the developed processes to track, prioritize, and ensure remediation of found vulnerability and compliance issues. Continuous monitor US FinTech infrastructure for Vulnerability and Compliance related issues. Make Improvements to monitors, scans, dashboards, and reporting. Ability to work independently and in a team environment, collaborate effectively with other InfoSec Teams and IT Infrastructure teams. Eager to learn and adapt to emerging cloud technologies and tools in a fast-paced environment.
Key Job Functions
- Vulnerability Assessment
- Act as a Subject Matter Expert for the VCM program, processes, and tooling.
- Configure, tune, and maintain vulnerability management tools
- Work with Security Architecture on new build outs, new business, new technologies, new environments to ensure coverage of VCM programs, processes, and tooling.
- Build out new Security baselines for CIS, DISA STIG, and custom baselines.
- Correlate Vulnerabilities with threat intelligence to assess exploitability and risk. Work with Cyber Security Operations Center to ensure mitigations are in place while vulnerabilities are being remediated
- Provide detailed risk assessments for discovered vulnerabilities.
- Enforce remediation timelines in accordance with Standard Operating Procedures. - Remediation Tracking & Reporting
- Collaborate with IT and DevOps teams to ensure timely remediation of vulnerabilities
- Conduct regular and ad-hoc vulnerability scans using tools like Wiz or Tenable
- Integrate tools with all cloud environments. Ensure complete coverage of all IT environments.
- Ensure alignment with internal security policies, regulatory requirements (NIST/SOC), and industry best practices.
- Support audits and assessments by providing evidence and documentation. - Stakeholder Engagement
- Act as a liaison between security, IT, development, and risk teams
- Provide clear, actionable recommendations tailored to technical and non-technical audiences. - Mentor Junior Analysts
- Provide guidance and training to junior members of the VCM team. - Process Improvements
- Identify potential gaps in the vulnerability or compliance management programs and propose improvements.
- Develop and maintain Standard Operating Procedures, Frameworks, and Job Aids/HowTos.
QUALIFICATIONS
Education
- Bachelor's Degree or equivalent required.BA/BS degree in Computer Sc