Cyber Security Engineer

Posted 2 hours ago
Bci Miami
About Bci

Bci provides financial services to individuals and corporation. We focus on being a global leader in innovations and personalized client experience and, with more than

10,500 employees, Bci is recognized as one of the best companies in which to work and develop a career. It is the third largest privately owned bank in Chile and it has more than 300 branch offices throughout Chile and representative offices in other countries.

Bci is an Equal Opportunity Employer - All qualified applicants will receive consideration without regard to race, color, religion, gender, national origin, age, disability, veteran status, or any other factor determined to be unlawful under applicable law.

Job Summary

We are seeking a hands-on, highly skilled Cybersecurity Engineer to join our Information Security team. In this role, you will be directly responsible for protecting our digital assets, sensitive customer data, and internal systems against sophisticated attack vectors, including emerging AI-driven threats.

This position requires a strategic yet hands-on defender who prioritizes proactive remediation over reactive firefighting. You will lead enterprise-wide patch management, maintain critical security platforms, and actively hunt for threats while ensuring our defenses align with the NIST Cybersecurity Framework (CSF) and high-level banking regulations. By collaborating across IT, Compliance, and offensive/defensive security disciplines, you will help continuously harden our environment and maintain a robust, audit-ready security posture.

DUTIES OF THE POSITION

The duties of the position include, but are not limited to, the following: 2. Threat Monitoring, Detection & Incident Response 3. Endpoint & Security Platform Engineering 4. Governance, Regulatory Compliance & Documentation

  • Proactive Remediation & Vulnerability Management
  • Lead Enterprise Patching: Plan, test, schedule, and execute system patch deployments across all endpoints, mobile devices, servers, and network infrastructure, focusing on rapid, proactive remediation to minimize the attack surface.
  • Vulnerability Assessments: Conduct continuous vulnerability scans and assessments; prioritize risks and partner with IT teams to drive remediation efforts before vulnerabilities can be exploited.
  • Asset Hardening: Establish, document, and enforce baseline security hardening standards across all enterprise assets and systems.
  • Active Monitoring & AI Threat Defense: Monitor security event logs for suspicious activities, anomalies, and potential breaches. Stay ahead of emerging AI threats (such as automated phishing, adversarial machine learning, and deepfake social engineering) by continuously updating detection logic.
  • Red and Blue Teaming Collaboration: Participate in and support red and blue team (purple teaming) exercises to validate the efficacy of our security controls, identify blind spots, and tune our alerting systems based on simulated real-world attacks.
  • Incident Response & Automation: Lead incident investigation and containment efforts during high-impact security events.
  • Endpoint Protection: Oversee the implementation, configuration, and daily management of Endpoint Detection and Response (EDR) solutions, Anti-Virus, DLP, and device access controls.
  • Tool Administration: Provide hands-on management for critical security platforms, including Security Email Gateways, IPS/IDS, and database security controls.
  • Cloud & Infrastructure Security: Support secure configurations and continuous security monitoring for cloud environments (AWS, Azure, SaaS, Office 365) in alignment with industry frameworks.
  • Framework & Regulatory Alignment: Ensure all technical controls, architectures, and operational procedures map directly to NIST Frameworks (CSF, SP 800-53) and demonstrate a strong understanding of banking regulations at a high level (such as FFIEC, GLBA, and FINRA).
  • Audit Readiness & Documentation: Enforce security policies, network/architecture diagrams, and standard operating procedures (SOPs). Assist internal and external auditors during security reviews.
  • Ability to understand, speak, read and write English and Spanish
  • Effectively speaking before groups of customers or employees
  • Assume evolving duties and responsibilities of position
  • Work all hours required to fulfill job duties and responsibilities (including, weekends, evenings and holidays as needed)
  • Travel as required
  • Provide coverage for other positions as requested
  • Ability to carry and lift boxes and objects that may weigh between 10 and 25 pounds.
  • Perform additional duties and responsibilities as assigned by management

Computer

PRE-HIRE REQUIREMENTS FOR THIS POSITION:

Ability to operate IBM compatible personal computers; fluency with Microsoft Word, Microsoft Excel, Microsoft PowerPoint and

Education

  • Degree in Information Security, Computer Science, Software Engineering, Management Information Systems, or practical background equivalent.
  • Minimum of 3 to 5 years executing hands-on responsibilities across SecOps, security engineering, or system defense.
  • Proven experience operating in heavily regulated sectors, maintaining strong familiarity with financial institution standards and banking compliance requirements.

Certifications/Licenses

  • Core Security: CISSP, CISA, OSCP, CHFI, or CISM
  • Operations & Cloud: CCSP, AWS Certified Security, Azure Security Engineer, Google Secops

EXPERIENCE:

  • Proactive Defense: A strong mindset for proactive remediation and vulnerability lifecycle management, with in-depth understanding of enterprise patch deployment processes.
  • Framework Expertise: Working knowledge and practical experience implementing the NIST Cybersecurity Framework.
  • Offensive/Defensive Dynamics: Familiarity with red and blue teaming methodologies and how to translate offensive findings into defensive engineering improvements.
  • Modern Threat Landscape: Up-to-date awareness of emerging AI threats and how large language models (LLMs) and artificial intelligence are altering the cyber threat landscape.
  • Hands-on Platform Skills: Proven experience configuring and supporting EDR tools, Firewalls, Secure Email Gateways, and vulnerability scanners.
  • Scripting Ability: Proficiency with Python, Bash, or PowerShell for automation and task execution.
  • Communication & Collaboration: Excellent verbal and written communication skills with the ability to explain complex regulatory and technical concepts to non-technical business partners.
Login to Apply Now

Recommended Jobs

Software Security Analyst

Posted 1 hour ago

Security Analyst

Posted 1 hour ago

Senior Cyber Threat Analyst

Posted 1 hour ago