Supernova Technology

Senior Information Security Engineer

About Supernova Technology

Founded in 2014, we offer the industry’s first and only cloud-based, fully-customizable, end-to-end software solution to automate securities-based lending from origination through the life of the loan. By combining thought leadership in suitability and risk management with industry-leading education and the latest technology, Supernova enables advisors to deliver holistic, goals-based advice and to help their clients achieve financial wellness. We partner with the industry’s largest banks, most prominent insurance companies and leading online brokerages to democratize access to securities-based lending and better the entire financial ecosystem.


Why Join Supernova?

At Supernova Technology, we believe that the best results come from a team that is passionate, driven, and supported in all aspects of their professional lives. Here, you’ll work alongside talented and innovative individuals who are committed to driving the future of securities-based lending technology. We foster a culture of collaboration, continuous learning, and growth, where each person’s contributions make a real impact.


About the Role

We are seeking a highly skilled and hands-on Senior Security Engineer to help protect Supernova’s financial technology platform and enterprise environment. This senior individual-contributor role combines proactive threat hunting, detection engineering, incident response, and ownership of critical security technologies and infrastructure.

 

The successful candidate will be a trusted technical leader capable of operating independently, making sound risk-based decisions, and leading complex security projects from requirements and design through implementation, testing, documentation, and ongoing operation. You will work across endpoint, identity, network, cloud, application, and SaaS environments to identify threats, strengthen controls, and continually improve Supernova’s security posture.

 

This role is well suited for someone who enjoys both investigating sophisticated security activity and building the systems, integrations, and processes needed to prevent, detect, and respond to it.


Responsibilities

Threat Hunting & Detection

  • Run hypothesis-driven and intelligence-led threat hunts across endpoint, network, identity, cloud, email, application, and SaaS telemetry, analyzing large datasets to surface suspicious behavior, control gaps, and emerging attack techniques.
  • Turn threat intel and adversary TTPs into hunt hypotheses and detection logic; build and tune SIEM queries, correlation rules, dashboards, and alerts aligned to MITRE ATT&CK.
  • Convert hunt findings and incident lessons into durable detections, prevention controls, and playbooks; continuously evaluate detection coverage, false-positive rates, and telemetry quality.
  • Track emerging threats relevant to financial services, cloud, and software supply chains.


Security Engineering & Platform Ownership

  • Design, implement, test, and own security technologies end-to-end, including SIEM, EDR/XDR, IDS/IPS, firewalls, WAF, vulnerability management, email security, identity protections, and automation, from requirements and design through deployment, documentation, post-implementation validation, and ongoing operation.
  • Strengthen security across AWS, Microsoft 365, Entra ID, Windows, macOS, Linux, containers, and SaaS, partnering with infrastructure, IT, and engineering teams.
  • Improve endpoint and identity controls: secure configuration, conditional access, least privilege, account lifecycle, and credential hygiene.
  • Maintain documentation, standards, and runbooks for owned systems; manage vendor relationships.


Incident Response & Vulnerability Management

  • Act as the senior technical escalation point and lead incident response, including triage, scoping, containment, eradication, recovery, evidence preservation, root-cause analysis, and lessons learned across endpoint, identity, network, cloud, email, and application environments.
  • Build and test IR playbooks for high-risk scenarios.
  • Lead vulnerability management, including identification, validation, risk-based prioritization, remediation coordination, retesting, and closure, partnering with system owners to track risk through resolution.
  • Coordinate security assessments, pen testing, and adversary simulation as needed.


Automation & Continuous Improvement

  • Build scripts, integrations, and automated workflows (Python, PowerShell, APIs) to improve visibility and reduce manual effort.
  • Establish security metrics (detection coverage, remediation performance, incident trends) and use them to drive improvement.
  • Own and improve network security controls, including firewall policies, VPN and secure connectivity, segmentation, traffic filtering, and associated monitoring. Review proposed systems, integrations, and architecture changes to define practical, risk-based security requirements.
  • Evaluate AI-assisted security workflows responsibly, with safeguards for sensitive data and human validation.


Collaboration & Leadership

  • Lead cross-functional security initiatives and act as a trusted advisor to engineering, IT, legal, and business teams, including during high-impact incidents with incomplete information.
  • Mentor junior team members and help build repeatable team practices.
  • Support audits/assessments and help maintain policies and standards aligned to NIST, ISO 27001, SOC 2, and financial-services requirements.

Qualifications

  • 5+ years in security engineering, threat hunting, detection engineering, security operations, incident response, or infrastructure security.
  • Proven ability to independently lead complex technical projects end-to-end.
  • Hands-on experience with enterprise security platforms (SIEM, EDR/XDR, firewalls, IDS/IPS, WAF, vuln management, email/identity security) and threat hunting across varied telemetry.
  • Strong knowledge of attacker TTPs, IR processes, and MITRE ATT&CK.
  • Solid grasp of network security fundamentals (segmentation, firewalls, VPNs, DNS, HTTP/TLS, access control).
  • Experience securing cloud/enterprise environments (AWS, M365, Entra ID, Windows, macOS, Linux preferred).
  • Scripting/automation ability (Python, PowerShell, Bash, REST APIs).
  • Strong analytical skills with incomplete/ambiguous information, and excellent communication with technical and non-technical audiences.
  • High integrity and discretion with privileged systems and sensitive investigations.
  • Fintech, financial services, or other regulated tech experience preferred.
  • Familiarity with tools like CrowdStrike, Microsoft Defender, Splunk, Rapid7, Palo Alto, Fortinet, Cisco, or Cloudflare preferred.
  • AWS security services, cloud-native detection, and Docker/ECS or comparable container-security experience preferred.
  • DevSecOps practices (SAST, DAST, SCA, secrets detection, CI/CD, IaC) preferred.
  • Digital forensics, malware analysis, or offensive security experience preferred.
  • SOAR/detection-as-code pipeline experience preferred.
  • Threat intel platforms and OSINT techniques preferred.
  • Relevant degree or certifications (CISSP, GCIH, GCIA, GCFA, GNFA, OSCP, CCSP, AWS Security Specialty, etc.) preferred.


Our Employee Benefits

At Supernova Technology, we provide a robust benefits package to support the health and well-being of our employees. Our offerings include:

  • Medical, Dental, and Vision Insurance: Multiple plans with coverage for employees and dependents.
  • HSA and FSA Accounts: Tax-advantaged accounts for health and dependent care expenses.
  • Life and Disability Insurance: Employer-paid basic coverage with options for additional voluntary coverage.
  • Compensation: $110,000 - $140,000 per year
  • Retirement Savings: 401(k) plan with employer contributions.
  • Employee Assistance Program (EAP): Confidential support services, including free therapy sessions.
  • Paid Time Off: Flexible PTO policies.
  • Additional Perks: Commuter benefits, pet insurance, continuing education assistance, and more.

Note: Actual salary at the time of hire may vary and may be above or below the range based on various factors, including but not limited to, the candidate's relevant qualifications, skills and experience, and the location where this position may be filled.


Join us and make an impact while growing your career at Supernova!

Technology

Chicago, IL

Compartilhar no:

Termos de serviçoPrivacidadeCookiesDesenvolvido pela Rippling