Supernova Technology Logo

Supernova Technology

Senior Information Security Engineer

Posted 34 Minutes Ago
Be an Early Applicant
Hybrid
Chicago, IL
110K-140K Annually
Senior level
Hybrid
Chicago, IL
110K-140K Annually
Senior level
Leads threat hunting, detection engineering, incident response, vulnerability management, and security platform ownership across endpoint, identity, network, cloud, application, and SaaS environments. Designs and operates security controls, automates workflows using scripts and APIs, manages incident response and assessments, improves network security, establishes metrics, and supports compliance with NIST, ISO 27001, SOC 2, and financial-services requirements. Mentors junior staff and advises cross-functional teams.
The summary above was generated by AI

About Supernova Technology

Founded in 2014, we offer the industry’s first and only cloud-based, fully-customizable, end-to-end software solution to automate securities-based lending from origination through the life of the loan. By combining thought leadership in suitability and risk management with industry-leading education and the latest technology, Supernova enables advisors to deliver holistic, goals-based advice and to help their clients achieve financial wellness. We partner with the industry’s largest banks, most prominent insurance companies and leading online brokerages to democratize access to securities-based lending and better the entire financial ecosystem.


Why Join Supernova?

At Supernova Technology, we believe that the best results come from a team that is passionate, driven, and supported in all aspects of their professional lives. Here, you’ll work alongside talented and innovative individuals who are committed to driving the future of securities-based lending technology. We foster a culture of collaboration, continuous learning, and growth, where each person’s contributions make a real impact.


About the Role

We are seeking a highly skilled and hands-on Senior Security Engineer to help protect Supernova’s financial technology platform and enterprise environment. This senior individual-contributor role combines proactive threat hunting, detection engineering, incident response, and ownership of critical security technologies and infrastructure.

 

The successful candidate will be a trusted technical leader capable of operating independently, making sound risk-based decisions, and leading complex security projects from requirements and design through implementation, testing, documentation, and ongoing operation. You will work across endpoint, identity, network, cloud, application, and SaaS environments to identify threats, strengthen controls, and continually improve Supernova’s security posture.

 

This role is well suited for someone who enjoys both investigating sophisticated security activity and building the systems, integrations, and processes needed to prevent, detect, and respond to it.


Responsibilities

Threat Hunting & Detection

  • Run hypothesis-driven and intelligence-led threat hunts across endpoint, network, identity, cloud, email, application, and SaaS telemetry, analyzing large datasets to surface suspicious behavior, control gaps, and emerging attack techniques.
  • Turn threat intel and adversary TTPs into hunt hypotheses and detection logic; build and tune SIEM queries, correlation rules, dashboards, and alerts aligned to MITRE ATT&CK.
  • Convert hunt findings and incident lessons into durable detections, prevention controls, and playbooks; continuously evaluate detection coverage, false-positive rates, and telemetry quality.
  • Track emerging threats relevant to financial services, cloud, and software supply chains.


Security Engineering & Platform Ownership

  • Design, implement, test, and own security technologies end-to-end, including SIEM, EDR/XDR, IDS/IPS, firewalls, WAF, vulnerability management, email security, identity protections, and automation, from requirements and design through deployment, documentation, post-implementation validation, and ongoing operation.
  • Strengthen security across AWS, Microsoft 365, Entra ID, Windows, macOS, Linux, containers, and SaaS, partnering with infrastructure, IT, and engineering teams.
  • Improve endpoint and identity controls: secure configuration, conditional access, least privilege, account lifecycle, and credential hygiene.
  • Maintain documentation, standards, and runbooks for owned systems; manage vendor relationships.


Incident Response & Vulnerability Management

  • Act as the senior technical escalation point and lead incident response, including triage, scoping, containment, eradication, recovery, evidence preservation, root-cause analysis, and lessons learned across endpoint, identity, network, cloud, email, and application environments.
  • Build and test IR playbooks for high-risk scenarios.
  • Lead vulnerability management, including identification, validation, risk-based prioritization, remediation coordination, retesting, and closure, partnering with system owners to track risk through resolution.
  • Coordinate security assessments, pen testing, and adversary simulation as needed.


Automation & Continuous Improvement

  • Build scripts, integrations, and automated workflows (Python, PowerShell, APIs) to improve visibility and reduce manual effort.
  • Establish security metrics (detection coverage, remediation performance, incident trends) and use them to drive improvement.
  • Own and improve network security controls, including firewall policies, VPN and secure connectivity, segmentation, traffic filtering, and associated monitoring. Review proposed systems, integrations, and architecture changes to define practical, risk-based security requirements.
  • Evaluate AI-assisted security workflows responsibly, with safeguards for sensitive data and human validation.


Collaboration & Leadership

  • Lead cross-functional security initiatives and act as a trusted advisor to engineering, IT, legal, and business teams, including during high-impact incidents with incomplete information.
  • Mentor junior team members and help build repeatable team practices.
  • Support audits/assessments and help maintain policies and standards aligned to NIST, ISO 27001, SOC 2, and financial-services requirements.

Qualifications

  • 5+ years in security engineering, threat hunting, detection engineering, security operations, incident response, or infrastructure security.
  • Proven ability to independently lead complex technical projects end-to-end.
  • Hands-on experience with enterprise security platforms (SIEM, EDR/XDR, firewalls, IDS/IPS, WAF, vuln management, email/identity security) and threat hunting across varied telemetry.
  • Strong knowledge of attacker TTPs, IR processes, and MITRE ATT&CK.
  • Solid grasp of network security fundamentals (segmentation, firewalls, VPNs, DNS, HTTP/TLS, access control).
  • Experience securing cloud/enterprise environments (AWS, M365, Entra ID, Windows, macOS, Linux preferred).
  • Scripting/automation ability (Python, PowerShell, Bash, REST APIs).
  • Strong analytical skills with incomplete/ambiguous information, and excellent communication with technical and non-technical audiences.
  • High integrity and discretion with privileged systems and sensitive investigations.
  • Fintech, financial services, or other regulated tech experience preferred.
  • Familiarity with tools like CrowdStrike, Microsoft Defender, Splunk, Rapid7, Palo Alto, Fortinet, Cisco, or Cloudflare preferred.
  • AWS security services, cloud-native detection, and Docker/ECS or comparable container-security experience preferred.
  • DevSecOps practices (SAST, DAST, SCA, secrets detection, CI/CD, IaC) preferred.
  • Digital forensics, malware analysis, or offensive security experience preferred.
  • SOAR/detection-as-code pipeline experience preferred.
  • Threat intel platforms and OSINT techniques preferred.
  • Relevant degree or certifications (CISSP, GCIH, GCIA, GCFA, GNFA, OSCP, CCSP, AWS Security Specialty, etc.) preferred.


Our Employee Benefits

At Supernova Technology, we provide a robust benefits package to support the health and well-being of our employees. Our offerings include:

  • Medical, Dental, and Vision Insurance: Multiple plans with coverage for employees and dependents.
  • HSA and FSA Accounts: Tax-advantaged accounts for health and dependent care expenses.
  • Life and Disability Insurance: Employer-paid basic coverage with options for additional voluntary coverage.
  • Compensation: $110,000 - $140,000 per year
  • Retirement Savings: 401(k) plan with employer contributions.
  • Employee Assistance Program (EAP): Confidential support services, including free therapy sessions.
  • Paid Time Off: Flexible PTO policies.
  • Additional Perks: Commuter benefits, pet insurance, continuing education assistance, and more.

Note: Actual salary at the time of hire may vary and may be above or below the range based on various factors, including but not limited to, the candidate's relevant qualifications, skills and experience, and the location where this position may be filled.


Join us and make an impact while growing your career at Supernova!

Similar Jobs at Supernova Technology

7 Days Ago
Hybrid
80K-100K Annually
Entry level
80K-100K Annually
Entry level
Cloud • Fintech • Payments • Software
The Junior Software Engineer will engage in the software development life cycle, perform hands-on coding, diagnose product issues, and contribute to software deployment.
Top Skills: C/C++JavaJava Spring FrameworkJavaScriptPythonSpring Boot
8 Days Ago
Hybrid
110K-130K Annually
Mid level
110K-130K Annually
Mid level
Cloud • Fintech • Payments • Software
Lead end-to-end release management for the Data Technology team: define release scope, build and communicate release plans, coordinate dependencies, improve internal release tooling and CI/CD pipelines, manage risks and readiness activities, and drive post-release retrospectives to ensure reliable, predictable deployments to production.
Top Skills: AWSCi/CdDeployment AutomationRelease Tooling
9 Days Ago
Hybrid
90K-120K Annually
Mid level
90K-120K Annually
Mid level
Cloud • Fintech • Payments • Software
Manage implementation of Supernova's SBL platform for enterprise clients, oversee project scope, facilitate requirements gathering, and ensure timely delivery.
Top Skills: Atlassian ProductsConfluenceJIRA

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account