Sr Information Security Systems Engineer
Description
Position Summary:
Responsible for designing, implementing, and operating enterprise-grade security engineering solutions with a focus on data loss prevention (DLP), sensitive data protection, and AI security controls across loanDepot’s technology environment. This role performs engineering, configuration, and continuous improvement of security tooling across SaaS, cloud, endpoint, and application layers.
Partners various technology teams to embed data protection and AI risk controls into the security stack, ensuring the protection of loanDepot’s proprietary data, regulated information, and AI-enabled workflows. Guides the implementation and monitoring of enterprise-wide threat, vulnerability, and data exposure management capabilities, while enforcing security best practices, standards, and policies to mitigate internal and external risk.
Responsibilities:
- Designs, engineers, and maintains Data Loss Prevention (DLP) controls across cloud, SaaS, endpoint, and application environments, including policy design, alert tuning, exception handling, and ongoing optimization to reduce data exfiltration risk.
- Responsible for security engineering efforts for AI security tooling and controls, including configuration and enforcement of safeguards for generative AI platforms, AI-enabled SaaS applications, and internally developed AI capabilities to prevent data leakage, misuse, and unauthorized model access.
- Designs and implements new technologies, frameworks, and platform improvements. Serves as subject-matter expert for application security, engaging, collaborating, and advising on application security and application security analytics practices, standards, and methods.
- Collaborates with development and DevOps teams to integrate Azure security services (e.g., Azure Key Vault, Azure Security Center, Azure Active Directory) into CI/CD pipelines.
- Provides guidance on secure use of Azure App Services, Azure Functions, and containerized workloads in AKS (Azure Kubernetes Service).
- Configures resources to detect vulnerabilities to operating systems, applications, databases, and the network infrastructure components. Detects, enumerates, and classifies major vulnerabilities, performs trend analysis and reporting using vulnerability assessment tools and methodologies.
- Provides oversight and assurance for assessment of enterprise applications, including web, cloud, and mobile applications to deliver secure and robust solutions.
- Works with development and infrastructure members to identify and resolve security issues in context of any potential compensating controls (WAF, IPS, IDS, ML, AI, NBA, EUBA, CASB).
- Works with software developers to integrate application security across the entire CI/CD pipeline.
- Formulates and interprets penetration test information results for the enterprise. Manages vulnerability detection, analysis, and exploitation remediation to ensure confidentiality, integrity, and availability of mission critical information assets.
- Provides guidance using specialized knowledge and toolsets to operational teams during enterprise-wide crisis scenarios outside of the routine change management process or production scope.
- Performs other duties and projects assigned.
Requirements:
- Bachelor’s Degree in Computer Information Systems, Computer Science, Business, Engineering, or related field preferred and a minimum of ten (10) + years’ experience working in a similar field.
- Experience working in an information security organization and understanding of Governance, Risk, and Controls processes.
- Experience with vulnerability management, application security concepts, best practices, and architectures for API, Microservices, networking and data.
- Prior experience with application software development life cycle (SDLC) and Security Software development life cycle (SSDLC) required.
- Demonstrated comprehensive knowledge of networking components (routers, switches, load balancers, wireless access points); client/server relationships; relational databases and structured query language; encryption algorithms and ciphers (PKI/SSL); malicious code (works, viruses spyware, etc.); Virtual Private Networking; and multi-tier environments).
- Prior experience with DAST/SAST/WSA/API and OWASP Top 10 security controls.
- Experience in Waterfall, Agile, SCRUM, CI/CD and DevOps – secure DevOps experience a plus.
- Experience with Windows, macOS, Linux, and Unix operating systems.
- Preferred Certifications: CISSP, GIAC, CRISC, GCIH, CEH, GSEC, CCNA.
- Experience in the Mortgage industry preferred.
Why work for #teamloanDepot:
- Work with other passionate, purposeful, and customer-centric team members.
- Inclusive, diverse, and collaborative culture where people from all backgrounds can thrive.
- Extensive internal growth and professional development opportunities including tuition reimbursement.
- Comprehensive benefits package including Medical/Dental/Vision.
- Wellness program to support both mental and physical health.
- Generous paid time off options to support work-life balance.
About loanDepot:
loanDepot (NYSE: LDI) is a digital commerce company committed to serving its customers throughout the home ownership journey. Since its launch in 2010, loanDepot has revolutionized the mortgage industry with a digital-first approach that makes it easier, faster, and less stressful to purchase or refinance a home. Today, loanDepot enables customers to achieve the American dream of homeownership through a broad suite of lending and real estate services that simplify one of life's most complex transactions. With headquarters in Southern California and offices nationwide, loanDepot is committed to serving the communities in which its team lives and works through a variety of local, regional, and national philanthropic efforts.
Base pay is one part of our total compensation package and is determined within a range. This provides the opportunity to progress as you grow and develop within a role. The base pay for this role is between $130,000 and $178,000. Your base pay will depend on multiple individualized factors, including your job-related knowledge/skills, qualifications, experience, and market location.
We are an equal opportunity employer and value diversity in our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.