First Citizens Bank is seeking a Cyber Security Engineer II to join their Cyber Risk Reduction team. The role involves supporting the rollout of the bank's Identity Risk Identification platform, improving visibility into identities and access relationships, and working with various stakeholders to onboard applications and build queries for identity-focused risk identification.
Responsibilities:
- Veza Application Integrations
- Coordinate with application owners and technical teams to onboard applications into Veza
- Support integration planning, information gathering, validation, and follow-up activities
- Confirm that integrated applications produce accurate and meaningful identity, entitlement, role, and permission visibility
- Identify gaps in integration data quality and work with application teams or internal partners to resolve issues
- Track integration progress and ensure assigned onboarding work moves forward consistently
- Veza Query Building and Identity Risk Identification
- Build and validate Veza queries to identify identity-focused risks across integrated applications
- Develop queries that help detect violations of IAM standards, excessive access, privileged access, non-human identity risks, and segregation-of-duties concerns
- Partner with senior team members and stakeholders to translate risk scenarios into accurate Veza query logic
- Validate query results for accuracy, explainability, and usefulness before promoting queries for broader use
- Help maintain a library of reusable queries, patterns, and documentation for common identity risk use cases
- Documentation, Tracking, and Auditability
- Maintain accurate records of integration work, query development, testing, decisions, and follow-ups in Jira and team tracking artifacts
- Create and contribute to SOPs, implementation guides, troubleshooting documentation, and knowledge articles in Confluence and SharePoint
- Ensure work is documented in a way that supports auditability, handoff, operational continuity, and future process improvement
- Keep trackers and status artifacts current, complete, and easy for others to understand
- Collaboration and Stakeholder Engagement
- Work directly with application teams, identity teams, cyber risk partners, and other internal stakeholders
- Participate actively in meetings, standups, working sessions, and integration discussions
- Ask thoughtful questions, clarify requirements, and surface blockers early
- Help create a collaborative environment where application teams understand the purpose and value of Veza onboarding
- Build strong working relationships through professionalism, accountability, and follow-through
- Professional Communication
- Communicate clearly and professionally in emails, Jira tickets, meeting notes, documentation, and status updates
- Provide timely updates on assigned work, including progress, blockers, risks, and next steps
- Tailor communication appropriately for technical and non-technical audiences
- Follow up consistently and ensure commitments are completed or escalated when needed
- Integrity, Ownership, and Continuous Improvement
- Demonstrate strong personal ownership and reliability in all assigned work
- Do the right thing, even when the right path is slower, more complex, or requires additional diligence
- Look for opportunities to improve processes, reduce manual effort, increase quality, and improve team execution
- Proactively seek feedback, learn from teammates, and contribute to a culture of trust, accountability, and continuous improvement
Requirements:
- Bachelor's Degree and 4 years of experience in Systems Engineering, Network, or Information Security OR High School Diploma or GED and 8 years of experience in Systems Engineering, Network, or Information Security
- Strong integrity, ownership, reliability, and follow-through
- Demonstrated ability to work independently while staying aligned with team priorities and expectations
- Strong desire to learn and grow in identity security, access governance, and cyber risk reduction
- Proactive approach to learning, including reading vendor documentation, researching issues, and asking thoughtful questions
- Familiarity with identity and access management concepts, including: Accounts, Users, Groups, Roles, Entitlements, Permissions, Least privilege, Privileged access, Segregation of duties
- Ability to evaluate competing priorities and make sound decisions in the best interest of the project and team
- Comfort working directly with application teams, business stakeholders, and technical partners
- Strong written communication skills, including clear documentation, concise status updates, and professional ticket comments
- Experience using ticketing, tracking, or documentation platforms such as Jira, ServiceNow, Confluence, SharePoint, or similar tools
- Strong attention to detail and commitment to maintaining accurate trackers, documentation, and audit trails
- Basic understanding of cybersecurity risks, vulnerabilities, attacker techniques, and control concepts
- Experience with the Veza platform, especially: Application integrations, Query Builder, Access graph concepts, Identity risk queries, Enrichment rules or tagging
- Experience with identity governance, identity security, IAM, PAM, or access review processes
- Experience working with application onboarding, access modeling, entitlement discovery, or identity data mapping
- Familiarity with Okta, Active Directory, Azure AD, ServiceNow, SailPoint, CyberArk, or similar identity/security platforms
- Python scripting experience, especially for: API integrations, Data transformation, Automation, Building OAA connectors or similar integration patterns
- Familiarity with REST APIs, JSON, OAuth, SAML, SCIM, or other integration concepts
- Experience working in Agile environments, including standups, backlogs, sprint planning, user stories, and acceptance criteria
- Experience analyzing data in Excel, Power Query, or similar tools to reconcile application, identity, or access datasets