Principal Engineer, IT Infrastructure & Security
Indexed description
Department: Information Technology - Data & Reporting
Location: Bloomington, MN
Compensation: $160,000 - $175,000 / year
DescriptionWe're looking for a hands-on infrastructure and security leader to architect, secure, and operate our hybrid enterprise environment. You'll own our defense-in-depth security model and Zero Trust strategy across identity, devices, network, applications, and data. You'll be the one building and running it, not just directing it. This role also has direct oversight of our Network & Systems Administrator.Responsibilities and Duties:
Enterprise Architecture & Zero Trust — Design and implement secure infrastructure across on-prem and Azure environments, applying Zero Trust principles throughout.
- Identity-driven access, device trust enforcement, and network micro-segmentation
- Defense-in-depth strategy spanning perimeter, endpoint, identity, and data layers
- Enterprise firewall management, including advanced threat protection and application control
- Network segmentation, access control, and authentication (RADIUS/802.1X)
- Traffic analysis and anomaly detection, integrated into centralized logging/SIEM
- Azure infrastructure: VMs, VNets, load balancers, and hybrid connectivity (VPN/ExpressRoute)
- Hybrid identity via Entra ID, including conditional access, MFA, and privileged identity management
- Infrastructure-as-code and automation of cloud provisioning
- Device lifecycle management and MDM/MAM policy enforcement
- EDR/XDR deployment, tuning, and threat hunting
- Data classification, encryption, and loss prevention
- Centralized monitoring, alerting, and performance baselining
- Incident response, digital forensics, and root cause analysis
- Disaster recovery and business continuity planning and testing
- Provide after-hours support for critical UIT issues and service disruptions when necessary.
- NIST, CIS, ISO 27001, and FFIEC alignment
- Audit support, risk assessments, and architecture/control documentation
- Scripting and automation (PowerShell, Bash, or similar) across routine operations
- Technical escalation points and mentor to engineering staff
- Direct oversight of the Network & Systems Administrator
- Bachelor’s degree in computer science, information systems, cybersecurity, engineering, or a related field — or equivalent experience/certifications
- 7+ years of progressive experience in network engineering, cloud infrastructure, or cybersecurity, with hands-on ownership of enterprise-scale environments
- Strong, hands-on expertise across enterprise networking/firewalls, Microsoft Azure architecture, and modern EDR/XDR tooling
- Working knowledge of Zero Trust principles, hybrid identity (Azure AD/Entra ID), and endpoint/MDM management
- Experience supporting regulatory or compliance frameworks common in financial services (e.g., NIST, FFIEC, ISO 27001)
- Comfortable scripting and automating routine operations (PowerShell, Bash, or similar)
- Enterprise Architecture Leadership: Designs secure, scalable infrastructure aligned with business and security objectives
- Cybersecurity Expertise: Implements advanced security frameworks and defense-in-depth strategies
- Cloud & Network Engineering: Demonstrates deep expertise across hybrid infrastructure and enterprise networking
- Technical Leadership: Serves as a trusted technical authority and mentor across the organization
- Automation & Innovation: Continuously improves operational efficiency through automation and modern engineering practices
- Integrity: Protects company systems, data, and infrastructure through disciplined security and governance practices
- Collaboration: Partners across IT, Security, and business teams to deliver secure and scalable solutions
- Excellence: Maintains high standards for infrastructure reliability, performance, and operational maturity
- Critical Curiosity: Evaluates emerging technologies and continuously improves enterprise architecture and security posture
- Competitive compensation package, including base salary and performance-based bonus opportunities
- 401(k) plan with 100% company match up to 4%
- Comprehensive health coverage: medical, dental, vision, HSA, and FSA options
- Generous paid time off: 20 days PTO, company holidays, and sick time
- Paid parental leave
- Company-paid life insurance and disability coverage
- Employee Assistance Program (EAP): mental health, financial, and wellness support
- Professional development: tuition reimbursement and growth opportunities
- Commuter and transit benefits
Maintaining a reliable, uninterrupted high speed internet connection is a requirement of hybrid or remote positions.
All job duties and responsibilities must be performed within the guidelines of the Verus Residential Mortgage Employee Handbook and established company policies and procedures. It is the responsibility of each employee to maintain confidentiality of the company, its clients and to follow applicable laws and regulations in the performance of duties.
Verus Mortgage Capital is an equal opportunity employer. All qualified applicants are welcomed to apply and will receive consideration for employment without unlawful discrimination because of a person’s race, religious creed, color, national origin, citizenship status, ancestry, marital status, sex, age, or sexual orientation, or because of a person’s disability or medical condition.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search