Invesco Infrastructure Security EngineerResponsible for execution of Invesco's enterprise vulnerability and security patch management capability across hybrid and cloud-native infrastructure. This role focuses on reducing material risk at scale through automation-first engineering, high-fidelity data, and AI-assisted prioritization, enabling faster, smarter remediation decisions across complex environments.As part of a dedicated infrastructure security engineering team, you will play a key role in protecting Invesco's platforms, data, and reputation by driving continuous improvement across the vulnerability lifecycle—from asset discovery and signal quality to remediation orchestration. Demonstrate through key metrics, challenges and success.You'll oversee the execution of vulnerability lifecycle automation (on-prem and cloud), accuracy and enrichment of vulnerability and asset data to improve prioritization and ownership, development of meaningful metrics, adoption and advancement of AI-assisted risk scoring, forecasting, and remediation decision support.This role works closely with infrastructure, cloud and platform engineering teams along with global security teams.Subject matter expert on Security patch deployment methodologies and tools based on best industry practice.Responsible for risk assessment, deployment activities, scheduling and prioritization.Comfortable using AI tools to classify, enrich and prioritize security data, detect anomalies and trends.Responsible for reporting back on progress of compliance; contribute to creating metric reports that track team success.
Drive accountability to ensure Invesco risk profile is maintained to zero breach in compliance.Ensure tools used in the role to maintain accurate and effective risk profileIdentify opportunities to improve process and tools that would gain either capacity in the team or reduce time taken to close out vulnerabilities.Provide technical assistance and lead response to audit reports, including creation of professional documents that would be shared at a senior executive level.Act as a mentor and guide to other Team members. Deputize in the absence of line Manager whilst acting as a technical lead on cross-team initiatives.Drive a culture of continuous improvement, experimentation and lead projects/initiatives where required.Technical mindset with proven experience working in Infrastructure environment in the past 8-10+ yearsExperience in managing cyclical security deployment program(s)Proven experience working in any of the following technology environments; Microsoft Operating Systems, CISCO Networks, UNIX/RedhatWorked in Financial services industry for a minimum of 5 years.Superior written and oral communication skills, working in a global enterprise organizationStrong skill base (5+ years) using legacy Microsoft End point Management (MECM)Demonstrate use, management and interpretation of Security scanning tools such as Wiz and QualysPractical experience of prioritizing remediations plans based on risk score classificationsDesigning and implementing automation pipelines for patch orchestration, validation and reporting and exception handlingLeverage AI/ML techniques to identify duplicate, inaccurate or noisy vulnerability data, including forecasting emerging exploit-based risksAPI-first mindsetAdvanced scripting, automation in PowerShell, Python, Microsoft Power AutomateFamiliar with ServiceNow and ITIL FrameworkStrong PowerBI, Windows Operating systems (Server and Desktop), advanced use of O365 products, in particular Excel and manipulation of extensive data setsProven automation / scripting-based skills to enable enterprise wide deployments or methodologies associated withInterpret and provide written recommendations on how vulnerabilities present a threat in a multitude of Technology platforms (stated above), the challenges associated to the environment that enable gauging risk profileProficient in working within regulated Change Management environment, focus on risk and impactDesirable (not essential) Red Hat Satellite ServerDeep hands-on experience, across enterprise cloud environments such as AWS and Microsoft Azure/M365 (Intune)Solid understanding of vulnerability industry standard scoring mechanisms such as CVSS, EPSS, KEV.Proven ability to improve fidelity of vulnerability and asset data (correlating across CMDB, Cloud discovery and scanner output).Building and maintaining PowerBI dashboards for analytical purpose that create insight to actionIndustry-recognized cloud platform certifications (foundational and/or associate/advanced), across enterprise cloud environments including but not limited to;Microsoft 365 Certified: Endpoint Administrator Associate/Expert/Security SpecializationWindows Server Hybrid Administrator AssociateAzure Administrator/Security/Hybrid/NetworkingMicrosoft Certified: Security Operations Analyst AssociateAWS Foundation/Associate/ProfessionalAWS Certified Security Specialist/DevOps/Solutions ArchitectFull timeEmployeeYesPursuant to Invesco's Workplace Policy, employees are expected to comply with the firm's most current workplace model, which as of October 1, 2025, includes spending at least four full days each week working in an Invesco office. This reflects our belief that spending time together in the office helps us build stronger relationships, collaborate more easily, and support each other's growth and development.Invesco's culture of inclusivity and its commitment to diversity in the workplace are demonstrated through our people practices.
We are proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender, gender identity, sexual orientation, marital status, national origin, citizenship status, disability, age, or veteran status. Our equal opportunity employment efforts comply with all applicable U.S.
state and federal laws governing non-discrimination in employment.