BOK Financial
IT Engineer IV - Cloud Platform Security Solutions
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About BOK Financial
BOK Financial Corporation is a diversified financial services company with a history dating back to 1910. Originally founded as Exchange National Bank of Tulsa, it has evolved from financing oil development in Oklahoma to becoming a prominent financial institution serving clients across multiple states. Operating in eight states, including Texas, Arizona, and Colorado, BOK Financial offers a wide range of financial services. The company focuses on building personal relationships with clients, combining technology with personal service to enhance financial management. BOK Financial aims to be a comprehensive financial partner, providing valuable advice and expertise to help clients achieve their financial goals. The company serves a diverse clientele, including individuals and international businesses. Its recent acquisition of CoBiz Financial has further strengthened its presence in Colorado and Arizona, reflecting its commitment to growth and community engagement.
Security at BOK Financial
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- BOK Financial maintains a company-level security posture with 24/7 real-time monitoring.
- Their approach emphasizes GitOps and DevSecOps, utilizing a guardrails-based strategy with merge policies, code owners, and short-lived credentials via HashiCorp Vault to streamline changes and ensure security.
Security Team
Kris Jackson serves as the Director of Security Engineering and Operations (also Manager of Cybersecurity, Engineering and Operations) at BOK Financial. Information regarding the AppSec team's size or full organizational reporting structure beyond this leader is not publicly available.
Key Initiatives
BOK Financial implements DevSecOps into the infrastructure and security components using a guardrails-based approach, including merge policies and code owners. They utilize HashiCorp Vault to issue short-lived STS tokens, which helps them approve almost 98% of changes in less than five minutes. No public evidence was found for a formal Security Champions program.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.