Bank of the Sierra is a regional community bank operating 34 full-service branches across California's southern San Joaquin Valley, with assets exceeding $3 billion. Founded in 1977, the institution provides retail, commercial, and lending services, but the attack surface that matters here is its digital footprint: online banking, mobile banking, and a suite of digital financial tools including mobile check deposit and secure messaging. That's where the threat model lives - credential stuffing, transaction fraud, API abuse, and the steady drumbeat of social engineering targeting both customers and internal staff at a bank with 500 employees.
The technical domains are squarely in the fintech-adjacent space where community banks are racing to modernize without the engineering headcount of a neobank. You'd be securing customer-facing platforms that interface with third-party ATM networks (over 55,000 surcharge-free ATMs via Allpoint and PULSE), mobile endpoints, and the usual stack of banking infrastructure. The regulatory environment is non-negotiable - FFIEC guidelines, GLBA, and California's own privacy frameworks shape everything from access controls to incident response playbooks.
Culturally, Bank of the Sierra leans into its community positioning - it has awarded over $5 million through its Sierra Grant Program to local nonprofits and holds a five-star rating from Bauer Financial. For a security team, that means working at an institution where trust isn't abstract branding; it's operational currency across six counties. The stakes are concrete: protecting the digital channels that a growing regional bank is betting its future on.






