Lead Security Engineer - IR and Vulnerability Management

Request Technology, LLC

Chicago (IL)

Hybrid

USD 150,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Request Technology, LLC in Chicago, IL is seeking a Lead Security Engineer – IR and Vulnerability Management to lead incident response and drive security monitoring across on-prem and cloud. You will coordinate investigations, implement playbooks, and oversee data preservation for forensics and post-incident analysis.

The role requires 5+ years in security operations, hands-on expertise with threat analysis, forensics, vulnerability tooling (Qualys, Nessus, Splunk, CrowdStrike), and strong

Qualifications

  • 5+ years in hands-on security operations.
  • Experience with threat analysis, incident response, and multi-domain security.
  • Familiarity with network exploitation and financial services context.
  • Experience deploying security platforms and vulnerability assessment tools.
  • Scripting and API usage to integrate security monitoring tools; knowledge of Generative AI.

Responsibilities

  • Lead cyber security incident responders in response activities.
  • Oversee technical analysis of security events with internal and external teams.
  • Ensure and oversee data collection and preservation for incident response activities.
  • Prioritize and identify security risks, threats and vulnerabilities.
  • Lead remediation efforts for identified gaps.
  • Develop security monitoring roadmaps for cloud-hosted solutions and SaaS.
  • Serve as SME on security tools including appliances, hosted systems, and SaaS.

Skills

Security operations
Incident response
Cyber threat analysis
Application security
OS security
Networking
Scripting/APIs
Generative AI awareness
Threat actor capabilities
Cryptographic controls

Tools

Splunk
CrowdStrike
Symantec DLP
Qualys
Nessus
nmap
tcpdump
EDR
Web Application Firewall

Job description

Lead Security Engineer – IR and Vulnerability Management

Salary: $150k-$180k + bonus

Location: Chicago, IL

Hybrid: 3 days onsite, 2 days remote

Qualifications
  • 5+ years hands‑on security operations experience including interdisciplinary experience with four or more of the following: Cyber Threat Analysis, Digital Computer Forensics, Incident Response, Application Security, Operating Systems Security, Cryptographic Controls, Networking, Programming languages, Incident Response.
  • Technical experience and comprehensive knowledge of threat actor capabilities, intentions, methodologies, and motives.
  • Familiarity with computer network exploitation and network attack methodologies while maintaining an understanding of the relationship these activities have with the financial services industry and critical infrastructure.
  • Implementation and maintenance of security platforms (Splunk, Crowdstrike, Symantec DLP) and vulnerability assessment tools (Qualys, Nessus, nmap), including incident response playbook development and remediation management.
  • Proficiency with network sniffers/packet tracing tools (Ethereal, tcpdump, etc.), preventative/detective technologies (EDR, network-based analysis), and Web Application Firewalls.
  • Strong background in encryption technologies (PGP, PKI, X.509) and directory services/LDAP security (Active Directory, CA Directory).
  • Experience across client/server platforms (Solaris, Windows, Linux) and OS hardening procedures, plus proxy/caching services.
  • Knowledge of LAN/WAN routing and high availability protocols (OSPF, BGP4/iBGP, EIGRP, NSRP), cloud security tools (AWS, Azure, GCP), and SOAR tools/concepts.
  • Some experience scripting and leveraging APIs to integrate security monitoring tools, with knowledge of Generative and Prompt AI.
Responsibilities
  • Lead cyber security incident responders in response activities including investigation, coordination, review, and reporting.
  • Oversee technical analysis of security events while coordinating incident response activities with internal and external teams.
  • Ensure and directly oversee the collection and preservation of data associated with cyber security incident response activities following industry best practices and established procedures.
  • Prioritize and identify security risks, threats and vulnerabilities of networks, systems, applications, and new technology initiatives.
  • Lead systems management team to operationalize remediation efforts for gaps identified.
  • Develop and implement security monitoring roadmaps for technologies, applications, SaaS, and other cloud-hosted solutions. These roadmaps will direct efforts on implementation of monitoring use cases and measurement of monitoring capabilities.
  • Subject matter expert on security tools including appliances, hosted systems, and SaaS – including health checks, version updates, and content development.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead, Security Assurance
Lead, Security Assurance

Request Technology, LLC • Chicago (IL)

Hybrid
USD 120,000 - 180,000
Lead Security Engineer - IR & Vulnerability Ops
Lead Security Engineer - IR & Vulnerability Ops

Request Technology, LLC • Chicago (IL)

Hybrid
USD 150,000 - 180,000
Lead, Security Assurance
Lead, Security Assurance

Request Technology, LLC • Coppell (TX)

Hybrid
USD 120,000 - 160,000
Platform Security Engineer
Platform Security Engineer

GloComms • Chicago (IL)

Hybrid
USD 160,000 - 200,000
Senior Cyber Security Specialist I - Insider Threat Analysis
Senior Cyber Security Specialist I - Insider Threat Analysis

Walgreens • United States

Hybrid
USD 98,000 - 158,000
Lead Security Engineer - Managed Services
Lead Security Engineer - Managed Services

Triwill Group • United States

On-site
USD 133,000 - 193,000
Remote work options
Bonus opportunity: quarterly 10%
Competitive benefits package
+1
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Jobot • Chicago (IL)

On-site
USD 100,000 - 150,000
Health, dental, and vision programs
Generous PTO and paid holidays
Paid parental leave
+2
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 112,000 - 150,000
Lead Cyber Security Engineer (HYBRID)
Lead Cyber Security Engineer (HYBRID)

Phantom Staffing • Boston (MA)

Hybrid
USD 120,000 - 160,000
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Northern (KY)

Hybrid
USD 140,000 - 180,000