Security Engineer

Seyfarth Shaw LLP

Chicago (IL)

On-site

USD 118,000 - 135,000

Full time

42 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Paid time off
Medical/dental/vision insurance
401(k)

Job summary

Seyfarth Shaw LLP seeks a Security Engineer - Application Security & Technology Risk to assess and protect the Firm's apps, SaaS, and integrations. You’ll analyze architecture, permissions, data access, and authentication, translating findings into practical, risk-based remediation.

You will work with IT, security, and business teams to identify gaps, verify deployments align with approved requirements, and help secure the environment against evolving threats.

Qualifications

  • At least three years in cybersecurity, security engineering, application security, vulnerability management, security operations, or related IT role.
  • Strong understanding of vulnerabilities, attack techniques, and how attackers compromise applications and endpoints.
  • Knowledge of software supply‑chain risk, compromised updates, and third‑party libraries.

Responsibilities

  • Perform technical security assessments of applications, SaaS platforms, browser extensions, integrations, and other technologies.
  • Evaluate architecture, permissions, data access, authentication methods, APIs, and OAuth integrations.
  • Assess how compromised applications could be leveraged as attack vectors and how to mitigate them.
  • Review security documentation, threat intel, dependencies, and research for risk identification.
  • Validate authentication and authorization configurations including SSO, SAML, OAuth/OIDC, MFA, and Conditional Access.
  • Collaborate with infrastructure, identity, cloud, and networking teams to close gaps with practical controls.
  • Document findings with risk, impact, and recommended controls for diverse audiences.
  • Support threat hunting, incident response, and other security operations as needed.

Skills

Security engineering
Application security
Vulnerability management
Penetration testing
Security operations
Threat hunting
Identity security
OpenID Connect

Tools

Qualys
CrowdStrike Falcon
Microsoft Sentinel
Microsoft Entra ID
Burp Suite

Job description

Why Seyfarth

At Seyfarth, we understand that great people are the key to our success, and we provide the opportunities to match. If you join us, you’ll work with state‑of‑the‑art technology in a friendly and professional environment, and we will continue to invest in your professional development. If you want the freedom to grow at a firm that is invested in your future, keep reading.

The Opportunity

As a Security Engineer - Application Security & Technology Risk, you will help evaluate and protect the Firm's technology environment by assessing the security risks associated with applications, SaaS platforms, browser extensions, integrations, and other technologies proposed for use within the Firm.

A significant part of this role will involve understanding how a technology works, the access and permissions it requires, the data it can access or process, how it integrates with the Firm's environment, and how it could potentially be abused or compromised. You will evaluate these technologies from both a defensive and adversarial perspective, considering vulnerabilities, software supply‑chain risk, authentication and authorization controls, configuration weaknesses, and the ways an attacker could leverage a compromised application or integration.

The successful candidate will combine strong technical security knowledge with the ability to translate security findings into practical, risk‑based recommendations for application owners, IT teams, and Firm leadership.

The Day‑To‑Day
  • Perform technical security assessments of software applications, SaaS platforms, browser extensions, integrations, AI‑enabled technologies, and other technologies proposed for use within the Firm.
  • Evaluate application architecture, permissions, data access, administrative controls, authentication methods, APIs, OAuth integrations, third‑party dependencies, logging capabilities, and security configuration.
  • Assess how compromised or malicious applications could be leveraged as an attack vector, including credential theft, data exposure, persistence, privilege escalation, lateral movement, command and control, and software supply‑chain compromise.
  • Review vendor and application security documentation, vulnerability information, threat intelligence, software dependencies, and publicly available security research to identify potential risks.
  • Evaluate authentication and authorization configurations including SSO, SAML, OAuth/OIDC, MFA, Microsoft Entra ID integrations, Conditional Access policies, service principals, application registrations, API permissions, and privileged access requirements.
  • Work with infrastructure, endpoint, cloud, identity, networking, and application teams to identify security design or configuration gaps and recommend practical remediation or compensating controls.
  • Review existing deployed applications to determine business need, usage, software versions, support status, known vulnerabilities, available updates, and potential security exposure.
  • Assist with application inventory and software lifecycle initiatives designed to identify unnecessary, obsolete, vulnerable, or unauthorized applications within the environment.
  • Validate approved application deployments to confirm that software, security controls, permissions, integrations, and configurations were implemented according to approved requirements.
  • Use vulnerability management, endpoint security, SIEM, identity, network, asset discovery, and other security telemetry to understand application behavior and identify potential security concerns.
  • Support Security Operations with threat hunting, security investigations, incident response, and other operational security activities as needed.
  • Clearly document findings, risk, technical impact, and recommended controls for both technical and non‑technical audiences.
  • Exercise independent judgment, curiosity, and initiative when investigating unfamiliar technologies and security risks.
You Have
  • At least three years of experience in cybersecurity, security engineering, application security, vulnerability management, penetration testing, security operations, or a related technical information technology role.
  • Strong understanding of common vulnerabilities, attack techniques, and the ways attackers compromise applications, endpoints, identities, cloud services, and enterprise environments.
  • Strong understanding of software supply‑chain risk, including compromised software updates, malicious dependencies, third‑party libraries, browser extensions, package repositories, software signing, and vendor compromise.
  • Familiarity with offensive security and penetration testing methodologies and the ability to apply an attacker mindset when evaluating new technologies.
  • Experience evaluating applications or SaaS platforms from a security perspective, including permissions, architecture, integrations, authentication, authorization, data access, and administrative controls.
  • Working knowledge of modern identity and authentication technologies including SSO, SAML, OAuth 2.0, OpenID Connect, MFA, Microsoft Entra ID, enterprise application registrations, and Conditional Access.
  • Understanding of Windows and cloud security concepts, endpoint security controls, networking, APIs, and common enterprise application deployment models.
  • Experience working with security technologies such as vulnerability scanners, endpoint detection and response platforms, SIEM platforms, identity security tools, network security platforms, or application security testing tools.
  • Familiarity with tools such as Qualys, CrowdStrike Falcon, Microsoft Sentinel, Microsoft Entra ID, Burp Suite, or comparable security platforms is preferred.
  • Ability to research unfamiliar technologies, understand how they operate, identify meaningful security concerns, and distinguish theoretical risk from realistic enterprise risk.
  • Strong analytical and troubleshooting skills with attention to technical detail.
  • Ability to communicate security findings clearly and work collaboratively with technical teams, application owners, vendors, and business stakeholders.
  • Scripting, API, or automation experience with PowerShell, Python, or similar technologies is preferred.
  • A strong desire to continuously learn about emerging technologies, vulnerabilities, attack techniques, and changes in the cyber threat landscape.
What We Provide

Seyfarth provides competitive salary and benefits at all levels, and our culture embraces the entrepreneurial spirit of its professionals like no other firm. Our professional staff are a collaborative team, helping to define the unique client experience offered by the firm. We understand that it takes more than attorneys to build a successful legal practice; everyone participates in our commitment to excellence.

  • We offer a comprehensive package of benefits including paid time off, medical/dental/vision insurance, and 401(k).
  • We offer a comprehensive package of benefits including paid time off, medical/dental/vision insurance, and 401(k).
More About Seyfarth

With approximately 1,000 lawyers across 19 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Learn more about The Seyfarth Experience at www.seyfarth.com/careers/.

Seyfarth Shaw is committed to equal employment opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability, medical condition, military and veteran status, gender identity or expression, genetic information, change of sex or transgender status, genetic information or any other basis protected by federal, state or local law.

If you would like more information about your EEO rights as an applicant under the law, please click EEO is the LAW and the Supplement poster through the following link: https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf

Location Specific Language

The salary range for this role is $118,000 to $135,000 annually, which is based on a 40 hour work week. This range is only applicable for jobs to be performed in Chicago. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s pay within the salary range will be based on numerous factors including, but not limited to, relevant education, qualifications, experience, skills, and business or organizational needs. This job is also eligible for an annual merit increase and bonus pay.

This position is based in Atlanta, GA 30309

This position is based in Charlotte, NC 28202

This position is based in Chicago, IL 60606

This position is based in Dallas, TX 75201

This position is based in Houston, TX 77002

This position is based in Miami, FL 33131

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Seyfarth Shaw LLP • United States

On-site
USD 118,000 - 135,000
401(k)
Medical/dental/vision insurance
Paid time off
Security Engineer
Security Engineer

Seyfarth Shaw LLP • Dallas (TX)

On-site
USD 120,000 - 150,000
Paid time off
Medical/dental/vision insurance
401(k)
Security Engineer
Security Engineer

Seyfarth Shaw LLP • Atlanta (GA)

On-site
USD 118,000 - 135,000
Paid time off
Medical/dental/vision insurance
401(k)
Strategic Pricing Manager
Strategic Pricing Manager

Seyfarth Shaw LLP • Los Angeles (CA)

On-site
USD 144,000 - 159,000
Senior Virtual Infrastructure and Systems Architect
Senior Virtual Infrastructure and Systems Architect

Seyfarth Shaw LLP • United States

On-site
USD 150,000 - 210,000
Client Development and Alumni Relations Coordinator
Client Development and Alumni Relations Coordinator

Seyfarth Shaw LLP • Boston (MA)

On-site
USD 77,000 - 79,000
Paid time off
Medical/dental/vision insurance
401(k)
Practice Development Assistant
Practice Development Assistant

Seyfarth Shaw LLP • Chicago (IL)

On-site
USD 52,000 - 62,000
Paid time off
Medical/dental/vision insurance
401(k)
Senior Virtual Infrastructure and Systems Architect
Senior Virtual Infrastructure and Systems Architect

Seyfarth Shaw LLP • Houston (TX)

On-site
USD 110,000 - 170,000
Strategic Pricing Manager
Strategic Pricing Manager

Seyfarth Shaw LLP • Chicago (IL)

On-site
USD 135,000 - 149,000
Senior Virtual Infrastructure and Systems Architect
Senior Virtual Infrastructure and Systems Architect

Seyfarth Shaw LLP • Miami (NM)

On-site
USD 120,000 - 180,000