Security Engineer

Sargent Lundy

Chicago (IL)

Hybrid

USD 78,000 - 119,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health plans
Life & Accident Insurance
401(k)
Paid time off

Job summary

Sargent & Lundy is seeking a senior Security Engineer in Chicago to translate security requirements into working controls and continuously improve them. You will partner with IT Infrastructure, Cloud Engineering, App Dev, SOC and GRC to strengthen defenses across IAM, cloud, data protection, and AI risk management.

This full-time hybrid role requires hands-on experience with Entra, Azure, OCI, and Palo Alto XSIAM, plus Microsoft Purview DLP.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field.
  • 5+ years of hands-on Security Engineering experience with enterprise security platforms.
  • Deep, hands-on IAM lifecycle experience with Microsoft Entra and Zero Trust implementation.
  • Hands-on cloud security experience with Microsoft Azure and Oracle Cloud Infrastructure.
  • Experience with Palo Alto security platforms: Prisma, Cortex XDR, XSIAM.
  • Experience with Microsoft Purview for DLP, labeling, and incident handling.
  • Familiarity with AI risks and enterprise controls.
  • Ability to work across Windows, macOS, and Linux environments.
  • Knowledge of ISO 27001, NIST 800-171, CMMC Level 2, SOC 2.

Responsibilities

  • Implement and operate technical security controls across IAM, device, network, and app layers.
  • Tune and monitor security controls to continuously improve posture.
  • Collaborate with IT Infrastructure, Cloud Engineering, App Dev, SOC, and GRC.
  • Design secure-by-default templates and enforce cloud security in Azure and OCI.
  • Lead architecture reviews for SaaS, IaaS, and PaaS applications.

Skills

IAM lifecycle
Zero Trust
Cloud security
Palo Alto XSIAM
Purview DLP
AI risk controls
Windows/macOS/Linux
Security tooling

Education

Bachelor's degree in CS/IS/Cybersecurity

Tools

Microsoft Entra
Azure
Oracle Cloud Infrastructure
Palo Alto Prisma/XDR/XSIAM
Microsoft Purview

Job description

Responsibilities

Sargent & Lundy is a leading consulting engineering firm specializing in the power and energy sectors. Since 1891, we have provided comprehensive engineering, design, and consulting services for both traditional and renewable power generation, grid modernization, nuclear power, and beyond. Our mission is to help clients achieve their energy goals effectively by leveraging advanced technologies and adopting sustainable practices.

Role Overview

Weare looking to hire a seniorfully technical, hands-on Security Engineerwho can take a security requirement and turn it into a working control, then tune it,monitorit, and improve it over time. You willbe responsible foroperatingthetechnicalsecuritycontrols andplatforms that protect Sargent & Lundy, our clients, andour partners.This is not asecuritygovernance, policy-writing, orprocessmanagement role.

You will work side by side with the IT Infrastructure, Cloud Engineering, Application teams, SOC, and GRC. Controls you buildwillsupportand enhanceoursecuritypostureandalignswithISO 27001, NIST 800-171, and CMMC 2, and protect sensitive data.

Key Responsibilities

Identity and Zero Trust

  • Establish,enforceandoperatethe full IAM lifecycle in Microsoft Entra: SSO, MFA, conditional access, lifecycle workflows, entitlement management, and privileged access integration.
  • Build and tune Zero Trust controls across identity, device, network, and application layers, including conditional access policies, and continuous verification.
  • Partner to integrate IAM with the rest of the security stack so that XSIAM, CASB, DLP, andEDR/XDR all see consistent identitysignal.
  • Run technical access reviews and tighten entitlement design where you find drift.

Cloud Security: Azure and Oracle Cloud

  • Establish and enforce cloudsecurity controls in Azure and Oracle Cloud Infrastructure: landing zones, network security groups, identity, key management, encryption, logging, and workload protection.
  • Operate CSPMtoolingagainst both clouds, triage findings, andprovide secure configurationsat thecloudresource level alongside the cloud engineering team.
  • Partner to build secure-by-default templates so cloud teams can deploy without round-tripping every change through security.

Palo Alto Security Platform

  • Understand and manage Prisma Access (SASE) for remote users and sites: tunnels, security policy, SSO integration, and trafficforwardingrules.
  • Understand and partner with SOC totune Palo Alto XSIAM, including data source onboarding, parser tuning, correlation rules, detection content, and SOAR playbooks that feed Unit 42.

Data Protection and Microsoft Purview DLP

  • Implement Microsoft Purview at a deep technical level: Information Protection, DLP, Insider Risk Management, sensitivity labels, and auto-classification.
  • Author and tune DLP policies across endpoint, Outlook and Exchange, Teams, SharePoint, OneDrive, and Egnyte. Reduce noise without missing real exposure.
  • Handle DLP incident triage, label troubleshooting, and policy iteration based on what productionactually showsyou.

AI Usage Security

  • Implement technical controls for safe AI usage across the company: data-exposure prevention for generative AI tools, prompt and usage monitoring, and integration with the existing DLP and CASB stack.
  • Evaluate emerging AI risks (prompt injection, model abuse,sensitive-dataleakage, shadow AI) and design configurations that mitigate them in our environment.
  • Partner with product and engineering teams shipping AI-enabled features so the controls land at the right layer.

Architecture and Design Reviews

  • Review the security design of new SaaS, IaaS, PaaS, and in-house applications and produce specific, actionable findings.
  • Work with project teamsearlyso controls are designed in, not retrofitted after go-live.

This position offers the flexibility of a hybrid schedule with the expectation of 3 days per week in our downtown Chicago office, and 2 days remote from home.

Qualifications

Required Experience

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, ora relatedfield. Equivalent professional experience will be considered.
  • 5+ years of hands-on Security Engineering experience withdemonstratedownership of enterprise security platforms in production. Pure governance, audit, or policy-only backgrounds will not match the work in this role.
  • Deep, hands-on IAM lifecycle experience with Microsoft Entra (SSO, MFA, conditional access, lifecycle workflows) and applied Zero Trust implementation.
  • Hands-on cloud security experience with Microsoft Azure (required) and Oracle Cloud Infrastructure (strongly preferred), including technical configuration of native security services.
  • Hands-on configuration and operation of the Palo Alto security platform: Prisma (Access and Cloud), Cortex XDR, and XSIAM.
  • Implementation-level experience with Microsoft Purview for DLP, including policy authoring, classification, labeling, tuning, and incident handling.
  • Working knowledge of AI risks (data exposure, prompt injection, model misuse, shadow AI) and the controls used to mitigate them in an enterprise setting.
  • Comfort working across on-prem and cloud environments and across Windows, macOS, and Linux endpoints.
  • Familiarity with compliance frameworks (ISO 27001, NIST 800-171, CMMC Level 2, SOC 2) and the ability to translate a control requirement into a working configuration.
  • Certifications: CompTIA Security+ or (ISC)² SSCP or PCCSE (Palo Alto Networks Certified Cloud Security Engineer) an equivalent foundational technical certification.

Preferred Experience

  • Microsoft Azure Security certification (AZ-500 or equivalent).
  • Microsoft Purview Information Protection and DLP certification or equivalent.
  • Oracle Cloud Infrastructure security credentials.
  • Microsoft Cybersecurity Architect (SC-100),
  • CISSPor CCSP.

Soft Skills

  • Strong written and verbal communication.You can walk an engineer through a config in one conversation and a business stakeholder through the impact in the next.
  • Bias for action. You would rather build a working control and iterate than spend weeks producing a perfect document.
  • Comfort with ambiguity. You can take a vague securityaskand break it into a concrete configuration plan.
  • Collaboration across teams. You will work daily with SOC, IT Infrastructure, Cloud, App Dev, and GRC, and the role only works if those partnerships do.
  • Operational discipline. You document what you build, version your configurations, and leave the next engineer better than you found it.

We do not sponsor employees for work authorization in the U.S. for this position.

Technology & Innovation

Sargent & Lundy values the appropriate use of technology to improve how work gets done and deliver high-quality outcomes for our clients. Depending on the role, employees may use data, automation, artificial intelligence, and other digital tools to support research, analysis, engineering and design activities, workflow improvement, or other aspects of their work. We value candidates who demonstrate an interest in learning and effectively using emerging technologies where relevant to their role. Employees remain accountable for their work and are expected to apply appropriate professional judgment and review when using technology-assisted tools. Experience with AI, automation, programming, or similar technologies is valued where relevant but is not required unless specifically identified elsewhere in the job description.

About Sargent & Lundy

At Sargent & Lundy, we care about the health and well-being of our employees. Our commitment extends beyond the workplace, offering comprehensive healthcare plans and generous paid time off to support our team members in every aspect of their lives. We understand the importance of work-life balance, which is why we are proud to provide competitive, award-winning benefits. Our dedication to employee satisfaction has earned us the prestigious Top Workplaces Culture Excellence Award for compensation and benefits in 2022, 2023, and 2024.

Health & WellnessFinancial BenefitsWork-Life Balance
  • Health Plans: Medical, Dental, Vision
  • Life & Accident Insurance
  • Disability Coverage
  • Employee Assistance Program (EAP)
  • Back-Up Daycare
  • FSA & HSA
  • 401(k)
  • Pre-Tax Commuter Account
  • Merit Scholarship Program
  • Employee Discount Program
  • Corporate Charitable Giving Program
  • Tuition Assistance
  • First Professional Licensure Bonus
  • Employee Referral Bonus
  • Paid Annual Personal/Sick Time (PST)
  • Paid Vacation
  • Paid Holidays
  • Paid Parental Leave
  • Paid Bereavement Leave
  • Flexible Work Arrangements
Compensation Range
$78,016 - $119,191
Transparency Statement
Sargent & Lundy discloses compensation ranges that comply with all local and state regulations. The total compensation package for eligible positions will include a base salary or an hourly rate and a comprehensive benefits package, reflecting our commitment to rewarding performance and supporting the overall well-being of our employees. Individuals may also be eligible to participate in our yearly discretionary bonus.
Equal Opportunity

Sargent & Lundy is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any protected status as defined by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Administrative Assistant - Energy & Industrial Group
Administrative Assistant - Energy & Industrial Group

Sargent Lundy • Chicago (IL)

Hybrid
USD 39,000 - 57,000
Health plans
Dental insurance
Vision insurance
+1
Electrical Engineer 1 (Entry Level) - Energy & Industrial (Summer 2027)
Electrical Engineer 1 (Entry Level) - Energy & Industrial (Summer 2027)

Sargent Lundy • Chicago (IL)

Hybrid
USD 63,000 - 91,000
Health Plans: Medical, Dental, Vision
Life & Accident Insurance
Disability Coverage
+15
Security Engineer
Security Engineer

Sargent & Lundy • Chicago (IL)

On-site
USD 64,915 - 95,019
Health Plans: Medical, Dental, Vision
401(k)
Paid Annual Personal/Sick Time
+1
Instrumentation & Controls Engineer 1 - Energy & Industrial (Summer 2027)
Instrumentation & Controls Engineer 1 - Energy & Industrial (Summer 2027)

Sargent & Lundy • Chicago (IL)

On-site
USD 63,000 - 91,000
Health plans
401(k)
Paid time off
+2
Instrumentation & Controls Engineer 1 - Energy & Industrial (Summer 2027)
Instrumentation & Controls Engineer 1 - Energy & Industrial (Summer 2027)

Sargent & Lundy • Englewood (CO)

On-site
USD 63,000 - 91,000
Health plans (Medical, Dental, Vision)
401(k)
Paid time off
+3
Instrumentation & Controls Engineer 1 - Energy & Industrial (Summer 2027)
Instrumentation & Controls Engineer 1 - Energy & Industrial (Summer 2027)

Sargent & Lundy • Midland (TX)

On-site
USD 63,000 - 91,000
Health Plans (Medical, Dental, Vision)
Life & Accident Insurance
Disability Coverage
+7
Lead Software Engineer
Lead Software Engineer

Sargent Lundy • Chicago (IL)

On-site
USD 100,000 - 144,000
Health insurance
Flexible work schedule
Paid time off
Electrical Engineer 1 (Entry Level) - Energy & Industrial
Electrical Engineer 1 (Entry Level) - Energy & Industrial

Sargent Lundy • Englewood (CO)

On-site
USD 63,000 - 91,000
Health plans
Paid time off
401(k) plan
+2
Electrical Engineer 1 (Entry Level) - Energy & Industrial (Summer 2027)
Electrical Engineer 1 (Entry Level) - Energy & Industrial (Summer 2027)

Sargent Lundy • Englewood (CO)

On-site
USD 63,000 - 91,000
Health Plans
401(k)
Paid Time Off
+2
Administrative Assistant - Grid Engineering Support
Administrative Assistant - Grid Engineering Support

careers-sargentlundy • Charlotte (NC)

Hybrid
USD 49,000 - 72,000
Health plans
Paid time off
401(k)
+3