Security Engineer

JR Recruiting

Chicago (IL)

Hybrid

USD 90,000 - 130,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

JR Recruiting supports a nonprofit client in Chicago seeking a Security Engineer to protect highly sensitive health, immigration, and financial data across headquarters and sites.

You will design, implement, and operate controls, monitor incidents, and drive security improvements with a mission-driven IT team. Experience in healthcare or nonprofit security is valued.

Qualifications

  • 3+ years in information security or security engineering.
  • Proficient with Microsoft 365 and Entra ID security.
  • Experience with EDR, SIEM, MFA/SSO, backups.
  • Experience leading incident response.
  • Familiarity with HIPAA Security Rule and at least one security framework.
  • Ability to explain security concepts clearly to non-technical colleagues.
  • Strong documentation habits and ability to work independently in a small team.
  • Bachelor’s degree or equivalent practical experience.

Responsibilities

  • Own day-to-day security operations: monitor alerts, triage incidents, lead response and containment, document root causes.
  • Administer security tooling: EDR, email security gateways, SIEM, MFA/SSO, vulnerability management.
  • Secure Microsoft 365 / cloud environment, networks, and endpoints across sites.
  • Lead vulnerability and patch management, track remediation to closure.
  • Design and enforce identity and access controls with least privilege and reviews.
  • Support HIPAA, PCI DSS, and state data privacy compliance; prepare audit evidence.
  • Assess third-party vendors and SaaS security during onboarding and post-onboarding.
  • Deliver security awareness training and phishing simulations for staff.
  • Maintain business continuity, DR, and backup procedures for critical services.
  • Write and maintain security policies; translate policy into practical guidance.

Skills

Information security
Security engineering
Incident response
Microsoft 365 security
Entra ID / Azure AD
Documentation
Nonprofit experience

Education

Bachelor's degree in CS or related field

Tools

EDR
SIEM
Email security gateways
MFA/SSO
Backup and recovery tools
Azure AD security

Job description

Chicago, United States | Posted on 08/26/2026

  • Industry Nonprofit Charitable Organizations
  • Work Experience 4-5 years
  • City Chicago
  • Country United States
Job Description

Our client is a large, well-established nonprofit that provides human services across the Chicago metropolitan area. Each year the organization serves hundreds of thousands of individuals and families through a network of food, housing, senior, family, mental health, immigration, and crisis programs delivered at dozens of sites across the region. Services are open to everyone regardless of faith or background, and the organization's culture is grounded in compassion, solidarity, and measurable impact. The client name will be shared with qualified candidates during the screening process.

Position Summary

The people this organization serves trust it with some of the most sensitive information in their lives: health records, immigration status, housing and financial histories, and the details of families in crisis. The Security Engineer is the hands-on owner of protecting that trust. You will design, implement, and operate the technical controls that safeguard its systems, data, and staff across headquarters, program sites, and residential communities, and you will help a mission-driven, largely non-technical workforce practice good security every day. This is a broad, high-ownership role on a small IT team, ideal for someone who wants their work to have a direct human impact.

Key Responsibilities
  • Own day-to-day security operations: monitor alerts, triage and investigate incidents, lead response and containment, and document root cause and lessons learned.
  • Administer and tune core security tooling, including endpoint detection and response, email security, identity and access management (MFA, SSO, conditional access), vulnerability scanning, and SIEM or log management.
  • Secure the organization's Microsoft 365 / cloud environment, network infrastructure, and endpoints across dozens of distributed program sites.
  • Run the vulnerability and patch management program: scan, prioritize by risk, coordinate remediation with IT and vendors, and track to closure.
  • Design and enforce identity and access controls, including role-based access, least privilege, joiner/mover/leaver processes, and periodic access reviews.
  • Support compliance with the regulations that apply to the organization's programs, including HIPAA, PCI DSS, state data-privacy laws,and government-grant security requirements; prepare evidence for audits and assessments.
  • Assess the security of third-party vendors and SaaS platforms (case management, donor, HR, and financial systems) before and after onboarding.
  • Build and deliver security awareness training and phishing simulations tailored to case workers, pantry and housing staff, volunteers, and leadership.
  • Maintain and test business continuity, disaster recovery, and backup procedures so critical services stay available to the people served.
  • Write and maintain security policies, standards, and run playbooks; help translate policy into practical guidance staff can follow.
  • Provide security input on new projects, system implementations, and integrations from the start rather than after the fact.
  • Track and report security metrics and risk posture to IT leadership and, as needed, to executive leadership and the board.
Requirements
Required Qualifications
  • 3+ years of hands-on experience in information security, security engineering, or a security-focused systems/network administration role.
  • Working knowledge of Microsoft 365 and Entra ID (Azure AD) security, Windows and endpoint security, and network fundamentals (firewalls, VPN, segmentation, Wi-Fi).
  • Practical experience with at least several of the following: EDR, email security gateways, SIEM/log analysis, vulnerability scanners, MFA/SSO, backup and recovery tools.
  • Experience leading or materially contributing to incident response.
  • Familiarity with HIPAA Security Rule requirements and at least one security framework (NIST CSF, CIS Controls, or ISO 27001).
  • Ability to explain security concepts clearly and patiently to non-technical colleagues and to build cooperative relationships across the organization.
  • Strong documentation habits and the ability to work independently and prioritize in a small-team environment.
  • Bachelor’s degree in computer science, information systems, or a related field, or equivalent practical experience.
Preferred Qualifications
  • Security certification such as Security+, CySA+, GSEC, CISSP, or a Microsoft security certification (SC-200, SC-300, AZ-500).
  • Experience in a nonprofit, healthcare, social services, or other resource-conscious, compliance-driven environment.
  • Experience securing case-management, EHR, or donor/CRM platforms and working with grant or government-funded program requirements.
  • Scripting ability (PowerShell, Python) for automation and reporting.
  • Experience with PCI DSS scope reduction and payment-processing security.

This position is based at the client's downtown Chicago headquarters with a hybrid schedule. Periodic travel to program sites across the greater Chicago area is required, as is occasional after-hours availability for incident response or planned maintenance. A valid driver’s license and reliable transportation are helpful. Employment is contingent on a background check consistent with the organization's commitment to protecting the vulnerable people it serves.

Why This Role

Your work will directly protect families, seniors, veterans, immigrants, and neighbors in crisis. Our client offers a competitive salary, a comprehensive benefits package including medical, dental, and vision coverage, retirement plan with employer contribution, generous paid time off and holidays, and support for professional development and certifications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Security Engineer
Security Engineer

Creative Financial Staffing, LLC • Evanston (IL)

Hybrid
USD 110,000 - 150,000
Medical, Dental, Vision (M/D/V)
401K
Pet Insurance
+1
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

Remote
USD 100,000 - 130,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
IT Security Engineer
IT Security Engineer

Gulf Coast Automation Group • Chicago (IL)

Hybrid
USD 93,500 - 110,000
Hybrid work environment
Modern cloud and cybersecurity tech
Professional development and career成长
+1
Security Engineer
Security Engineer

TalentBridge • Illinois

Remote
USD 100,000 - 130,000
Security Engineer
Security Engineer

Phoenix Staff, Inc. • Tempe (AZ)

On-site
USD 85,000 - 110,000
Security Engineer
Security Engineer

Sargent & Lundy • Chicago (IL)

Hybrid
USD 64,915 - 95,019
Health Plans: Medical, Dental, Vision
401(k)
Paid Annual Personal/Sick Time
+1
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Peyton Resource Group • Bethesda (MD)

On-site
USD 150,000 - 210,000