Senior Information Engineer

Fulcrum GT

Schaumburg (IL)

On-site

USD 140,000 - 190,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health Insurance
Dental Insurance
Vision Insurance
401k
Flexible schedule
Paid Holidays

Job summary

Fulcrum GT is seeking a Senior Information Engineer to design, implement, and manage security controls across enterprise infrastructure, IAM, and cloud environments. You will drive compliance with SOC 2, ISO 27001, CSA STAR Level 2, and CyberEssentials+ while guiding a security team and coordinating with auditors.

This role requires 7–10 years in IT/security with 3 years in leadership, deep knowledge of security frameworks, and hands-on experience with automation and cloud security in a dynamic

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field or equivalent experience.
  • Minimum 7-10 years in IT or information security with at least 3 years in a leadership role.
  • Hands-on experience implementing and managing security controls in enterprise environments.
  • Deep understanding of security frameworks including NIST CSF, CIS Controls, and MITRE ATT&CK.
  • Knowledge of AI/ML security, zero-trust, and DevSecOps.
  • Scripting and automation skills using Python, PowerShell, Bash, Terraform.

Responsibilities

  • Design, implement, and maintain security controls to support compliance with SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, CSA STAR Level 2, and CyberEssentials+.
  • Oversee IAM program including RBAC, PAM, access governance.
  • Manage secure authentication systems including MFA and SSO.
  • Lead malware protection across endpoints, servers, and cloud workloads.
  • Design and enforce DLP strategies across email, endpoints, network, and cloud.
  • Lead IT asset configuration management and automated compliance monitoring.
  • Direct vulnerability management including scanning, remediation, and reporting.
  • Collaborate on cloud security controls across GCP and Azure.
  • Coordinate with auditors during assessments and certifications.
  • Provide technical leadership and mentorship to security team.

Skills

Security leadership
Security frameworks
Scripting & automation
Cross-functional collaboration

Education

Bachelor's degree in CS or related field

Tools

Python
PowerShell
Bash
Terraform

Job description

Position Summary

The Fulcrum GT Senior Information Engineer will lead the design, implementation, and management of controls that support enterprise-level security frameworks and compliance. This role will be responsible for ensuring that Fulcrum GT maintains a robust security posture across multiple standards including SOC 2, ISO/IEC 27001, ISO/IEC 42001, CSA STAR Level 2, and CyberEssentials+. The Fulcrum GT Senior Information Engineer Manager will possess deep technical expertise in implementing and managing security controls across enterprise infrastructure, identity systems, and cloud environments.

Key Responsibilities
  • Design, implement, and maintain security controls that support compliance with SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, CSA STAR Level 2, and CyberEssentials+ standards.
  • Oversee the enterprise Identity and Access Management (IAM) program, including role-based access controls, privileged access management, and access governance processes.
  • Manage secure authentication systems including multi-factor authentication (MFA) and single sign-on (SSO).
  • Implement and maintain malware protection solutions across endpoints, servers, and cloud workloads, including next-generation antivirus and endpoint detection and response (EDR) platforms.
  • Design and enforce data loss prevention (DLP) strategies and technologies to protect sensitive information across email, endpoints, network, and cloud environments.
  • Establish and maintain IT asset configuration management processes, including configuration baselines, change control, and automated compliance monitoring.
  • Lead the technical vulnerability management program, including vulnerability scanning, assessment, prioritization, remediation tracking, and exception management.
  • Collaborate with VP, Director of Infrastructure, and CISO to architect and implement cloud security controls across GCP and Azure.
  • Oversee physical security monitoring systems, including access control systems and integration with logical security controls.
  • Collaborate with VP and CISO on security assessments, gap analyses, and remediation efforts.
  • Collaborate with external auditors during security assessments, audits, and certification processes.
  • Provide technical leadership and mentorship to the security team, fostering a culture of continuous improvement and security awareness.
Core Technical Expertise
Identity and Access Management (IAM)
  • Extensive experience with enterprise IAM platforms.
  • Implementation of RBAC, ABAC, and least-privilege access models.
  • Privileged access management (PAM) and secrets management solutions.
  • Identity lifecycle management and automated provisioning/de-provisioning.
Secure Authentication
  • Multi-factor authentication (MFA) implementation and enforcement.
  • Single sign-on (SSO) integration and federation protocols (SAML, OAuth 2.0, OIDC).
  • Certificate-based authentication and PKI management.
Malware Protection
  • Enterprise antivirus and anti-malware deployment and management.
  • Endpoint detection and response (EDR) and extended detection and response (XDR) platforms.
  • Threat intelligence integration and automated response capabilities.
  • Malware analysis and incident response procedures.
Data Loss Prevention
  • Enterprise DLP solution implementation.
  • Data classification and labeling strategies.
  • Content inspection and policy enforcement across network, endpoint, and cloud.
  • Encryption and tokenization technologies for data protection.
IT Asset Configuration Management
  • Configuration management tools.
  • Security baseline development and enforcement.
  • Automated compliance scanning and drift detection.
  • Infrastructure as Code (IaC) security and configuration validation.
Technical Vulnerability Management
  • Vulnerability assessment tools.
  • Vulnerability prioritization.
  • Patch management processes and automation.
  • Penetration testing coordination and vulnerability validation.
Physical Security Monitoring
  • Physical access control systems (PACS) and badge management.
  • Integration of physical and logical security controls.
Compliance and Standards Expertise
  • SOC 2 Type II: Understanding of Trust Service Criteria and evidence requirements for security, availability, processing integrity, confidentiality, and privacy.
  • ISO/IEC 27001: Experience in supporting an Information Security Management System (ISMS) and Annex A controls.
  • ISO/IEC 42001: Knowledge of AI Management System requirements and controls for artificial intelligence governance.
  • CSA STAR Level 2: Familiarity with Cloud Controls Matrix (CCM) and Cloud Security Alliance attestation requirements.
  • CyberEssentials+: Understanding of UK government cyber security certification requirements including boundary firewalls, secure configuration, access control, malware protection, and patch management.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Security, or related technical field (or equivalent experience).
  • Minimum 7-10 years of experience in IT or information security, with at least 3 years in a leadership role.
  • Hands-on technical experience implementing and managing security controls in enterprise environments.
  • Deep understanding of security frameworks including NIST CSF, CIS Controls, and MITRE ATT&CK.
  • Knowledge of emerging technologies including AI/ML security, zero-trust architecture, and DevSecOps.
  • Scripting and automation skills (e.g., Python, PowerShell, Bash, Terraform).
Key Competencies
  • Ability to align security initiatives with business objectives.
  • Strong analytical and problem-solving abilities.
  • Continuous learning mindset to stay current with evolving threats and technologies.
  • Collaborative approach with ability to work across technical and business teams.
Benefits
  • Competitive Health, Dental and Vision Insurance
  • Pet Insurance
  • 401k
  • Flexible schedule
  • Paid Holidays plus Paid Time Off
Job Type
  • Full-time
Language
  • English (Required)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Engineer
Senior Information Engineer

Fulcrum Global Technologies • Schaumburg (IL)

On-site
USD 120,000 - 150,000
Health, Dental and Vision Insurance
Pet Insurance
401k
Senior Information Security & IAM Architect
Senior Information Security & IAM Architect

Fulcrum GT • Schaumburg (IL)

On-site
USD 140,000 - 190,000
Health Insurance
Dental Insurance
Vision Insurance
+3
Information Systems Security Architect
Information Systems Security Architect

Fulcrum Technology Solutions, LLC • Houston (TX)

On-site
USD 80,000 - 100,000
Medical insurance
Dental insurance
Vision insurance
+7
Governance, Risk, and Compliance (GRC) Analyst
Governance, Risk, and Compliance (GRC) Analyst

Fulcrum Global Technologies • Schaumburg (IL)

On-site
USD 70,000 - 90,000
Competitive Health, Dental and Vision Insurance
Pet Insurance
401k
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
IT Security - Sr. Analyst
IT Security - Sr. Analyst

CKE Restaurants, Inc. • Franklin (TN)

On-site
USD 85,000 - 110,000
Security Engineer
Security Engineer

Gravity IT Resources • Salt Lake City (UT)

On-site
USD 120,000 - 160,000
IT Security Engineer
IT Security Engineer

Gravity IT Resources • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Senior IT Security Manager I
Senior IT Security Manager I

GoFormz • San Diego (CA)

On-site
USD 150,000 - 190,000
Senior Information Security Engineer
Senior Information Security Engineer

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000