This is a permanent opportunity that will require someone to be on site 5 days a week initially in Schaumburg IL. An onsite first interview will be also required. Please dont apply if you dont meet these requirements.
The Senior Information Security Engineer is responsible for designing, implementing, and managing enterprise security controls that support regulatory compliance and strengthen the organization’s overall security posture. This role leads the implementation of security technologies across cloud, infrastructure, identity, and endpoint environments while supporting compliance with SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, CSA STAR Level 2, Cyber Essentials+, HIPAA, and other industry frameworks.
Key Responsibilities
- Design, implement, and maintain enterprise security controls aligned with industry standards and compliance requirements.
- Lead Identity and Access Management (IAM), including RBAC, privileged access management (PAM), access governance, and identity lifecycle management.
- Manage secure authentication solutions, including MFA, SSO, federation, and certificate-based authentication.
- Administer endpoint and cloud security technologies, including antivirus, EDR/XDR, malware protection, and threat detection.
- Develop and maintain Data Loss Prevention (DLP) strategies across endpoints, email, networks, and cloud environments.
- Oversee vulnerability management, including scanning, risk prioritization, remediation tracking, patch management, and penetration test coordination.
- Establish secure configuration management processes, including security baselines, change control, compliance monitoring, and Infrastructure as Code (IaC) validation.
- Partner with Infrastructure leadership and the CISO to design and implement security controls for Azure and Google Cloud Platform (Google Cloud Platform).
- Support physical security technologies and integrate physical and logical access controls.
- Assist with security assessments, audits, certifications, and remediation activities while working with internal stakeholders and external auditors.
- Provide technical leadership and mentor security team members on security best practices and continuous improvement initiatives.
Technical Expertise
- Enterprise IAM, RBAC, ABAC, PAM, and identity governance
- MFA, SSO, SAML, OAuth 2.0, OpenID Connect (OIDC), PKI, and certificate management
- Endpoint security, EDR/XDR, threat intelligence, malware protection, and incident response
- Data Loss Prevention (DLP), encryption, tokenization, and data classification
- Configuration management, security baselines, compliance automation, and IaC security
- Vulnerability management, patch management, penetration testing, and remediation
- Physical access control systems (PACS) and integrated security monitoring
- Compliance & Security Frameworks
Experience supporting security programs aligned with:
- SOC 2 Type II
- ISO/IEC 27001
- ISO/IEC 42001
- CSA STAR Level 2
- HIPAA
- NIST Cybersecurity Framework (CSF)
- CIS Controls
- MITRE ATT&CK
Qualifications
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 5 years of information security, including hands‑on implementation of enterprise security controls.
- Experience securing cloud environments (Azure and Google Cloud Platform) and enterprise infrastructure.
- Knowledge of Zero Trust architecture, DevSecOps, AI/ML security, and security automation.
- Proficiency with scripting and automation tools such as Python, PowerShell, Bash, or Terraform.