Senior Information Security Engineer
Indexed description
This is a permanent opportunity that will require someone to be on site 5 days a week initially in Schaumburg IL. An onsite first interview will be also required. Please dont apply if you dont meet these requirements.
The Senior Information Security Engineer is responsible for designing, implementing, and managing enterprise security controls that support regulatory compliance and strengthen the organization’s overall security posture. This role leads the implementation of security technologies across cloud, infrastructure, identity, and endpoint environments while supporting compliance with SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, CSA STAR Level 2, Cyber Essentials+, HIPAA, and other industry frameworks
.
Key Responsibiliti
es
Design, implement, and maintain enterprise security controls aligned with industry standards and compliance requiremen
ts.Lead Identity and Access Management (IAM), including RBAC, privileged access management (PAM), access governance, and identity lifecycle manageme
nt.Manage secure authentication solutions, including MFA, SSO, federation, and certificate-based authenticati
on.Administer endpoint and cloud security technologies, including antivirus, EDR/XDR, malware protection, and threat detecti
on.Develop and maintain Data Loss Prevention (DLP) strategies across endpoints, email, networks, and cloud environmen
ts.Oversee vulnerability management, including scanning, risk prioritization, remediation tracking, patch management, and penetration test coordinati
on.Establish secure configuration management processes, including security baselines, change control, compliance monitoring, and Infrastructure as Code (IaC) validati
on.Partner with Infrastructure leadership and the CISO to design and implement security controls for Azure and Google Cloud Platform (Google Cloud Platfor
m).Support physical security technologies and integrate physical and logical access contro
ls.Assist with security assessments, audits, certifications, and remediation activities while working with internal stakeholders and external audito
rs.Provide technical leadership and mentor security team members on security best practices and continuous improvement initiativ
es.
Technical Exper
tise
Enterprise IAM, RBAC, ABAC, PAM, and identity gover
nanceMFA, SSO, SAML, OAuth 2.0, OpenID Connect (OIDC), PKI, and certificate manag
ementEndpoint security, EDR/XDR, threat intelligence, malware protection, and incident res
ponseData Loss Prevention (DLP), encryption, tokenization, and data classific
ationConfiguration management, security baselines, compliance automation, and IaC sec
urityVulnerability management, patch management, penetration testing, and remedi
ationPhysical access control systems (PACS) and integrated security monit
oringCompliance & Security Frame
works
Experience supporting security programs aligned
with:
SOC 2
Type IIISO/IE
C 27001ISO/IE
C 42001CSA STAR
Level 2Cyber Esse
ntial
s+HIPAANIST Cybersecurity Framewor
k (CSF)CIS C
ontrolsMITRE ATT
&CK
Qualif
ications
Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent exp
erience).5 years of information security, including hands-on implementation of enterprise security
controls.Experience securing cloud environments (Azure and Google Cloud Platform) and enterprise infras
tructure.Knowledge of Zero Trust architecture, DevSecOps, AI/ML security, and security au
tomation.Proficiency with scripting and automation tools such as Python, PowerShell, Bash, or T
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search