Security Engineer
Sargent & Lundy2 hours ago
Base Salary
$78k - $119k/yr
Responsibilities
- Operate the full IAM lifecycle in Microsoft Entra, including SSO, MFA, conditional access, lifecycle workflows, entitlement management, and privileged access integration.
- Build, tune, and monitor Zero Trust controls across identity, device, network, and application layers.
- Implement and operate cloud security controls in Microsoft Azure and Oracle Cloud Infrastructure, including landing zones, network security groups, identity, key management, encryption, logging, workload protection, and CSPM tooling.
- Manage Palo Alto Prisma Access and partner with the SOC to tune Cortex XSIAM, including data onboarding, parser tuning, correlation rules, detection content, and SOAR playbooks.
- Implement and tune Microsoft Purview Information Protection, DLP, Insider Risk Management, sensitivity labels, and auto-classification across enterprise collaboration and storage platforms.
- Design controls for safe enterprise AI usage, including data-exposure prevention, prompt and usage monitoring, and mitigation of prompt injection, model abuse, sensitive-data leakage, and shadow AI risks.
- Review SaaS, IaaS, PaaS, and in-house application security designs and provide actionable findings.
- Translate security and compliance requirements into working configurations aligned with ISO 27001, NIST 800-171, CMMC Level 2, and SOC 2.
Requirements
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
- At least 5 years of hands-on Security Engineering experience with ownership of enterprise security platforms in production.
- Deep hands-on Microsoft Entra IAM lifecycle experience and applied Zero Trust implementation experience.
- Hands-on Microsoft Azure cloud security experience and strong preference for Oracle Cloud Infrastructure security experience.
- Hands-on configuration and operation of Palo Alto Prisma Access, Prisma Cloud, Cortex XDR, and XSIAM.
- Implementation-level Microsoft Purview DLP experience, including policy authoring, classification, labeling, tuning, and incident handling.
- Working knowledge of enterprise AI risks and mitigation controls, plus experience across on-premises and cloud environments and Windows, macOS, and Linux endpoints.
- Familiarity with ISO 27001, NIST 800-171, CMMC Level 2, and SOC 2, with the ability to convert control requirements into working configurations.
- Required certification of CompTIA Security+, (ISC)² SSCP, PCCSE, or an equivalent foundational technical certification.
- Preferred qualifications include Microsoft Azure Security certification such as AZ-500, Microsoft Purview Information Protection and DLP certification, Oracle Cloud Infrastructure security credentials, SC-100, CISSP, or CCSP.
Benefits
- Hybrid schedule with 3 days per week in the downtown Chicago office and 2 days remote from home.
- Medical, dental, and vision health plans; life and accident insurance; disability coverage; employee assistance program; back-up daycare; and FSA and HSA options.
- 401(k), pre-tax commuter account, merit scholarship program, employee discount program, corporate charitable giving, and tuition assistance.
- First professional licensure bonus, employee referral bonus, and flexible work arrangements.
- Paid personal/sick time, vacation, holidays, parental leave, and bereavement leave.