Information Security Engineer - Applications
Security architect job in Oak Brook, IL
In this role, you will work closely with IT teams to secure our applications throughout the development lifecycle. You'll help build a secure-by-design culture, drive security automation, and protect our systems against evolving threats. This position reports to the Manager of Information Security.
ESSENTIAL JOB FUNCTIONS:
Work with the Information Security Team to improve security for the company by configuring and administering security systems and tools
Monitor and respond to security events using SIEM and SOAR tools
Investigate security incidents to determine root cause and remediation tactics
Help automate security monitoring and remediation processes
Prepare and analyze security incident data and metrics for periodic reporting
Collaborate on vulnerability management, remediation, and penetration testing efforts
Implement and manage SAST, DAST, and Burp Suite across GitHub CI/CD pipelines and development workflows
Champion secure coding practices based on OWASP Top 10 and SSDF guidelines
Help secure cloud environments (Azure, AWS) and container-based deployments
Conduct regular security assessments to ensure alignment with SSDLC standards
After-hours configuration changes and on-call support required
MINIMUM QUALIFICATIONS:
Bachelor's degree in Computer Science, Information Systems (or related degree), or equivalent experience.
3+ years of experience in Application or Information Security
Strong understanding of SSDLC, NIST SSDF, and DevSecOps principles.
Experience with SAST/DAST tools (e.g., GitHub Advanced Security, BURP).
Solid knowledge of OWASP Top 10 and secure coding best practices.
Proficiency in GitHub for code review, pipeline security, and automation.
Hands-on with scripting (Python, PowerShell, Bash) and API security.
Experience in Azure and AWS cloud security, containers, and infrastructure-as-code.
Familiarity with SIEM/SOAR platforms and incident response workflows.
Experience with Windows, MacOS, and Linux operating systems
Proficient in Microsoft Office applications such as Microsoft Outlook, Word, Excel, PowerPoint, and SharePoint
** This is a full-time, W2 position with Hub Group - We are NOT able to provide sponsorship at this time **
Salary:
$95,000-150,000/year
+ bonus eligibility
**
This is an estimated range based on the circumstances at the time of posting, however, may change based on a combination of factors, including but not limited to skills, experience, education, market factors, geographical location, budget, and demand**
Benefits
We offer a comprehensive benefits plan including:
Medical
Dental
Vision
Flexible Spending Account (FSA)
Employee Assistance Program (EAP)
Life & AD&D Insurance
Disability
Paid Time Off
Paid Holidays
BEWARE OF FRAUD!
Hub Group has become aware of online recruiting related scams in which individuals who are not affiliated with or authorized by Hub Group are using Hub Group's name in fraudulent emails, job postings, or social media messages. In light of these scams, please bear the following in mind
Hub Group will never solicit money or credit card information in connection with a Hub Group job application.
Hub Group does not communicate with candidates via online chatrooms such as Signal or Discord using email accounts such as Gmail or Hotmail.
Hub Group job postings are posted on our career site: ********************************
About Us
Hub Group is the premier, customer-centric supply chain company offering comprehensive transportation and logistics management solutions. Keeping our customers' needs in focus, Hub Group designs, continually optimizes and applies industry-leading technology to our customers' supply chains for better service, greater efficiency and total visibility. As an award-winning, publicly traded company (NASDAQ: HUBG) with $4 billion in revenue, our 6,000 employees and drivers across the globe are always in pursuit of "The Way Ahead" - a commitment to service, integrity and innovation. We believe the way you do something is just as important as what you do. For more information, visit ****************
Sr. Information Security Engineer - AI
Security architect job in Rosemont, IL
Job Title: Senior Information Security Engineer - AI
Primary Location: Rosemont, IL - Hybrid, 3 days onsite
Direct Hire
TalentFish is casting a line for a Senior Information Security Engineer - AI/Artificial Intelligence. This is a Direct Hire role based in Rosemont, IL with a hybrid schedule (3 days onsite) with our premier client.
This is a new, exciting position within an awarded top Chicago employer organization where you'll contribute to the organization's Responsible Artificial Intelligence governance by assessing the security, integrity, and risks associated with the use of AI models and technologies. This role is hands-on and works closely with multi-disciplinary teams to evaluate AI use cases and maintain AI security frameworks and standards.
What You Bring to the Role (Ideal Experience)
• Bachelor's degree in Computer Science, Mathematics, or related field
• 5+ years of total professional experience, including security, data security, or control validation experience
• 2-3 years of practical, hands-on experience working with Artificial Intelligence technologies; working directly with AI models or ML systems
• Ability to evaluate AI model risks, including bias, data exposure, data leakage, and model poisoning
• Data processing or analytics skills are a plus
What You'll Do (Skills Used in This Position)
• Lead security assessments for AI models, including Large Language Models (LLMs), Natural Language Models (NLMs), and Small Language Models (SLMs)
• Participate in review committees to assess AI use cases for value, complexity, feasibility, risk, compliance, and strategic alignment
• Review AI architecture and usage within internal and third-party solutions to ensure adherence to AI security frameworks and regulatory requirements
• Support development and maintenance of AI security standards, frameworks, and governance models
• Provide education on AI security best practices, emerging risks, and mitigation strategies
• Perform additional related responsibilities as required
Compensation Information
The expected salary range for this position is $120,000 - $150,000 per year, depending on experience and qualifications. This role also qualifies for comprehensive benefits such as health insurance, 401(k), and paid time off. TalentFish is committed to pay transparency and equal opportunity. The salary range provided is in compliance with applicable state and federal regulations.
This role requires authorization to work in the U.S. without current or future visa sponsorship.
All offers are contingent upon the completion of a background check, which may include but is not limited to reference checks, education verification, employment verification, drug testing, criminal records checks, and any required certifications or compliance requirements based on the end client's background check policies and applicable laws.
TalentFish is an employee-owned company pioneering a new realm in talent acquisition. We are redefining IT staffing by evolving AI, video screening, and our unique platform. TalentFish focuses on providing the best employee, consultant, and client experience possible.
At TalentFish we are an Equal Opportunity Employer; we embrace and encourage diversity!
Information Security Officer
Security architect job in Chicago, IL
Job Title:
Business Information Security Officer - Clinical
Employment Type:
Full-Time
Salary Range:
$130,000 - $140,000 + Benefits (Health, Dental, Vision, PTO, 401K)
About the Role:
We're seeking a Business Information Security Officer (BISO) to serve as a trusted advisor and strategic partner to business and clinical leaders. In this highly visible role, you'll embed cybersecurity into everyday operations, influence security adoption, and ensure compliance with frameworks like NIST, HIPAA, and FERPA.
This is an opportunity to shape cybersecurity strategy in healthcare, research, and education while collaborating with executive leadership to advance a security-first culture.
Key Responsibilities:
Act as the frontline cybersecurity liaison for business and clinical leaders
Identify and escalate domain-specific cybersecurity risks
Monitor compliance with security policies and regulatory frameworks (HIPAA, FERPA, NIST CSF)
Lead security awareness and risk engagement programs
Develop and execute a roadmap of security initiatives aligned with business goals
Drive change management for cybersecurity adoption
What We're Looking For:
Bachelor's degree in Computer Science or related field
5-7 years in Information Security, GRC, or cybersecurity education
3+ years managing cross-functional teams and projects
Strong background in risk management, governance, and compliance
Excellent communication and leadership skills
Preferred:
Healthcare or clinical environment experience
Certifications: CISSP, CISM, PMP
Security Engineer
Security architect job in Chicago, IL
About Us
Founded in 2014, we offer the industry's first and only cloud-based, fully-customizable, end-to-end software solution to automate securities-based lending from origination through the life of the loan. By combining thought leadership in suitability and risk management with industry-leading education and the latest technology, Supernova enables advisors to deliver holistic, goals-based advice and to help their clients achieve financial wellness. We partner with the industry's largest banks, most prominent insurance companies and leading online brokerages to democratize access to securities-based lending and better the entire financial ecosystem.
Why Join Supernova?
At Supernova Technology, we believe that the best results come from a team that is passionate, driven, and supported in all aspects of their professional lives. Here, you'll work alongside talented and innovative individuals who are committed to driving the future of securities-based lending technology. We foster a culture of collaboration, continuous learning, and growth, where each person's contributions make a real impact.
Job Overview
We are seeking a highly motivated and detail-oriented Security Engineer to help secure our securities-backed lending SaaS platform. The successful candidate will focus primarily on application security, secure SDLC, and application vulnerability management, while also assisting with the execution and implementation of broader information security initiatives. You'll partner with engineering, SRE/DevOps, and business teams to embed security into our build and delivery processes, support risk reduction across cloud and endpoint surfaces, and drive measurable remediation outcomes in a regulated financial-services environment.
RESPONSIBILITIES:
Perform hands-on web/API penetration tests, validate scanner findings, and provide clear PoCs, impact statements, and prioritized remediation aligned with OWASP.
Integrate and tune SAST, DAST, SCA, container, and secret-detection tools in CI/CD; define pass/fail gates and PR checklists.
Conduct lightweight threat modeling and security design reviews for new features such as authentication, session management, and secrets handling.
Manage the full application vulnerability lifecycle (discover → prioritize → fix → retest → close) with SLAs and metrics.
Assist in hardening AWS and ECS/Docker workloads (IAM roles, network segmentation, image policies, logging/monitoring) and support patch hygiene across cloud, container, and endpoints.
Participate in incident response, including exploit reproduction, log analysis, impact assessment, and lessons learned.
Provide evidence for audits (ISO 27001, SOC 2, NIST SSDF), maintain policies and developer guidance, and support vendor/security evaluations.
Translate findings into developer-ready tickets, publish secure-coding guidance, and partner with engineering to streamline secure delivery.
Prototype automation, explore AI/LLM-assisted workflows to improve triage and code review, and share improvements across teams.
Contribute to organization-wide cybersecurity training and awareness efforts.
QUALIFICATIONS:
Bachelor's degree in security engineering, information assurance, or related field.
2-3 years of experience in security or software engineering (internships, labs, or open-source count), preferably in regulated industries.
Strong knowledge of web/API security issues (auth, session management, injections, SSRF, CSRF, access control) and common cloud/web misconfigurations.
Experience with SDLC security tools (SAST/DAST/SCA/secret detection/container scanning), CI/CD workflows, and Git.
Scripting or coding skills (Python or JavaScript/TypeScript) and ability to read backend code.
Familiarity with AWS security basics (IAM least privilege, KMS, logging/monitoring, security groups) and Docker/ECS runtime considerations.
Clear communication skills with the ability to translate risk into actionable remediation.
Experience using AI/LLM-assisted tools for triage, documentation, or code review preferred.
Exposure to WAF/CDN tuning, API protection, and risk-based remediation SLAs/metrics preferred.
Familiarity with frameworks like OWASP ASVS/SAMM, NIST SSDF, ISO 27001, SOC 2, PCI DSS preferred.
Relevant security certifications preferred.
Our Employee Benefits
At Supernova Technology, we provide a robust benefits package to support the health and well-being of our employees. Our offerings include:
Medical, Dental, and Vision Insurance: Multiple plans with coverage for employees and dependents.
HSA and FSA Accounts: Tax-advantaged accounts for health and dependent care expenses.
Life and Disability Insurance: Employer-paid basic coverage with options for additional voluntary coverage.
Compensation: $95,000 - $130,000
Retirement Savings: 401(k) plan with employer contributions.
Employee Assistance Program (EAP): Confidential support services, including free therapy sessions.
Paid Time Off: Flexible PTO policies.
Additional Perks: Commuter benefits, pet insurance, continuing education assistance, and more.
Note: Actual salary at the time of hire may vary and may be above or below the range based on various factors, including but not limited to, the candidate's relevant qualifications, skills and experience, and the location where this position may be filled.
Our Core Values
Our core values drive everything we do. At Supernova, we...
Form, execute, and communicate new ideas that add value to our employees and customers
Strive through obstacles and failures
Follow-through on promises or commitments to others, accept responsibility, and answer for actions & decisions
Listen to, understand, and support our employees and customers
Act with speed, positive attitude, and flexibility
Exceed expectations and surpass ourselves every day; we embrace a sense of pride and never stop growing
Join us and make an impact while growing your career at Supernova.
Senior Security Engineer
Security architect job in Chicago, IL
Salary: Open + Bonus
Hybrid: 3 days onsite, 2 days remote
*This role is open to H1B transfer*
Qualifications
Bachelors' degree including 6+ years of related experience
Experience in one or more of the following disciplines: security operations, development, engineering, or architecture
Experience supporting privileged access management and access controls programs.
Professional or personal experience using AI coding agents such as OpenAI Codex, Claude Code, or Gemini CLI.
Expertise in providing operational and engineering support for one or more of the following: CyberArk, HashiCorp Vault, Active Directory Certificate Services (ADCS), HSMs, and Public Key Infrastructure (PKI).
Expertise in scripting languages and developing in one or more of the following languages Golang, Bash, Python, PowerShell, Ansible, and/or Terraform.
Knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation.
Knowledge of application authentication and authorization systems (i.e., Active Directory, OAuth 2.0, OIDC, AWS IAM, App Role, k8s, LDAPS, Kerberos, Certificate)
Working knowledge of the cloud ecosystem and CI/CD deployments with Terraform, Ansible, and Jenkins pipelines.
Working knowledge of security architecture design and principles including confidentiality, integrity and availability.
Responsibilities
Manage privileged access systems that protect most critical assets, implement AI-based security capabilities, and help shape security architecture.
Provide 24x7 operational support for the suite of privileged management solutions (e.g., CyberArk, Hashi, PKI), including implementing hot fixes, resolving bugs, troubleshooting issues, performing break-fixes, managing secrets lifecycle, and delivering end-user support.
Maintain robust operational integrity of privileged access management infrastructure throughout its lifecycle (e.g., patching, version control, system upgrades, etc.). Provide organizational subject matter experts on secrets management and privileged access management architecture, establishing and enforcing security as code principles throughout the environment.
Develop and implement system enhancements to improve platform user experience and automated integrations, while designing long-term solutions to address operational issues through innovative technologies including artificial intelligence for faster detection and remediation of functional and technical problems.
Sr. Security Engineer - Red Team
Security architect job in Chicago, IL
About the Company:
A Leading Financial Service Client is looking to hire a strong Security Engineer who can lead Red team exercises against a hybrid environment using threat intelligence and the MITRE Telecommunication&CK Framework.
Responsibilities:
Approx 8 years' experience with industry standard Red Team testing tools (Cobalt Strike, Mythic C2, Rubeus, Bloodhound, Covenant, etc.) or the ability to demonstrate equivalent knowledge.
Expert understanding of how an Advanced Persistent Threat could compromise a financial institution without using phishing.
Expert understanding of Red Team concepts, tools, and automation strategies.
Expert understanding of MITRE Telecommunication&CK framework tactics, techniques, and procedures.
Expert understanding of measuring and rating vulnerabilities based on principal characteristics of a vulnerability.
Expert understanding of Windows and Linux system hardening concepts and techniques.
Senior Manager, Information Security Office (ISO) Consultant
Security architect job in Chicago, IL
Senior Manager, Information Security Office (ISO) Consultant At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
The Senior Lead ISO Consultant will provide cyber security architecture advisory support needed to build the Technology & Business capabilities on a novel Modern platform, that will enable customer set-up, use, and management of a Capital One Credit Card, including Data Product. In this role, the responsibilities will include:
Act as a central Information Security point of contact for the Global Payment Networks line of business
Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's Information Security capabilities, solutions, policies, procedures and standards
Collaborating with enterprise cyber teams and tech architects in defining and driving the cyber architecture strategy and guiding principles for the architecting and designing of the modern platforms.
Support security architecture and implementation needs for technology modernization efforts
Overseeing all cyber related dependencies across the multiple components being built for the modernization effort.
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad-hoc support on special Information Security hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
Support the team on collectively mapping technologies to a standardized framework in order to identify and execute on best practices in risk reduction through the configuration of cybersecurity tools and platforms.
Support the development, modification, and use of capability, risk, or threat classification frameworks and standardization methodologies to facilitate the conduct of correlative capability, maturity, and effectiveness evaluations.
Support data validation and communications on the impact of identified operational, compliance, process, control, and tooling gaps and potential remediation courses of action to multiple audiences, including leadership, to support the enhancement of their cybersecurity postures.
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
At least 4 years of experience with cloud security
Preferred Qualifications:
Bachelor's Degree
7+ years of experience in securing a public cloud environment (AWS, GCP, Azure)
6+ years of cyber security advisory and technology consulting experience
6+ years of experience in Cyber Risk Management
3+ years of experience on cryptography, HSMs and similar systems
Knowledge of HPNS, ATM, Mainframe technologies and other payment networks infrastructure technologies
Experience in security integration for Mergers and Acquisitions
Experience with PCI and Payment Network Compliance.
Professional certifications AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $204,900 - $233,800 for Sr Manager, Cyber Technical
McLean, VA: $225,400 - $257,200 for Sr Manager, Cyber Technical
New York, NY: $245,900 - $280,600 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections ; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
Principal Cloud Security Architect
Security architect job in Chicago, IL
Role OverviewThe Principal Cloud Security Architect evaluates cloud architectures, identity models, permissions, and security controls across large-scale environments. This role focuses on identifying architectural risks, misconfigurations, and long-term security design gaps.
What You'll Do- Assess cloud architectures (AWS, Azure, GCP) for security gaps - Review IAM configurations, network segmentation, and resource policies - Identify misconfigurations, privilege risks, and insecure patterns - Summarize architectural flaws and provide structured mitigation guidance - Validate alignment with security frameworks and best practices - Support recurring assessments of cloud environments and deployment patterns What You BringMust-Have:- Deep experience in cloud security architecture - Strong understanding of IAM, network design, and cloud service models - Ability to document complex architectures in clear, structured form Nice-to-Have:- Experience with multi-cloud, zero-trust, or high-compliance environments
Auto-ApplyStaff Systems Security Engineer
Security architect job in Rolling Meadows, IL
RELOCATION ASSISTANCE: Relocation assistance may be available CLEARANCE TYPE: SAPTRAVEL: Yes, 10% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
We are seeking capable, talented, and motivated team-contributors at our Northrop Grumman Rolling Meadows site. Our products range from advanced sensing technologies to state-of-the-art targeting and tracking systems that are deployed in Electro-Optical Infrared (EOIR) and Radio Frequency Electronic Warfare (RFEW) systems. These systems are designed, developed, built, integrated, and tested by the capable folks at our company to protect the lives of US and Allied warfighters in present and future conflicts. Enjoy a culture where your voice is valued and start contributing to our team of passionate professionals providing real-life solutions to our world's biggest challenges. We take pride in creating purposeful work and allowing our employees to grow and achieve their goals every day by Defining Possible. With our competitive pay and comprehensive benefits, we have the right opportunities to fit your life and launch your career today. If you are interested in consideration to be included as a part of this team, we would invite you to apply.
Northrop Grumman Mission Systems Sector (NGMS) is seeking a Staff Systems Security Engineer to join our Systems Security Engineering team. The Security Engineering team is cross-disciplinary across the security domain; encompassing embedded Systems Engineering, Cybersecurity, Software Security and Anti-Tamper Engineering.
Roles & Responsibilities:
· Design/develop system architectures and generate system designs to be implemented in a cost-effective manner.
Implement and ensure compliance with government policies (e.g., JSIG, DAAPM, NIST 800-53, CNSSI 1253, DODI 5200.39, etc.) by reviewing process tailoring needs and approving documented procedures.
Guide and monitor technical documentation/publication to document trades studies, system designs, analysis, and results related to a systems security posture such as identifying Critical Program Information (CPI) and creation of Anti-Tamper Plans
Develop an understanding of system interfaces and how to protect them.
Assist with the definition of key capabilities and performance requirements.
Adapt production and development products to meet unique customer needs and support the development of system security functions.
Collaborate with security engineering team(s), across a portfolio of programs, through the duration of program execution to solve issues and to prepare for requirements sell off.
Support technical work products developed by the larger engineering team in support of major milestone deliveries (e.g.: SRR, SVR, PDR, CDR, TRR, PRR).
Authoring technical documentation such as white papers, proposal technical volumes, and program milestone briefings.
Collaborate with security engineering team(s), across a portfolio of programs, through the duration of program execution to solve issues and to prepare for requirements sell off.
Other duties may include technical leadership, business capture activities, interfacing with industry partners and the USG.
This position will be full-time, on-site at our Rolling Meadows, IL location.
This position is contingent upon Funding/Contract award, special access program and acquiring and maintaining the necessary US Government security clearance per customers' requirements prior to start.
Basic Qualifications for a Staff Systems Security Engineer:
Bachelor's degree in Electrical Engineering, Software Engineering, Computer Engineering, Computer Science, Cybersecurity, or related technical fields with 12+years of related experience, a Master's degree in Electrical Engineering, Software Engineering, Computer Engineering, Computer Science, Cybersecurity, or related technical fields with 10+ years of related experience or a PhD in Electrical Engineering, Software Engineering, Computer Engineering, Computer Science, Cybersecurity, or related technical fields with 7+ years of related experience.
3 years of cumulative experience on DoD based platforms and/or systems regarding the application of Cybersecurity RMF or Anti-Tamper with competencies in security threat analysis, systems architecture, engineering design, requirements derivation, validation, and verification.
Must have demonstrated experience in leading teams to solve technical problems, including decomposition, root cause analysis, solution development, implementation and monitoring
Experience contributing to and/or making technical presentations to internal and external customers.
Ability to obtain and maintain a minimum of a Secret Clearance with additional customer specified clearance prior to start.
Preferred Qualifications for a Staff Systems Security Engineer:
Advanced degrees in Electrical Engineering, Software Engineering, Computer Engineering, Computer Science, Cybersecurity, or related technical fields.
Experience with design verification testing, reverse engineering, embedded software development, Cybersecurity, or Anti-Tamper Possess a DoD 8140 certification, e.g. CompTIA Security+, CISSP, or similar. Experience with proposals and creating basis of estimates (BOEs)
Primary Level Salary Range: $163,200.00 - $244,800.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
Auto-ApplySenior Security Architect
Security architect job in Schaumburg, IL
Job DescriptionDescription:
Paylocity is an award-winning provider of cloud-based HR and payroll software solutions, offering the most complete platform for the modern workforce. The company has become one of the fastest-growing HCM software providers worldwide by offering an intuitive, easy-to-use product suite that helps businesses automate and streamline HR and payroll processes, attract and retain talent, and build a strong workplace culture.
While traditional HR and payroll providers automate basic HR processes such as payroll and benefits administration, Paylocity goes further by developing tools that HR and businesses need to compete for talent and deliver against the expectations of the modern workforce.
We give our employees what they need to succeed, including great benefits and perks! We offer medical, dental, vision, life, disability, and a 401(k) match, as well as perks that support you, your family, and your finances. And if it's career development you desire, we provide that, too! At Paylocity, people matter most and have always been at the heart of our business.
Help Paylocity enhance communication and enable employees to connect, collaborate, and create from anywhere with a position in Product & Technology!
Want to develop the strategies and principles needed to deliver compelling software? Join our team and help us enhance our all-in-one software platform, elevate our one-of-a-kind technology, and improve the employee experience. Take your career to the next level at one of G2's Top 100 Software Companies. Explore our Product & Technology positions to see where you fit!
Position Overview
The Senior Security Architect plays a critical role in shaping and securing the technology landscape at Paylocity. This individual is responsible for the strategic planning, evaluation, and design of security controls across the enterprise. As a senior member of the Information Security team, you will serve as a trusted advisor and subject matter expert, collaborating with cross-functional teams to embed security into the fabric of our products, services, and infrastructure.
This is a hands-on, forward-looking role that offers the opportunity to influence the future of security architecture in a fast-paced, SaaS based, and innovation-driven environment. The ideal candidate is a self-starter with deep technical expertise, strong communication skills, and a passion for building secure, scalable systems.
Primary Responsibilities
The Senior Security Architect is accountable for maintaining the confidentiality, integrity, and availability of Paylocity's systems and data. This includes leading the development of secure architectural patterns, evaluating technical risks, and partnering with engineering and product teams to implement effective security controls.
Key Responsibility Areas:
Serve as a strategic contributor in identifying and driving security architecture initiatives aligned with business and technology goals.
Collaborate across engineering, product, infrastructure, and compliance teams to ensure security is embedded throughout the software development lifecycle (SDLC).
Design and mature enterprise security tools, frameworks, and architectural patterns to support scalable and resilient security operations.
Participate in the Enterprise Architecture Review Board to evaluate proposed changes, assess security implications, and promote secure design principles.
Develop and operationalize a framework for assessing cloud and on-premises infrastructure for security risks, providing actionable recommendations to enhance the organization's security posture.
Provide architectural guidance on the secure integration and use of AI technologies, including third-party tools and embedded AI capabilities, with a focus on risk mitigation and compliance.
Lead and influence large-scale, cross-functional security initiatives, ensuring alignment with architectural standards and successful delivery of outcomes.
Actively manage stakeholder expectations and communicate security architecture strategies, roadmaps, and project statuses to technical and non-technical audiences.
Foster strong partnerships across the Information Security department and other business units to jointly deliver secure solutions.
Apply a risk-based approach to prioritize architectural decisions and resource allocation, balancing innovation with security.
Stay informed of changes in Paylocity's technical environment and proactively identify areas of emerging risk or architectural improvement.
Operate independently, driving initiatives from concept to execution while keeping stakeholders informed and engaged throughout the process.
Lead vendor evaluations and architecture design for next-generation security solutions, including Zero Trust, Passwordless Authentication, and modern SIEM platforms.
Technical Expertise
Demonstrated experience in architecting and securing one or more of the following platforms and technologies:
Identity & Access Management: Active Directory (Azure AD, On-prem), Privileged Access Management (PAM), Public Key Infrastructure (PKI)
Cloud Security: Microsoft 365 E5 (Secure Email, DLP, Collaboration), AWS/GCP/Azure security services
Data Protection: Data Loss Prevention (ProofPoint, ForcePoint), Email Security (ProofPoint, Mimecast)
Network & Endpoint Security: DNS Filtering and Web Proxies (Cisco Umbrella, Zscaler), Endpoint Detection & Response (Microsoft Defender ATP, CrowdStrike, Carbon Black), Network Firewalls (Cisco, Palo Alto, Checkpoint)
Monitoring & Detection: Centralized logging and SIEM (Splunk, Exabeam), Web Application Firewalls (F5 ASM, Imperva)
Emerging Technologies: Familiarity with GenAI, LLMs, and Agentic AI, including associated security risks and architectural considerations
Qualifications
Education & Experience:
Bachelor's degree in information security, Computer Science, or a related field, or equivalent work experience.
10+ years of experience in Security Architecture, Information Security, or related technical roles
Deep understanding of security frameworks and methodologies including:
NIST Cybersecurity Framework (CSF)
NIST Risk Management Framework (RMF)
MITRE ATT&CK
Threat modeling techniques such as STRIDE, DREAD, and PASTA
Architecture frameworks such as TOGAF, SABSA, and Zachman
Certifications (Preferred):
Certified Information Systems Security Professional (CISSP)
Certified Information Security Manager (CISM)
AWS Certified Solutions Architect - Professional
Google Cloud Professional Cloud Architect
Cloud Security Alliance Certificate of Competency in Zero Trust (CCZT)
Other relevant certifications in cloud, architecture, or risk management
Paylocity is an equal-opportunity employer. Paylocity is committed to the full inclusion of all individuals. We recruit, train, compensate, and promote regardless of race, religion, color, national origin, sex, disability, age, veteran status, and other protected status as required by applicable law. At Paylocity, we believe diversity makes us better.
We embrace and encourage our employees' differences in age, culture, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion or spiritual belief, sexual orientation, socio-economic status, veteran status, and other characteristics that make our employees unique. We actively cultivate these differences through our employee resource groups (ERGs), employee experiences, perspectives, talents, and approaches to drive innovation in the software and services we provide our customers.
We comply with federal and state disability laws and make reasonable accommodations for applicants and employees with disabilities. To request reasonable accommodation in the job application or interview process, please contact accessibility@paylocity.com. This email address is exclusively designated for such requests, aligning with federal and state disability laws. Please do not send resumes to this email address, as they will be removed.
This role can be performed from any office in the US. The pay range for this position is $118k - $170/yr; however, base pay offered may vary depending on job-related knowledge, skills, and experience. This position is eligible for an annual restricted stock unit grant based on individual performance in addition to a full range of benefits outlined here. This information is provided per the relevant state and local pay transparency laws for the location in which this position will be performed. Base pay information is based on market location. Applicants should apply via **************************
Requirements:
Senior Security Architect (Loveland, CO, NYC, Newark, NJ)
Security architect job in Oak Brook, IL
We understand that the world we want tomorrow starts with how we do business today, and that's why we're inspired to make A Better World for Pets. Antech is comprised of a diverse team of individuals who are committed to each other's growth and development. Our culture is centered on our guiding philosophy, The Five Principles: Quality, Responsibility, Mutuality, Efficiency and Freedom. Today Antech is driving the future of pet health as part of Mars Science & Diagnostics, a family-owned company focused on veterinary care.
Current Associates will need to apply through the internal career site. Please log into Workday and click on Menu or View All Apps, select the Jobs Hub app, then click the magnifying glass to Browse Jobs.
**The Target Pay Range for this position is as follows:**
**- Loveland, Colorado: $143,000- $178,000 annually.**
**- Chicago $149,000 - $187,000 annually.**
**- New York City: $156,000- $195,000 annually**
**At Antech, pay decisions are determined using factors such as relevant job-related skills, experience, education, training and budget.**
**Job Summary:**
The Senior Security Architect (SA) is responsible for designing and evolving secure enterprise architecture across our cloud, hybrid, and on-premises environments as part of the Cybersecurity function. The SA will work closely with Business Stakeholders, Enterprise Architects, and Information technology teams to ensure that SDx solutions designed follow Mars standards and are consistent throughout the SDx division. This individual will bring deep technical expertise in cloud security, API security, threat modeling, and design of reusable security reference architecture patterns to support scalable and resilient systems.
**Key Responsibilities:**
+ Define, design, and maintain enterprise-grade security architecture patterns, reference models and blueprints that align to Mars and SDx security standards and practices.
+ Architect secure solutions across multi-cloud, hybrid and on-premise solutions.
+ Work with our Product Security Engineers, Cloud and Development teams to embed security controls into our DevSecOps pipelines, micro-services, APIs and other components of SDx solutions.
+ Lead and facilitate threat modeling sessions with our Product Security Engineers and Cloud Development teams using methods such as STRIDE, DREAD or MITRE ATT&CK to ensure adversarial and attack-route analysis is built into our models.
+ Identify architectural risks and propose mitigation strategies early in the design lifecycle as well as performing retroactive security architecture reviews for existing solutions.
+ Partner with enterprise architects, cloud engineers, and DevOps teams to enforce security best practices.
+ Contribute to security policies, standards and guidelines aligning with business needs, Mars and any regulatory requirements.
+ Serve as a trusted security advisor to product engineering and infrastructure teams.
+ Support product security reviews, architecture discussions and secure design validation with our Product Security Engineers and Cloud Development teams.
+ Work with Mars Global Digital Operations (GDO) teams to explore, adapt and incorporate solutions into SDx environment.
+ Collaborate with Mars Risk Management, Vendor Cyber Risk Management, and other teams to ensure that risks identified are properly reported and managed through remediation.
+ Serve as the SA subject matter expert and coordinate with our GRC Specialist for the implementation of SDx cybersecurity governance to enforce policies, procedures, and standards, following SDx and Mars business requirements and security best practices.
+ Collaborate with critical teams including infrastructure, development, R&D, and Mars GDO to ensure alignment with Mars strategies.
+ Collaborate with other teams to achieve efficiencies while building a secure environment that integrates validated technology stack components.
+ Provide security architecture support in the design, implementation, and maintenance of solutions in an agile manner to improve efficiency and reduce errors or disruptions across SDx.
+ Work with our R&D and IT departments to apply threat modeling and/or adversarial approaches to ensure customer-facing technologies and products are secure and updated to best security practices in security architecture.
**Qualifications & Experience:**
+ Bachelors in Cybersecurity, Information Technology, Computer Science, Engineering, or related field. Master's degree is a plus, but not essential.
+ Knowledge applying Cloud and DevSecOps Security Architecture principles for Zero-trust.
+ Security Architecture design and review expertise in API security such as OAuth 2, OpenIDConnect, mTLS, API gateways, among others.
+ Threat Modeling and secure design reviews integrating them into a DevSecOps pipeline.
+ Pen testing and red teaming knowledge, specifically privilege escalation paths and incident management as well as threat modeling, attack-route analysis, application testing and vulnerability management related to security architecture designs.
+ Experience communicating complex security concepts effectively (technical, non-technical and executive level audiences).
+ Relevant certifications such as CISSP, GIAC Defensible Security Architecture, CISA or Security+.
+ Cloud security architecture or related certifications in Azure, AWS or GCP are preferred.
+ Experience in regulated industries (finance, healthcare, manufacturing, etc.) applying regulatory regulations and/or security frameworks.
+ Experience in a laboratory setting, veterinary clinics, healthcare or related systems.
+ Strong problem-solving and analytical mindset.
+ Hands-on background in DevSecOps, secure coding, and penetration testing.
+ Experience applying Identity Governance & Administration (IGA).
_Required Qualifications:_
+ 8+ years of experience in designing security reference architectures and reusable components.
+ Strong knowledge of network security principles including segmentation/microsegmentation and Zero Trust Architecture.
+ Strong knowledge of security coding as well as DevSecOps and Systems Development Lifecycle (SDLC).
+ Strong knowledge in Identity and Access Management solutions including Multi-factor authentication and Identity Service Providers (IdSP) such as Okta, ForgeRock, or other IAM tools.
+ Strong knowledge of information security frameworks such as NIST, ISO 27001, HITRUST, CIS, SOC 1/2/3, PCI-DSS, as well as privacy-related regulatory frameworks including GDPR.
**Physical Demands:**
+ Extensive sitting, phone, and computer use
+ Extend and reach with hands and arms and use hands and fingers
+ Occasionally required to bend, kneel, stoop, or crouch
+ May be required to lift, move, and carry up to 15 lbs.
+ Specific vision abilities required including close vision, color vision, depth perception, and the ability to adjust focus.
+ Hearing ability to effectively communicate via the telephone and in person
+ Ability to communicate verbally on the telephone and in person
+ Fluency in the English language
+ Extended hours may be needed
**Work Environment:**
The employee will primarily work in a typical office environment including use of cubicles, computers and overhead lighting. Temperature extremes will be minimal to nonexistent.
The noise level in the work environment is usually moderate. The employee will be required to use a computer, spreadsheets, database management, email, and the Internet. The employee is frequently required to use a calculator; fax, copy machine, and phone system.
**About Antech**
Antech is a leader in veterinary diagnostics, driven by our passion for innovation that delivers better animal health outcomes. Our products and services span 90+ reference laboratories around the globe; in-house diagnostic laboratory instruments and consumables, including rapid assay diagnostic products and digital cytology services; local and cloud-based data services; practice information management software and related software and support; veterinary imaging and technology; veterinary professional education and training; and board-certified specialist support services.
**Benefits**
Antech offers an industry competitive benefits package and continues to invest in and evolve benefits programs that meet the health, wellness and financial needs of our associates.
_Benefits eligiblity is based on employment status._
+ Paid Time Off & Holidays
+ Medical, Dental, Vision (Multiple Plans Available)
+ Basic Life (Company Paid) & Supplemental Life
+ Short and Long Term Disability (Company Paid)
+ Flexible Spending Accounts/Health Savings Accounts
+ Paid Parental Leave
+ 401(k) with company match
+ Tuition/Continuing Education Reimbursement
+ Life Assistance Program
+ Pet Care Discounts
**Commitment to Equal Employer Opportunities**
We are proud to be an Equal Opportunity Employer - Veterans / Disabled. For a complete EEO statement, please see our Career page at Antech Careers (************************************************************** .
**Note to Search Firms/Agencies**
Antech Diagnostics, Inc. and its subsidiaries and affiliates (Antech) do not compensate search firms for unsolicited assistance unless they have a written search agreement with Antech and the requisition is position-specific. Any resumes, curriculum vitae, and other unsolicited assistance from search firms that do not have a written search agreement or position-specific requisition submitted to any Associate of Antech will be deemed the sole property of Antech and no fee will be paid in the event the candidate is hired by Antech.
Google Cloud Security Architect
Security architect job in Chicago, IL
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies
As a Consultant or Senior Consultant, you will collaborate with cross-functional teams, including IT, security, and business units, to design and implement Google Cloud-based application innovation solutions. You will work alongside experienced cloud architects, data scientists, and other specialists, ensuring the successful delivery of scalable, cloud-native applications and AI-powered solutions.
What You'll Do
* Stay current with security trends, technologies, and best practices around Google Cloud solutions, leveraging tools like Cloud IAM, Cloud Security Command Center, BeyondCorp, and Cloud Armor.
* Define and guide transformational security strategies for Google Cloud environments, ensuring alignment with Google's Zero Trust and BeyondCorp principles.
* Translate complex regulatory requirements (e.g., GDPR, SOC 2, HIPAA) and technology standards into actionable functional and technical requirements for cloud and hybrid environments, ensuring security and compliance.
* Lead teams through various phases of gap analyses, including security assessments, remediation planning, roadmap development, and implementation of remediation actions using Google Cloud-native tools.
* Deliver on the vision, architecture, execution, and quality assurance of security projects on Google Cloud, driving initiatives that secure enterprise workloads and data.
* Guide stakeholders and senior leaders on aligning security solutions with broader business goals, ensuring the architecture follows Google Cloud's security best practices and roadmap.
* Establish security architecture patterns based on Google Cloud security frameworks and industry standards to meet the unique needs of enterprise clients.
* Collaborate with other Google Cloud architects and security teams to continuously improve security knowledge assets and best practices, ensuring the most effective security solutions for clients.
* Design and architect solutions to secure Generative AI models and applications against adversarial attacks, prompt injection, and their potential misuse for malicious cyber activities.
What You'll Bring
* Proven experience with Google Cloud security architecture, with hands-on experience in tools like Cloud IAM, VPC Service Controls, Cloud DLP, and Cloud Armor.
* Strong background in defining and implementing Zero Trust and BeyondCorp security models within Google Cloud environments.
* Familiarity or direct experience with Identity and Access Management (IAM), Data Protection, Vulnerability Management, and Cloud Security solutions in Google Cloud.
* Extensive experience with security design patterns specific to Google Cloud, as well as hybrid and multi-cloud security architecture.
* Experience in security and risk advisory consulting, particularly related to cloud security transformations.
* Ability to lead the development and implementation of cloud security roadmaps aligned with business goals and compliance needs.
* Familiarity with Google Cloud's Artificial Intelligence (AI) capabilities (e.g., Vertex AI, Generative AI services, Model Armor) including their applications, associated security risks (e.g., prompt injection, data poisoning, privacy concerns), and proven strategies for implementing security controls, governance, and responsible AI practices.
* Relevant certifications are strongly desired, including (but not limited to):
* GCP Professional Security Engineer
* GCP Professional Cloud Architect
* CISSP
* Security+
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices. For this position the base salary pay ranges are listed below. In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
East Bay, San Francisco, Silicon Valley:
* Consultant: $120,000-$177,000
* Senior Consultant: $140,000-$203,000
San Diego, Los Angeles, Orange County, Seattle, Houston, New Jersey, New York City, Westchester, Boston, Washington DC:
* Consultant: $110,000-$162,000
* Senior Consultant: $130,000-$186,000
All other locations:
* Consultant: $105,000-$148,000
* Senior Consultant: $115,000-$171,000
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
We are accepting applications until 12/31.
Information Security Manager
Security architect job in Downers Grove, IL
blue Stone Executive Search has been retained by our client, a multi billion dollar global organization, a world leader in their vertical, with a dedication to cutting-edge technology and work/family balance, to search for a motivated and energetic IT Leader to direct and manage their Information Security objectives on a company-wide basis.
Job Description
As the Manager of Information Security, you will be responsible for the development and execution of a comprehensive company wide information security strategy. The Information Security Manager will build and work with appropriate internal staff to deploy an information security awareness program to support compliance with information security policy, standards, procedures, and best practices. The Information Security Manager will develop needed security policies while working with appropriate HR and Legal teams on final version approval and distribution. You will also be expected to participate in information security response and provide audit/compliance and forensic activities for the company, as needed. As the Information Security Manager, you will implement proactive processes and technologies to monitor the company internal and external network environment for potential threats with appropriate response processes. You will also evaluate new technology that the company would use in execution of the information security strategy using both quantitative and qualitative methods. The Information Security Manager will also help to create a policy for the company and design and implement necessary tools to protect company data on employee owned devices.
Qualifications
Experience and familiarity with control and security frameworks such as COSO, COBiT, and ISO
Candidate has one or more current CISSP, CISM, CISA certifications
Two to five years security leadership experience required
Bachelor's degree in related field preferred
Solid understanding of information technology and information security including; firewalls, VPN's, penetration testing and other security devices with an emphasis on network security
Experience with management and administration with firewall technologies from Cisco and other firewall manufacturers
Knowledge in developing and socializing security policies and processes
Demonstrated ability to create information security strategy and execution plans
Knowledge of intrusion detection and prevention solutions and experience implementing them in a corporate environment
Excellent interpersonal skills with the ability to communicate with technical and non-technical contacts
Must be highly organized and detail oriented
Exceptional analytical and problem solving skills
Excellent written and verbal communication skills
Ability to manage multiple priorities to deliver results
Additional Information
blue Stone Executive Search successfully finds and secures the top talent within targeted industries. As executive search professionals, the advice we impart and the solutions we provide can have a significant impact on the businesses, careers and lives of others. We recognize these responsibilities and take them seriously. We value long-term relationships above short-term gain. We are continually seeking exceptional talent with the highest standards of professionalism.
E-mail resumes to
[email protected]
and phone ************.
SAP Security
Security architect job in Chicago, IL
Job Title: SAP Security Architect Duration for Contract: 5 Months + - ECC 6.0 Security design / architecture is the base requirement for the role. - 7+ years of experience in application or SAP ECC, BI, HR, portal and CRM security architecture, design and administration.
Summary:
Provide solutions architecture oversight for new development projects specific to SAP according to timelines and budget, while following accepted programming, testing and change control standards, and accepted business intelligence technology best practices.
Job Responsibilities:
• Define and document the structure, connections and relationships of business processes, organizational work groups, SAP data models, SAP applications, user interfaces, applications interfaces, SAP infrastructure and network topology.
• Provide standards, guidelines and statements of direction for IT system architectures, establishing a framework that constrains the design of systems for the purpose of integration of systems and accessibility of data supporting various business processes and functions.
• Define, design and develop the SAP enterprise systems information architecture to enable cross functional operational reporting and performance optimization.
• Identify strategic opportunities and drive cross-business and cross-functional change.
Skills:
• Knowledge of ITIL and SDLC.
• Experience in business system application design, development and installation.
• Experience in planning/architecture development and support.
• Experience designing and implementing advanced SAP application architectures.
Education/Experience:
• Bachelor's degree in Computer Science or a related field.
• Master's degree in Business or Management Information Systems preferred.
• 8-10 years of SAP functional systems experience.
• SAP Certification preferred.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Manager, Information Security
Security architect job in Chicago, IL
About Rethink First
Rethink First is a leading behavioral health technology company working to make mental wellness, education, and support accessible and scalable. Through our suite of cloud-based platforms-including RethinkEd, RethinkCare, and RethinkBH-we serve educators, employers, and providers with tools that deliver measurable, inclusive outcomes.
We're on a mission to make behavioral health more effective, equitable, and human-and we're looking for a creative visionary to help lead that charge.
About the Role
We are building a modern, cloud-forward security program grounded in Cyber Resilience, Application Security, and Security Assurance. As our Manager, Information Security, you will be the operational and execution leader for our Security Assurance function while helping shape key processes across SecOps and AppSec.
This role is ideal for someone who thrives in a high-growth SaaS environment, collaborates well cross-functionally, and wants to help mature a security program that must support HIPAA, SOC 2 Type II, HITRUST, and a broad healthcare customer base.
You will own the day-to-day execution of GRC, Audit Readiness, Evidence Collection, Policy Management, TPRM, and Client Trust-and must have hands-on experience implementing or operating Vanta as a centralized compliance automation platform.
You will serve as a multiplier for the Sr Director, creating repeatable processes, driving deadlines, maturing documentation, and ensuring audit-ready control operation across Azure, M365, and our SaaS product ecosystem.
Key Responsibilities
Security Assurance Leadership (Primary Responsibility - 60%)
Lead the end-to-end Security Assurance function across SOC 2, HIPAA, HITRUST, and regulatory frameworks.
Act as the program manager for all audits, coordinating with Legal, HR, Engineering, Product, and Infrastructure to maintain year-round audit readiness.
Own the implementation, configuration, optimization, and continuous operation of Vanta, including:
Control mapping and ownership assignments
Evidence collection workflows
Vendor risk management modules
Client Trust functionality (best answers, trust portal, knowledge base)
Build and maintain an audit calendar, evidence repository, and standardized evidence collection playbooks.
Drive development and continuous maintenance of security policies, standards, and procedures.
Operate the Third-Party Risk Management process, including vendor classification (Tier 1/BAA), questionnaire review, residual risk scoring, and contract security review.
Respond to customer security questionnaires, RFPs, and client audit requests with clarity, accuracy, and speed.
Cyber Resilience & SecOps Leadership (25%)
While not a hands-on SecOps role, you will:
Partner with the SecOps Engineers to build daily operational cadence across alerts, incidents, vulnerability management, and hygiene controls.
Ensure controls monitored by Tenable, Microsoft Defender, Sentinel, and other platforms produce audit-ready evidence.
Help design operational dashboards and KPIs for incident response, vulnerability SLAs, and hygiene metrics.
Validate operational controls for compliance frameworks (MFA, SSO, logging, monitoring, access reviews, backups, endpoint security, network protections, etc.).
Application Security Collaboration (15%)
Work with Engineering, Architecture, and DevOps teams to ensure Product and AppSec controls align with SOC 2 and HITRUST expectations.
Contribute to secure SDLC processes, risk assessments for new features, and remediation tracking for vulnerabilities and findings.
Validate that security requirements are integrated into CI/CD workflows where appropriate.
Required Qualifications
7+ years of progressive experience in Information Security, with at least 3+ years in a governance, compliance, or Security Assurance leadership role.
Direct experience implementing or operating Vanta (must be hands-on).
Strong experience supporting and maturing SOC 2 Type II, HIPAA Security Rule, and HITRUST programs in a SaaS environment.
Deep understanding of Microsoft Azure security architecture, including Entra ID, RBAC, Conditional Access, Defender for Cloud, Sentinel, and workload identities.
Clear understanding of audit control design, evidence, and auditor expectations.
Experience building vendor risk programs, reviewing DPAs and BAAs, and performing vendor due diligence.
Excellent writing skills for policies, procedures, client responses, and audit documentation.
Demonstrated ability to lead complex projects with multiple stakeholders and tight deadlines.
Strong communication and relationship-building skills across technical and non-technical teams.
Preferred Qualifications
Experience in healthcare SaaS or other regulated industries.
Hands-on experience with:
Vanta Vendor Risk + Trust Center
Microsoft Purview (DLP, Information Protection)
Azure DevOps or GitHub governance
Tenable, Defender, or other vulnerability platforms
Jira/Confluence
Certifications such as CISA, CISSP, HCISPP, HITRUST CCSFP, or similar.
Experience working with offshore teams.
Benefits:
Generous health, dental, & vision benefits package
Flexible paid time off
11 paid company holidays
401k + matching
Parental leave
Access to our award-winning RethinkCare platform supporting neurodiversity in the workplace through parental success, professional resilience, and personal wellbeing.
Location: Remote opportunities are available to candidates who reside in the following states: AL, AZ, CT, FL, GA, HI, IA, IL, IN, KY, LA, MD, MA, MI, MN, MO, MT, NC, NE, NH, NJ, NV, OH, OR, PA, RI, TN, TX, VA, WA, WI, WY
Our commitment to an inclusive workplace
RethinkFirst is an equal opportunity employer and is committed to providing a workplace free from harassment and discrimination. We celebrate the unique differences of our employees because that is what drives curiosity, innovation, and the success of our business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws. Accommodations are available for applicants with disabilities.
JazzHR Privacy Policy
JazzHR Terms of Use
California Privacy Notice
#remote
Auto-ApplyInformation Security Manager Architect_Deerfield, Illinois
Security architect job in Deerfield, IL
We are seeking an experienced Quality Assurance Analyst to test updates to our client's website and other interactive deliverables. Primary responsibilities include executing test plans, updating test reports, writing bug defects, verifying fixes, and testing pages and emails on supported environments.
Job Description
Interview mode: Phone and Skype (On site interview may be required)
We can submit C2C consultants
JD:
OBJECTIVES:
• Reports to the Head of Security Strategy & Architecture
• Provides leadership and guidance to the regional IT organization on cyber and information security and risk management activities, education, and solutions
• Contributes to defining global security strategy and architecture processes
• Defines and establishes regional security processes based on global security strategy and architecture, with a focus on practices for Vulnerability Management, Systems Development Lifecycle, Information Security Processes including risk based Architecture design.
• Directs a regional approach for the implementation of global IT security standards and methodologies
• Provides input to global security operations such as incident response, monitoring, trend identification, and security posture and remediation
ACCOUNTABILITIES:
• Reports to the Head of Security Strategy & Architecture on plans and status of relevant projects, including the regional security strategy and implementation initiatives
• Contributes to the design, development, and deployment of global security strategy and architecture concepts
• Cooperates with regional teams in understanding global security strategy and architecture requirements
• Conducts periodic review of security-related SDLC processes and stage gates
• Incorporates cyber security and IT risk management into regional activities
• Be the subject matter expert in security and assessments, including vulnerability management processes, vendor security reviews, penetration testing, and application security
• Conducts follow-ups on any identified corrective actions
• Functions as an advisor to system owners, security program managers and others in all matter (technical and otherwise) involving IT security and continuity
• Directs or delegates level 3 support services for the region
• Manages the relationship between IT security and regional business executives and business managers
• Provides recommendations in planning of programs and projects in the area of cyber security
• Reviews and manages budget and reports financial and event status to Head of Security Strategy & Architecture
EDUCATION, BEHAVIOURAL COMPETENCIES AND SKILLS:
Required:
• Bachelor's Degree (business administration, risk management, information security, Management Information Systems (MIS), Computer Science or related IT field) or high school degree
• 7+ years IT experience
• 5+ years of work experience in developing, implementing and managing security solutions
• 3+ years of work experience in designing and architecture security strategy and solutions
• Demonstrated leadership role in working with C-Suite executives and the Board
• Experience with implementing and operating security programs in a global environment, with a focus in Germany and European countries
• Hands-on experience with the development of security strategy and frameworks, architectural methodologies, and service delivery
• Project management experience including full lifecycle implementation
• Proven ability to analyze a wide variety of data and make calculated, risk-based decisions
• Ability to communicate ideas and data both verbally and written in a persuasive and appropriate manner
• Ability to assess strengths and weaknesses of staff members and provide suggestions for improvement
• Ability to write and speak in the English language
Desired:
• In-depth pharmaceutical industry and drug development experience
• Experience with validated systems
LICENSES/CERTIFICATIONS:
• Information security certification (CISSP, CISM, CISA, GIAC, CEH, CCSK)
TRAVEL REQUIREMENTS:
• Access to transportation to attend meetings
• Ability to fly to meetings regionally and globally
• Willingness to travel up to 25-50%.
Location: Deerfield, IL.
Duration: 1 Year+
Additional Information
All your information will be kept confidential according to EEO guidelines. Please call @ ************ Ext 183
Security Systems Engineer - Research & Testing
Security architect job in Chicago, IL
Full-time Description
WHO WE ARE:
At ZBeta we endeavor to be the most sought-after Security Partner in the world. This drives every decision we make, and the most effective way to realize this goal is through garnering a reputation for excellence and innovation in everything we do. The ZBeta Innovation Lab (LabZ) initiative is a specialized team and program with the mission of inventing, developing, testing, and analyzing better ways, both big and small, to do physical security - for us, for our clients, and for the industry. LabZ seeks to optimize the value of physical security to the client's business mission, to optimize the value of the solutions we recommend, design, deliver, and manage, and to continuously identify opportunities to perform at a higher level. The LabZ program helps ensure that ZBeta and its approach are always data-driven, technology-led, and human-centered.
Find out more about us here.
WHO YOU ARE:
You are a forward-thinking strategic partner with a passion for the physical security mission and for building programs, optimizing operations, and delivering integrated solutions. You excel in fast-paced settings where your leadership abilities can catalyze meaningful action and tangible progress towards objectives. You thrive in a workplace culture that is:
Innovative
Excellence Focused
Reliable
Detail Oriented
Adaptable
Highly Organized
Client Obsessed
Curious
Resilient
Does this sound like you? If so, join us in our mission to redefine security standards and make a lasting difference in our community.
WHAT YOU'LL DO:
The Physical Security Research Engineer (PSRE) is a critical resource of the ZBeta LabZ team and will conduct research and proof of concept (PoC) testing at the LabZ facility for clients and internal teams. The PSRE assists in requirements gathering, testing, and report production in the ZBeta LabZ program and leads, develops, manages, and completes key LabZ efforts for the testing and analysis of stand-alone and integrated physical security technology solutions. The PSRE is familiar with security software applications, integrations, and network-connected devices and engages both internally and externally, working collaboratively with other LabZ engineering resources and with project and production team members.
The PSRE will help grow, mature, and optimize the LabZ program by contributing to the tools and processes LabZ uses to effectively evaluate physical security products against real-world design requirements and generate research reports.
This is an in-office position at the ZBeta LabZ location in Schiller Park, IL. Relocation assistance provided.
Core Competencies
Growth Minded: High self-awareness of strengths and areas for development with a curiosity and appetite for change and innovation
Data-Driven: Strong analytical skills, with the ability to work effectively with data and think critically
Collaborative: Ability to solicit and understand multiple perspectives and maximize the application of team talent and experience
Evaluative: Ability to evaluate outputs rigorously to ensure consistent excellence in delivery
Tactical: Ability to recognize current priorities, manage changes and risks, and efficiently clear roadblocks and resolve issues
Position Responsibilities
The essential duties and responsibilities include, but are not limited to the following:
ZBeta Lab Environment
In partnership with ZBeta LabZ team, maintain a ZBeta test/dev environment of technology solutions that represent both client and industry standards.
Work with ZBeta IT to build appropriate server environments and remote access abilities for LabZ platforms.
Load, configure, and update Lab environment software applications, and wire, connect, and configure test hardware, devices, and technologies.
Design and build (or manage the production of) custom testing apparatus, devices, and mechanisms.
Maintain current knowledge of and training in key applications and products.
Solution Testing
Work with ZBeta LabZ team and client resources to plan, implement, and conduct hands-on testing of physical security products, applications and functions, and integrated solutions.
Lead the development of testing concepts to address client and industry needs, challenges, & opportunities.
Manage and execute testing scope related to server, application, and IoT elements.
Create test plans and testing requirement documentation, record and analyze testing results, and document outcomes and conclusions in testing reports.
Research & Requirements Gathering
Conduct studies and analysis of technology categories, trends, solution proposals, and industry approaches.
Research, collect, and analyze relevant documentation and data to reach meaningful conclusions, form opinions of value propositions, generate ideas for solutions and approach improvement, and categorize study topics in terms of potential application and impact to client and industry needs and expectations.
Work with consultants to gather requirements for client proof of concept tests and internal teams for quarterly research projects.
Research Program Development
Assist in the development and ongoing management of process, approach, and standards for the research performed in the ZBeta LabZ program.
Identify opportunities and initiatives for improvements in the efficiency and thoroughness of ZBeta LabZ research deliverables.
Hold regular research update meetings to review, improve, and manage the status of ongoing projects and deliverables.
Requirements
WHAT YOU'LL NEED:
Experience:
5+ years of physical security industry and technology experience. 3+ years of experience in a software or hardware engineering role.
Education:
Bachelor's degree in engineering, computer science, or related technical field, or equivalent work experience
Knowledge:
Knowledge of and working familiarity with server and network storage solutions, operating systems architecture and key considerations, and network architecture models and principles.
Professional knowledge of and training in the principles of electrical systems, components, and circuits.
Skills:
Highly proficient in the use of Microsoft Office applications including Word, Excel, PowerPoint, Teams, OneNote and Visio
Proficiency in project management tools, such as MS Project, SharePoint and QuickBase
Training and manufacturer certification in multiple industry-leading platforms and equipment components, with particular emphasis on software applications and network-connected security devices. Genetec and LenelS2 experience a plus.
Abilities:
Demonstrated excellence in communication and interpersonal skills, with proven ability to communicate and present complex information to technical and non-technical stakeholders, both verbally and in written form
Strong technical documentation, technical writing, and data analysis and interpretation skills
Exceptional attention to detail and highly organized, with the ability to prioritize and balance workloads
Team player with the ability to establish collaborative working relationships across all levels of the organization
Self-directed problem solver who takes the initiative to start projects, work unsupervised, complete tasks independently, solve roadblocks, and address issues before they become problems
Physical Demands:
Lifting and Carrying: Ability to lift and carry equipment weighing up to 50 lbs or more, including cameras, control panels, and tools.
Climbing and Crawling: Must be able to climb ladders, scaffolding, and operate a high lift to install and maintain equipment
Manual Dexterity: Requires good hand-eye coordination and fine motor skills for handling tools, wiring components, and making precise adjustments to security systems
Kneeling, Squatting, and Crawling: Must be comfortable kneeling, squatting, or crawling to install or troubleshoot security equipment.
WHAT WE OFFER:
Competitive salary based on job-related skills, experience, and qualifications
Our excellent benefits package includes 100% paid premiums on health, dental, vision, and life insurance, a 401(k) retirement plan, and significant work schedule and workplace flexibility.
Diverse and supportive culture
WHAT'S IMPORTANT TO KNOW:
Full-time, in-office role at our Schiller Park, IL LabZ facility (relocation assistance provided). While ZBeta is a remote-first company, this role requires hands-on, on-site lab work.
This position is not eligible for visa sponsorship
Candidates must be able to meet client and/or government security screening requirements for the role
This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. As a condition of employment, the successful candidate will be required to provide proof of citizenship.
The successful completion of a background check is required upon hire and every two years thereafter
We look forward to connecting with individuals who are passionate about our mission and can bring diverse contributions to our team - not just those who check all the boxes.
We are committed to creating a supportive, encouraging environment where everyone can fully express their diverse perspectives, showcase their talents, and grow their knowledge, skills, and abilities.
The base pay offered will depend on factors, including but not limited to job-related knowledge, skills, experience, and internal equity. At ZBeta, new hires are rarely placed at the top of the pay range; compensation is determined by the specific circumstances of each position and candidate.
A note to third-party recruiters - we do not accept unsolicited agency resumes, and we are not responsible for any fees related to unsolicited resumes.
Salary Description $110,000 - $130,000
Data and System Security Engineer
Security architect job in Lincolnshire, IL
AYR Global IT Solutions is a national staffing firm focused on cloud, cyber security, web application services, ERP, and BI implementations by providing proven and experienced consultants to our clients. Our competitive, transparent pricing
model and industry experience make us a top choice of Global System
Integrators and enterprise customers with federal and commercial
projects supported nationwide.
Job Role: Data and System Security Engineer
Location: Lincolnshire, IL
Duration: 6+ Months
Qualifications
Job Description:
Data and System Security engineer
Experience with data encryption management solutions, such as Vormteric and CloudLink
Experience with PKI management solutions, such as ADCS and External providers
Investigative and analytical problem solving skills
Customer service/support experience
Additional Skills:PKI
Knowledge of encryption management technologies, such as Vormetric, CloudLink.
Additional Information
If anyone might be intersted please send resumes to kmarsh@ayrglobal (dot) com or you can reach me direct at **************
Security & Fire Systems Engineer III
Security architect job in Calumet City, IL
Build your best future with the Johnson Controls team
As a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe. You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience, focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard - your next great opportunity is just a few clicks away!
What we offer
Paid vacation/holidays/sick time - 15 days of vacation first year
Comprehensive benefits package including 401K, medical, dental, and vision care - Available day one
Extensive product and on the job/cross training opportunities with outstanding resources
Encouraging and collaborative team environment
Dedication to safety through our Zero Harm policy
Check us Out: A Day in a Life at Johnson Controls:
What you will do
Under specific direction, assists in the design, configuration, and operation of building systems including security, fire, and other low voltage control sub-systems (i.e. lighting, nurse call, data networks, etc.) to meet the intent of the project requirements. Assists in the development of software programs, commissioning and troubleshooting to ensure proper operations of the building control system. Provides detailed information and submittals to communicate design and operation to customers, consultants, Johnson Controls field installation team and subcontractors.
How you will do it
Design and configure technically complex Security & Fire systems as defined by the contract documents. Create flow diagrams, sequence of operations and bill of material, network layouts and electrical schematics as required.
Develop and test software programs necessary to operate the system per the intent of the project requirements.
Use your ability to integrate different Security subsystems with each other.
Coordinate and create the necessary drawings and equipment schedules for submittals and installation.
Select, order, and track the delivery of materials for assigned projects.
Coordinate factory-mounting processes to meet factory and project schedule.
Assist in the loading and commissioning of all system and network-level controllers as required. Assist in validation of complete system functionality and troubleshoot problems with subcontractors and other trades to ensure proper operation.
Provide field change information to the project team for the creation of as-built drawings and software.
Keep management and JCI contractor or customer informed of job progress and issues. Assist in performing site-specific training for owner / operator on the total building control system.
Participate in release meeting with project field team. Perform value engineering to provide cost effective results while maintaining customer satisfaction.
Adhere to safety standards. Operate with a high degree of regard to employee and subcontractor safety.
What we look for:
Required
Experience in setting up application deployment (Installation, Configuration, Integration with other components) on Cloud environment based on underlying Application Architecture
Experience in Disaster Recovery setup
Administration, Maintenance and support of the Application instances on Reference, Validation and Customer environments
Identify any known incident resolutions using a knowledge management system
Apply identified resolutions to the incident and interact with the customer to ensure the incident has been properly resolved
Antivirus - Symantec (Installation, updates and remediation's of antivirus client for servers and computers
Off-shift support for machine moves quarterly maintenance
Deployment of physical and virtual server deployment, troubleshooting and maintenance
Ability to learn security software programs (I.E. C-cure9000, Milestone, Genetec)
Strong technical skills in the domain of Windows Server 2008/2012, Microsoft Hyper-V and SCCM/SCOM/SCVMM is essential
Basic MS SQL database and scripting skills is an asset Basic MS SQL database and scripting skills is an asset
HIRING SALARY RANGE: $85,000 - $106,000 Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, location and alignment with market data.) This role offers a competitive Bonus plan that will take into account individual, group, and corporate performance. This position includes a competitive benefits package. For details, please visit the About Us tab on the Johnson Controls Careers site at *****************************************
#LI - AD2
#LI - DS1
Johnson Controls International plc. is an equal employment opportunity and affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, sexual orientation, gender identity, status as a qualified individual with a disability or any other characteristic protected by law. To view more information about your equal opportunity and non-discrimination rights as a candidate, visit EEO is the Law. If you are an individual with a disability and you require an accommodation during the application process, please visit here.
Auto-ApplyPAM/HashiCorp Security Engineer
Security architect job in Chicago, IL
***Hybrid, 3 days onsite, 2 days remote***
***We are unable to sponsor as this is a permanent full-time role***
Responsibilities:
Provide 24x7 operational support for the suite of privileged management solutions (e.g., CyberArk, Hashi, PKI), including implementing hot fixes, resolving bugs, troubleshooting issues, performing break-fixes, managing secrets lifecycle, and delivering end-user support.
Maintain robust operational integrity of privileged access management infrastructure throughout its lifecycle (e.g., patching, version control, system upgrades, alignment with Security standards, etc.). Provide organizational subject matter expert on secrets management and privileged access management architecture, establishing and enforcing security as code principles throughout the environment.
Develop and implement system enhancements to improve platform user experience and automated integrations, while designing long-term solutions to address operational issues through innovative technologies including artificial intelligence for faster detection and remediation of functional and technical problems.
Qualifications:
Experience in one or more of the following disciplines: security operations, development, engineering, or architecture
Experience supporting privileged access management and access controls programs.
Professional or personal experience using AI coding agents such as OpenAI Codex, Claude Code, or Gemini CLI.
Expertise in providing operational and engineering support for one or more of the following: CyberArk, HashiCorp Vault, Active Directory Certificate Services (ADCS), HSMs, and Public Key Infrastructure (PKI).
Expertise in scripting languages and developing in one or more of the following languages GoLang, Bash, Python, PowerShell, Ansible, and/or Terraform.
Knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation.
Knowledge of application authentication and authorization systems (i.e., Active Directory, oAuth 2.0, OIDC, AWS IAM, App Role, k8s, LDAPS, Kerberos, Certificate)
Working knowledge of the cloud ecosystem and CI/CD deployments with Terraform, Ansible, and Jenkins pipelines.