Security Engineer
Security engineer job in Chicago, IL
About Us
Founded in 2014, we offer the industry's first and only cloud-based, fully-customizable, end-to-end software solution to automate securities-based lending from origination through the life of the loan. By combining thought leadership in suitability and risk management with industry-leading education and the latest technology, Supernova enables advisors to deliver holistic, goals-based advice and to help their clients achieve financial wellness. We partner with the industry's largest banks, most prominent insurance companies and leading online brokerages to democratize access to securities-based lending and better the entire financial ecosystem.
Why Join Supernova?
At Supernova Technology, we believe that the best results come from a team that is passionate, driven, and supported in all aspects of their professional lives. Here, you'll work alongside talented and innovative individuals who are committed to driving the future of securities-based lending technology. We foster a culture of collaboration, continuous learning, and growth, where each person's contributions make a real impact.
Job Overview
We are seeking a highly motivated and detail-oriented Security Engineer to help secure our securities-backed lending SaaS platform. The successful candidate will focus primarily on application security, secure SDLC, and application vulnerability management, while also assisting with the execution and implementation of broader information security initiatives. You'll partner with engineering, SRE/DevOps, and business teams to embed security into our build and delivery processes, support risk reduction across cloud and endpoint surfaces, and drive measurable remediation outcomes in a regulated financial-services environment.
RESPONSIBILITIES:
Perform hands-on web/API penetration tests, validate scanner findings, and provide clear PoCs, impact statements, and prioritized remediation aligned with OWASP.
Integrate and tune SAST, DAST, SCA, container, and secret-detection tools in CI/CD; define pass/fail gates and PR checklists.
Conduct lightweight threat modeling and security design reviews for new features such as authentication, session management, and secrets handling.
Manage the full application vulnerability lifecycle (discover → prioritize → fix → retest → close) with SLAs and metrics.
Assist in hardening AWS and ECS/Docker workloads (IAM roles, network segmentation, image policies, logging/monitoring) and support patch hygiene across cloud, container, and endpoints.
Participate in incident response, including exploit reproduction, log analysis, impact assessment, and lessons learned.
Provide evidence for audits (ISO 27001, SOC 2, NIST SSDF), maintain policies and developer guidance, and support vendor/security evaluations.
Translate findings into developer-ready tickets, publish secure-coding guidance, and partner with engineering to streamline secure delivery.
Prototype automation, explore AI/LLM-assisted workflows to improve triage and code review, and share improvements across teams.
Contribute to organization-wide cybersecurity training and awareness efforts.
QUALIFICATIONS:
Bachelor's degree in security engineering, information assurance, or related field.
2-3 years of experience in security or software engineering (internships, labs, or open-source count), preferably in regulated industries.
Strong knowledge of web/API security issues (auth, session management, injections, SSRF, CSRF, access control) and common cloud/web misconfigurations.
Experience with SDLC security tools (SAST/DAST/SCA/secret detection/container scanning), CI/CD workflows, and Git.
Scripting or coding skills (Python or JavaScript/TypeScript) and ability to read backend code.
Familiarity with AWS security basics (IAM least privilege, KMS, logging/monitoring, security groups) and Docker/ECS runtime considerations.
Clear communication skills with the ability to translate risk into actionable remediation.
Experience using AI/LLM-assisted tools for triage, documentation, or code review preferred.
Exposure to WAF/CDN tuning, API protection, and risk-based remediation SLAs/metrics preferred.
Familiarity with frameworks like OWASP ASVS/SAMM, NIST SSDF, ISO 27001, SOC 2, PCI DSS preferred.
Relevant security certifications preferred.
Our Employee Benefits
At Supernova Technology, we provide a robust benefits package to support the health and well-being of our employees. Our offerings include:
Medical, Dental, and Vision Insurance: Multiple plans with coverage for employees and dependents.
HSA and FSA Accounts: Tax-advantaged accounts for health and dependent care expenses.
Life and Disability Insurance: Employer-paid basic coverage with options for additional voluntary coverage.
Compensation: $95,000 - $130,000
Retirement Savings: 401(k) plan with employer contributions.
Employee Assistance Program (EAP): Confidential support services, including free therapy sessions.
Paid Time Off: Flexible PTO policies.
Additional Perks: Commuter benefits, pet insurance, continuing education assistance, and more.
Note: Actual salary at the time of hire may vary and may be above or below the range based on various factors, including but not limited to, the candidate's relevant qualifications, skills and experience, and the location where this position may be filled.
Our Core Values
Our core values drive everything we do. At Supernova, we...
Form, execute, and communicate new ideas that add value to our employees and customers
Strive through obstacles and failures
Follow-through on promises or commitments to others, accept responsibility, and answer for actions & decisions
Listen to, understand, and support our employees and customers
Act with speed, positive attitude, and flexibility
Exceed expectations and surpass ourselves every day; we embrace a sense of pride and never stop growing
Join us and make an impact while growing your career at Supernova.
Information Security Engineer - Applications
Security engineer job in Oak Brook, IL
In this role, you will work closely with IT teams to secure our applications throughout the development lifecycle. You'll help build a secure-by-design culture, drive security automation, and protect our systems against evolving threats. This position reports to the Manager of Information Security.
ESSENTIAL JOB FUNCTIONS:
Work with the Information Security Team to improve security for the company by configuring and administering security systems and tools
Monitor and respond to security events using SIEM and SOAR tools
Investigate security incidents to determine root cause and remediation tactics
Help automate security monitoring and remediation processes
Prepare and analyze security incident data and metrics for periodic reporting
Collaborate on vulnerability management, remediation, and penetration testing efforts
Implement and manage SAST, DAST, and Burp Suite across GitHub CI/CD pipelines and development workflows
Champion secure coding practices based on OWASP Top 10 and SSDF guidelines
Help secure cloud environments (Azure, AWS) and container-based deployments
Conduct regular security assessments to ensure alignment with SSDLC standards
After-hours configuration changes and on-call support required
MINIMUM QUALIFICATIONS:
Bachelor's degree in Computer Science, Information Systems (or related degree), or equivalent experience.
3+ years of experience in Application or Information Security
Strong understanding of SSDLC, NIST SSDF, and DevSecOps principles.
Experience with SAST/DAST tools (e.g., GitHub Advanced Security, BURP).
Solid knowledge of OWASP Top 10 and secure coding best practices.
Proficiency in GitHub for code review, pipeline security, and automation.
Hands-on with scripting (Python, PowerShell, Bash) and API security.
Experience in Azure and AWS cloud security, containers, and infrastructure-as-code.
Familiarity with SIEM/SOAR platforms and incident response workflows.
Experience with Windows, MacOS, and Linux operating systems
Proficient in Microsoft Office applications such as Microsoft Outlook, Word, Excel, PowerPoint, and SharePoint
** This is a full-time, W2 position with Hub Group - We are NOT able to provide sponsorship at this time **
Salary:
$95,000-150,000/year
+ bonus eligibility
**
This is an estimated range based on the circumstances at the time of posting, however, may change based on a combination of factors, including but not limited to skills, experience, education, market factors, geographical location, budget, and demand**
Benefits
We offer a comprehensive benefits plan including:
Medical
Dental
Vision
Flexible Spending Account (FSA)
Employee Assistance Program (EAP)
Life & AD&D Insurance
Disability
Paid Time Off
Paid Holidays
BEWARE OF FRAUD!
Hub Group has become aware of online recruiting related scams in which individuals who are not affiliated with or authorized by Hub Group are using Hub Group's name in fraudulent emails, job postings, or social media messages. In light of these scams, please bear the following in mind
Hub Group will never solicit money or credit card information in connection with a Hub Group job application.
Hub Group does not communicate with candidates via online chatrooms such as Signal or Discord using email accounts such as Gmail or Hotmail.
Hub Group job postings are posted on our career site: ********************************
About Us
Hub Group is the premier, customer-centric supply chain company offering comprehensive transportation and logistics management solutions. Keeping our customers' needs in focus, Hub Group designs, continually optimizes and applies industry-leading technology to our customers' supply chains for better service, greater efficiency and total visibility. As an award-winning, publicly traded company (NASDAQ: HUBG) with $4 billion in revenue, our 6,000 employees and drivers across the globe are always in pursuit of "The Way Ahead" - a commitment to service, integrity and innovation. We believe the way you do something is just as important as what you do. For more information, visit ****************
PAM/HashiCorp Security Engineer
Security engineer job in Chicago, IL
***Hybrid, 3 days onsite, 2 days remote***
***We are unable to sponsor as this is a permanent full-time role***
Responsibilities:
Provide 24x7 operational support for the suite of privileged management solutions (e.g., CyberArk, Hashi, PKI), including implementing hot fixes, resolving bugs, troubleshooting issues, performing break-fixes, managing secrets lifecycle, and delivering end-user support.
Maintain robust operational integrity of privileged access management infrastructure throughout its lifecycle (e.g., patching, version control, system upgrades, alignment with Security standards, etc.). Provide organizational subject matter expert on secrets management and privileged access management architecture, establishing and enforcing security as code principles throughout the environment.
Develop and implement system enhancements to improve platform user experience and automated integrations, while designing long-term solutions to address operational issues through innovative technologies including artificial intelligence for faster detection and remediation of functional and technical problems.
Qualifications:
Experience in one or more of the following disciplines: security operations, development, engineering, or architecture
Experience supporting privileged access management and access controls programs.
Professional or personal experience using AI coding agents such as OpenAI Codex, Claude Code, or Gemini CLI.
Expertise in providing operational and engineering support for one or more of the following: CyberArk, HashiCorp Vault, Active Directory Certificate Services (ADCS), HSMs, and Public Key Infrastructure (PKI).
Expertise in scripting languages and developing in one or more of the following languages GoLang, Bash, Python, PowerShell, Ansible, and/or Terraform.
Knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation.
Knowledge of application authentication and authorization systems (i.e., Active Directory, oAuth 2.0, OIDC, AWS IAM, App Role, k8s, LDAPS, Kerberos, Certificate)
Working knowledge of the cloud ecosystem and CI/CD deployments with Terraform, Ansible, and Jenkins pipelines.
Sr. Information Security Engineer - AI
Security engineer job in Rosemont, IL
Job Title: Senior Information Security Engineer - AI
Primary Location: Rosemont, IL - Hybrid, 3 days onsite
Direct Hire
TalentFish is casting a line for a Senior Information Security Engineer - AI/Artificial Intelligence. This is a Direct Hire role based in Rosemont, IL with a hybrid schedule (3 days onsite) with our premier client.
This is a new, exciting position within an awarded top Chicago employer organization where you'll contribute to the organization's Responsible Artificial Intelligence governance by assessing the security, integrity, and risks associated with the use of AI models and technologies. This role is hands-on and works closely with multi-disciplinary teams to evaluate AI use cases and maintain AI security frameworks and standards.
What You Bring to the Role (Ideal Experience)
• Bachelor's degree in Computer Science, Mathematics, or related field
• 5+ years of total professional experience, including security, data security, or control validation experience
• 2-3 years of practical, hands-on experience working with Artificial Intelligence technologies; working directly with AI models or ML systems
• Ability to evaluate AI model risks, including bias, data exposure, data leakage, and model poisoning
• Data processing or analytics skills are a plus
What You'll Do (Skills Used in This Position)
• Lead security assessments for AI models, including Large Language Models (LLMs), Natural Language Models (NLMs), and Small Language Models (SLMs)
• Participate in review committees to assess AI use cases for value, complexity, feasibility, risk, compliance, and strategic alignment
• Review AI architecture and usage within internal and third-party solutions to ensure adherence to AI security frameworks and regulatory requirements
• Support development and maintenance of AI security standards, frameworks, and governance models
• Provide education on AI security best practices, emerging risks, and mitigation strategies
• Perform additional related responsibilities as required
Compensation Information
The expected salary range for this position is $120,000 - $150,000 per year, depending on experience and qualifications. This role also qualifies for comprehensive benefits such as health insurance, 401(k), and paid time off. TalentFish is committed to pay transparency and equal opportunity. The salary range provided is in compliance with applicable state and federal regulations.
This role requires authorization to work in the U.S. without current or future visa sponsorship.
All offers are contingent upon the completion of a background check, which may include but is not limited to reference checks, education verification, employment verification, drug testing, criminal records checks, and any required certifications or compliance requirements based on the end client's background check policies and applicable laws.
TalentFish is an employee-owned company pioneering a new realm in talent acquisition. We are redefining IT staffing by evolving AI, video screening, and our unique platform. TalentFish focuses on providing the best employee, consultant, and client experience possible.
At TalentFish we are an Equal Opportunity Employer; we embrace and encourage diversity!
Sr. Security Engineer - Red Team
Security engineer job in Chicago, IL
About the Company:
A Leading Financial Service Client is looking to hire a strong Security Engineer who can lead Red team exercises against a hybrid environment using threat intelligence and the MITRE Telecommunication&CK Framework.
Responsibilities:
Approx 8 years' experience with industry standard Red Team testing tools (Cobalt Strike, Mythic C2, Rubeus, Bloodhound, Covenant, etc.) or the ability to demonstrate equivalent knowledge.
Expert understanding of how an Advanced Persistent Threat could compromise a financial institution without using phishing.
Expert understanding of Red Team concepts, tools, and automation strategies.
Expert understanding of MITRE Telecommunication&CK framework tactics, techniques, and procedures.
Expert understanding of measuring and rating vulnerabilities based on principal characteristics of a vulnerability.
Expert understanding of Windows and Linux system hardening concepts and techniques.
Network Security Engineer
Security engineer job in Mount Prospect, IL
Seeking a Senior Network Security Engineer to spearhead a major network infrastructure standardization and security initiative. This is a unique opportunity for a highly autonomous and experienced engineer to own and redefine the network strategy for a multi-site enterprise. The ideal candidate will leverage their deep technical expertise in firewalls, hybrid cloud networking, and security to drive significant, long-term operational improvements.
Key Responsibilities
Network Standardization: Lead a year-long project to evaluate, clean up, and standardize all network architecture, including IP subnetting and VLAN configurations, across multiple physical locations.
Security and Monitoring: Manage day-to-day firewall maintenance, review security logs, and implement a Security Information and Event Management (SIEM) solution to visualize and secure internal (east/west) network traffic.
Infrastructure Management: Oversee the migration to and maintenance of Cisco network devices and manage the operation of the hybrid cloud environment, including connectivity like ExpressRoutes to the cloud platform.
Required Qualifications
Proven hands-on experience with Palo Alto firewall administration and maintenance.
Expertise in managing a hybrid network environment with strong cloud service (e.g., Azure/EntraID) integration.
Demonstrable competency in core networking concepts, including VLANs and IP subnetting.
Familiarity with network device patching, security hardening, and leveraging SIEM tools for security monitoring.
Demonstrated ability to function as a highly independent, senior resource capable of self-managing large-scale, strategic projects.
This is a pivotal role for a security-minded Network Engineer to design, secure, and fully own the network infrastructure for a growing company.
#11273
Information Security Officer
Security engineer job in Chicago, IL
Job Title:
Business Information Security Officer - Clinical
Employment Type:
Full-Time
Salary Range:
$130,000 - $140,000 + Benefits (Health, Dental, Vision, PTO, 401K)
About the Role:
We're seeking a Business Information Security Officer (BISO) to serve as a trusted advisor and strategic partner to business and clinical leaders. In this highly visible role, you'll embed cybersecurity into everyday operations, influence security adoption, and ensure compliance with frameworks like NIST, HIPAA, and FERPA.
This is an opportunity to shape cybersecurity strategy in healthcare, research, and education while collaborating with executive leadership to advance a security-first culture.
Key Responsibilities:
Act as the frontline cybersecurity liaison for business and clinical leaders
Identify and escalate domain-specific cybersecurity risks
Monitor compliance with security policies and regulatory frameworks (HIPAA, FERPA, NIST CSF)
Lead security awareness and risk engagement programs
Develop and execute a roadmap of security initiatives aligned with business goals
Drive change management for cybersecurity adoption
What We're Looking For:
Bachelor's degree in Computer Science or related field
5-7 years in Information Security, GRC, or cybersecurity education
3+ years managing cross-functional teams and projects
Strong background in risk management, governance, and compliance
Excellent communication and leadership skills
Preferred:
Healthcare or clinical environment experience
Certifications: CISSP, CISM, PMP
Network Systems Engineer
Security engineer job in Chicago, IL
Links Technology is seeking a driven and skilled Network Systems Engineer to join our client's team in Chicago, IL. Our client is the industry leader in data-driven, client-to-cloud networking for large data center, campus and routing environments. They leverage the latest advancements in cloud computing, artificial intelligence, and software-defined networking to provide their clients with a competitive edge in an increasingly interconnected world.
Responsibilities of the Network Systems Engineer:
The Pre-Sales Systems Engineer has the key responsibility of acting as a trusted advisor for our clients customers and partners to gather requirements and identify opportunities with existing and new customers.
Own the pre and post-sales technical relationship with the assigned territory and customer base.
Build and maintain a deep, sound knowledge of all our client's technologies, in order to support and help in the enablement of strategic customers.
Facilitate technical training on our client's products, differentiators, solutions, and demos.
Engage with key partners to develop proficiencies in delivering services around Our client's solution set.
Participate in the execution of Proof of Concepts (POCs) and on-site customer testing.
Execute technical Quarterly Business Reviews with customer base.
Support onsite requirements at the customer site.
Respond to inbound questions from the customers including research and lab testing of solutions.
Present technical content to worldwide organizations both virtually and in-person.
Create technical marketing materials for the global Arista organization.
Travel expectations is approximately 10%.
Qualifications of the Network Systems Engineer:
Minimum of 5 years of networking design and implementation experience with a focus on Data Center, Campus, WI-FI and Security solutions working with Financial Services customers.
Strong presentation and selling skills including communication of complex technical material.
Solid understanding and knowledge of how to build successful relationships between an equipment manufacturer and a customer base of executives, architects, engineers and operations teams.
Good interpersonal skills, customer relations skills, and problem management skills, with the ability to stay calm and professional under pressure while working to strict deadlines.
Experience creating technical material (slides, white papers, battle cards, solution guides, etc).
Solid knowledge of competitive products, solutions, and services.
Experience with Network Overlay and Virtualization is highly desired.
Previous experience building network automation using Python and Ansible desired.
Network Industry Certification including Arista Cloud Engineer (ACE) level 3-5 desired.
Benefits of the Network Systems Engineer:
10 Days PTO
Health, Dental, and Vision Insurance
Matching 401k
Direct hire opportunity!
Hybrid role in Chicago, IL
Salary Range: $112k - $160k
Network Engineer
Security engineer job in Chicago, IL
This role is responsible for designing, planning, implementing, maintaining, and supporting network infrastructures, including local area networks (LANs), wide area networks (WANs), and intranets in order to support and protect the business operations and growth of Tootsie Roll Industries.
This role will manage the network architecture and this person will need knowledge and experience in routing, switching, and security. This role requires deep expertise in networking technologies, protocols, and infrastructure, as well as strong problem-solving and analytical skills. The network engineer collaborates closely with cross-functional teams to assess requirements, troubleshoot issues, and optimize network performance.
This role plays a critical part in implementing and maintaining network security measures such as firewalls, intrusion detection systems, and virtual private networks (VPNs). The network engineer also ensures that networks are safeguarded against potential threats. They perform continuous monitoring of the network performance to ensure optimal functionality.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
Provides direct support in the day-to-day operations on network hardware and operating systems; duties include evaluation of system utilization, monitoring response time, and primary support for detection and correction of operational problems.
Perform administration, configuration, maintenance, and support of all network equipment, including but not limited to firewalls, routers, switches, and wireless access points.
Participates in the design, technical review, and implementation for network infrastructure hardware and network operating systems for voice and data communication networks.
Analyze network traffic and predict growth to determine future needs.
Ensure the TRI network has the proper security in place and that the latest cybersecurity measures are in place.
Staying up to date on the latest technologies to determine the best options for TRI.
Design solutions with other teams to support new or updated applications and/or technologies.
Monitor cloud and datacenter traffic for network outages, performance issues, and security vulnerabilities.
Perform and document routine adds, moves, or changes to voice and data networks.
Analyze, resolve, and document network, hardware, software problems as well as incidents escalated from service desk tickets.
Other duties as assigned.
Requirements and Skills:
Bachelor's degree in computer science, information technology, or a related field. Master's degree preferred.
Proven experience in network architecture, design, implementation, and support.
In-depth knowledge of networking protocols, including TCP/IP, DNS, DHCP, VLANs, VPNs, and routing protocols.
Strong understanding of network security principles and best practices, including firewalls, intrusion detection/prevention systems, VPNs, and encryption technologies.
Proven ability to configure and manage networking equipment, including routers, switches, firewalls, VPNs, and voice.
Strong problem-solving and analytical skills for diagnosing and resolving complex network issues.
Experience working on network-related projects, demonstrating leadership in system upgrades, migrations, and implementations.
Excellence in communication and teamwork is a must.
Network Engineer
Security engineer job in Downers Grove, IL
Our client operates worldwide and stands at the forefront of developing innovative solutions for the government, municipal, and industrial industries. They provide everything from state-of-the-art emergency vehicles to effective street sweepers, significantly improving our daily experiences and the cleanliness of our cities. Focused on advanced public safety and communication systems, they guarantee the swift delivery of essential alerts to the appropriate parties.
The Network Engineer will be responsible for maintaining and administering our company's computer Wide Area and Local networks. Primary duties will include maintenance of computer networks, hardware, software, and other related systems, performing disaster recovery operations, protecting data, software, and hardware from attacks, and replacing faulty network hardware components when necessary. They will also be working closely with the users of our network to identify potential issues and resolve existing problems.
Candidates will need to have a strong understanding of network infrastructure and network hardware. Will also need to be able to implement, administer, and troubleshoot network devices including WAPs, firewalls, routers, switches, and controllers. A deep knowledge of application transport and network infrastructure protocols is highly desired.
Position Summary
Maintaining and administering computer networks and related computing environments including systems software, applications software, hardware, and configurations.
Performing disaster recovery operations and data backups when required.
Protecting data, software, and hardware by coordinating, planning and implementing network security measures.
Troubleshooting, diagnosing and resolving hardware, software, and other network and system problems.
Replacing faulty network hardware components when required.
Maintaining, configuring, and monitoring virus protection software and email applications.
Monitoring network performance to determine if adjustments need to be made.
Conferring with network users about solving existing system problems.
Operating master consoles to monitor the performance of networks and computer systems.
Coordinating computer network access and use.
Designing, configuring, and testing networking software, computer hardware, and operating system software.
Some Travel required.
Lead/Manage Network team.
Minimum Experience
Bachelor's degree in information technology or equivalent experience in a related field with a network engineering focus.
Strong understanding of network infrastructure and network hardware.
Ability to think through problems and visualize solutions.
Ability to implement, administer, and troubleshoot network infrastructure devices, including wireless access points, firewall, routers, switches, controllers.
Knowledge of application transport and network infrastructure protocols.
Ability to create accurate network diagrams and documentation for design and planning network communication systems.
Provides specific detailed information for hardware and software selection.
Ability to quickly learn new or unfamiliar technology and products using documentation and internet resources.
Ability to work with all levels of staff within and outside of IT and outside the organization.
A self-starter able to work independently but comfortable working in a team environment.
Good analytical and problem-solving skills.
Dependable and flexible when necessary.
Network security experience.
LAN and WAN experience.
Comp
$115,000 - $130,000
MMD Services Inc. is an equal opportunity employer. All applicants are considered for all positions without regard to race, religion, color, sex, gender, sexual orientation, pregnancy, age, national origin, ancestry, physical/mental disability, medical condition, military/veteran status, genetic information, marital status, ethnicity, alienage, or any other protected classification, in accordance with applicable federal, state, and local laws.
Senior Manager, Information Security Office (ISO) Consultant
Security engineer job in Chicago, IL
Senior Manager, Information Security Office (ISO) Consultant At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
The Senior Lead ISO Consultant will provide cyber security architecture advisory support needed to build the Technology & Business capabilities on a novel Modern platform, that will enable customer set-up, use, and management of a Capital One Credit Card, including Data Product. In this role, the responsibilities will include:
Act as a central Information Security point of contact for the Global Payment Networks line of business
Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's Information Security capabilities, solutions, policies, procedures and standards
Collaborating with enterprise cyber teams and tech architects in defining and driving the cyber architecture strategy and guiding principles for the architecting and designing of the modern platforms.
Support security architecture and implementation needs for technology modernization efforts
Overseeing all cyber related dependencies across the multiple components being built for the modernization effort.
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad-hoc support on special Information Security hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
Support the team on collectively mapping technologies to a standardized framework in order to identify and execute on best practices in risk reduction through the configuration of cybersecurity tools and platforms.
Support the development, modification, and use of capability, risk, or threat classification frameworks and standardization methodologies to facilitate the conduct of correlative capability, maturity, and effectiveness evaluations.
Support data validation and communications on the impact of identified operational, compliance, process, control, and tooling gaps and potential remediation courses of action to multiple audiences, including leadership, to support the enhancement of their cybersecurity postures.
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
At least 4 years of experience with cloud security
Preferred Qualifications:
Bachelor's Degree
7+ years of experience in securing a public cloud environment (AWS, GCP, Azure)
6+ years of cyber security advisory and technology consulting experience
6+ years of experience in Cyber Risk Management
3+ years of experience on cryptography, HSMs and similar systems
Knowledge of HPNS, ATM, Mainframe technologies and other payment networks infrastructure technologies
Experience in security integration for Mergers and Acquisitions
Experience with PCI and Payment Network Compliance.
Professional certifications AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $204,900 - $233,800 for Sr Manager, Cyber Technical
McLean, VA: $225,400 - $257,200 for Sr Manager, Cyber Technical
New York, NY: $245,900 - $280,600 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections ; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
Network Engineer
Security engineer job in Schaumburg, IL
As a key member of the network engineering team, you will have strong experience with routing and switching in an ISP setting, including SD-WAN, network monitoring, infrastructure, as well as general network troubleshooting skills. This position is a hybrid with onsite presence required in our Schaumburg, IL office.
Responsibilities:
Work directly with customers to design, implement, and operate solutions that are resilient, high-performing, and maintainable.
Ensure accuracy of backend systems and documentation.
Perform root cause analysis and determine corrective actions.
Design, provision, maintain, and troubleshoot services for clients including SD-WAN, SASE, MPLS, DIA, SIP, and UCaaS.
Assist with infrastructure design, maintenance, and operation, including SNMP, Netflow, Syslog, Prometheus, Grafana, Solarwinds, Netscout, Netbox, and Veeam. Part of your role will be to support Coeo's network and infrastructure in addition to customer networks.
Participate in trouble ticket resolution and troubleshoot advanced issues escalated from Tier 1 support.
May require some travel.
Qualifications:
Experience working on ISP data networks at all layers or experience working at an MSP with a wide range of technologies.
Experience troubleshooting at the packet layer, capturing, and analyzing traffic, and working with Wireshark.
Experience with layer three routing protocols in an ISP environment. (e.g. IS-IS, OSPF, BGP and BGP traffic engineering).
Understanding of metro ethernet design including EVCs, UNIs, and NNIs.
Understanding of network design and deployment of routers and switches, e.g. Juniper, Cisco, ALU, Ciena, Fortinet, Mikrotik, etc.
Experience with SD-WAN and SSE technologies, deployment, and use-case evaluation (i.e., Versa, Broadcom/VeloCloud, Client/Silver Peak).
Understanding of resiliency and redundancy in network design, protocols involved, and hardware options for high availability
Vendor certifications a plus, Cisco, Juniper, Palo Alto, Fortinet, etc.
Excellent communications skills.
Desire to take on new opportunities and work independently.
Ability to work effectively as part of the Network team.
Strong desire to learn and demonstrated commitment to professional development.
Prior experience with any of the following would be a plus:
Firewall configuration and management.
Scripting and automation in PowerShell, Python, Go, etc.
Voice network architecture, Clients, hosted PBX, SIP Phones, ATAs.
Windows and Linux server administration.
Azure, GCP, or AWS cloud configuration and management.
Virtualization management experience with VMware, KVM, OpenStack, Docker, Kubernetes, or others.
Systems Engineer
Security engineer job in Chicago, IL
Chicago-based financial technology firm, is seeking a Systems Engineer to maintain and enhance the environment for a variety of innovative trading, market risk, and broker systems used by clients worldwide. The candidate is expected to be a highly motivated individual who will be responsible for collaborating with a top-notch team of technologists in growing a world-class organization. The position reports to the VP of Hardware and Infrastructure.
Primary Responsibilities:
Manage, support, and troubleshoot data storage, servers, and other virtual computing platforms including Microsoft Cluster Manager, Microsoft Hyper-V, Red Hat OpenShift.
Install hypervisors and operating systems in support of infrastructure to include patching, updating releases, firmware, and BIOS updates.
Serve as a subject matter expert for virtualization, automation, and orchestration platforms.
Manage server stability, security, performance, and capacity.
Adapt, Improve, Develop, execute, and troubleshoot Windows provisioning scripts that utilize multiple languages/scripting technologies to streamline deployment.
Develop, execute, and troubleshoot Windows provisioning scripts that utilize multiple languages/scripting technologies.
Perform root cause analysis for supported environments.
Prioritize multiple work streams simultaneously and meet deadlines.
Deploy, maintain, and troubleshoot multiple virtualized environments (DevTest, Stage, Production).
Develop plans for the future strategy of server/serverless, container services, storage, and platforms. Provide budgetary information as needed.
Job Requirements:
• Achieved or working towards MCSA/MCSE of advanced Windows Server/Active Directory Certification.
• 5+ years' experience supporting Hyper-V virtualization platform including cluster implementation and automated fail-over.
• Must be a creative problem solver with excellent trouble-shooting skills; flexible, proactive, and able to work in a fast-paced, ever-changing, and exciting environment.
Nice to have:
Cybersecurity experience
Experience with administering Microsoft 365, Intune and SolarWinds is a plus.
Experience with Rubrik or similar backup solutions.
Experience with Tanium or similar third-party patching
Linux, Ansible, Puppet
Network Engineer
Security engineer job in Chicago, IL
Network Engineer (On-site, Chicago, IL)
Type: Full-time, Direct Hire
Compensation: $115,000 base salary + discretionary bonus (2-6%)
Benefits: Medical, Dental, Vision; HSA/FSA; 401(k) with 6% match; 2% profit sharing; Life & Disability insurance; Paid Time Off; Paid Holidays
This an exciting full time, permanent opportunity with tremendous stability and growth potential! Join an iconic U.S. manufacturer and help modernize mission-critical network infrastructure that powers production, distribution, and enterprise operations. As a Network Engineer, you'll design, build, secure, and optimize LAN/WAN environments, strengthen perimeter and endpoint defenses, and collaborate across IT and business teams to keep the organization fast, resilient, and safe.
What You'll Do
Design, implement, and support scalable LAN/WAN/intranet architectures across plants, offices, and cloud endpoints
Administer and harden network gear-firewalls, routers, switches, wireless APs, VPN-with defense-in-depth practices
Monitor performance & security, triage incidents, document fixes, and drive preventive improvements
Plan capacity & growth by analyzing traffic and forecasting future needs
Partner with cross-functional teams to architect network solutions for new apps, SaaS, and datacenter/cloud workloads
Stay current on emerging networking/cybersecurity tech and recommend pragmatic enhancements
What You'll Bring
Bachelor's in Computer Science, IT, or related field (Master's preferred)
Proven success designing and supporting enterprise network architectures
Hands-on mastery of TCP/IP, DNS, DHCP, VLANs, VPNs, and routing protocols
Strong understanding of network security (firewalls, IDS/IPS, encryption, zero-trust concepts)
Experience configuring/managing routers, switches, firewalls, VPNs, and voice
Problem-solving mindset with crisp documentation and communication
Experience leading upgrades/migrations and multi-stakeholder implementations
Pay Transparency (Illinois)
Base salary: up to $115,000
Discretionary bonus: 2-6% of base salary
Benefits: Medical, Dental, Vision; HSA/FSA; 401(k) with 6% match; 2% profit sharing; Life & Disability; PTO; Holidays
Equal Opportunity
We are committed to equal employment opportunity. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic.
Network Engineer
Security engineer job in Itasca, IL
Title: Network Engineer
Type: 24+ month contract
Domestic and International Travel required: 20-25%
US Citizens and GCH encouraged to apply (this opportunity does not offer sponsorship now or in the future)
Required Skills:
Proven experience in a Network Engineer role
5+ years' work experience in Cisco and FortiGate and other related network technologies
Support network integration efforts related to mergers and acquisitions (M&A), including infrastructure consolidation, data migration, and application alignment across acquired entities.
Previous experience designing\implementing\administrating an SD-WAN network
Excellent knowledge of best practices around management, control, and monitoring of Cisco infrastructure
Good Knowledge and experience with routing protocols like EIGRP, BGP, and MPLS
Experience with hybrid network design\administration, on-prem and cloud environments like Azure and AWS
Working knowledge of Cisco ISE environments
Configuration and monitoring of Cisco WIFI networks
Ability to set up and configure hardware connections to different WAN technologies
Experience in configuration of Cisco Routers and Switches to support a multi - VLAN, environment
Great at organizing, prioritizing, and multitasking
Strong troubleshooting skills
Bachelor's degree in related field or 5+ years work experience in CISCO and other related network technologies
Holding credentials that demonstrates ability to perform a specific level of tasks related to implementing and maintaining network infrastructure.
Troubleshoot network operation errors
Experience working in Windows and VMware environments
Contact:
Ashley Falkenberg - Senior Recruiting Consultant
Forbes Technical Consulting
*******************
Microsoft System Engineer
Security engineer job in Chicago, IL
Microsoft 365 Engineer
Onsite Daily
Locals Preferred
This is a Full time, permanent position and is not open to sponsorship, 3rd party representation or H1B transfer at this time.
I am looking for a hands-on Microsoft 365 Engineer to own, administer, and continuously improve our enterprise M365 environment. This is a great opportunity for someone who wants full ownership of a modern collaboration platform, enjoys solving complex technical challenges, and thrives in an onsite team environment.
You'll manage daily operations, lead platform enhancements, and drive adoption across the business. Your work will directly impact company productivity, data security, and collaboration effectiveness.
OVERVIEW OF RESPONSIBILITIES
Microsoft 365 Administration
Manage user identities, groups, licensing, and security settings in Entra ID (Azure AD).
Administer Exchange Online (mail flow, hybrid connectivity, retention policies).
Maintain and optimize Teams, SharePoint Online, OneDrive, Outlook, and collaboration workflows.
Implement backup and recovery procedures for M365 email and files.
Security & Compliance
Enforce Conditional Access, MFA, and identity protection protocols.
Configure retention/sensitivity labels and compliance policies via Microsoft Purview.
Perform periodic security audits and resolve vulnerabilities.
Support hybrid identity integration between AD and Azure AD.
Monitoring & Troubleshooting
Use PowerShell, Graph API, M365 Admin Center, and Defender portal to monitor performance and security.
Quickly resolve complex issues related to email flow, Teams meetings, SharePoint access, and identity authentication.
Build automation scripts, runbooks, and dashboards.
Support & Collaboration
Partner with the Service Desk and app teams to improve processes and ensure change control.
Provide user training, communications, and documentation.
Participate in on-call rotation and off-hours upgrades.
Windows Server Management
Maintain and support on-prem Windows Server infrastructure.
Install, upgrade, patch, and troubleshoot server systems to ensure reliability.
QUALIFICATIONS
5+ years in IT; 3+ years administering Microsoft 365 / Azure environments.
Strong experience with Exchange Online, Teams, Intune, SharePoint Online, and Entra ID.
Azure experience, including VMs, AKS, SQL managed instances, and Azure firewall.
Strong PowerShell automation expertise.
Experience with backup/disaster recovery and security protocols.
Excellent communication and problem-solving ability.
Microsoft or Azure certifications are a plus (Azure Admin, Azure Architect, M365, CCNA).
Overview: Sterling Engineering / Staffing has a rich history of delivering top talent to our clients. We are a nationwide Staffing Firm that has been in business for over 56 years. With over 200 currently active clients, Sterling works within the Automation, Energy, Facilities, Information Technology, Food, Logistics / Supply Chain, Manufacturing, Packaging, Life Sciences, Pharmaceuticals, Engineering and R&D industries.
Qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information.
Network and Systems Engineer (IT Generalist & Security Focus)
Security engineer job in New Lenox, IL
Network & Systems Engineer (IT Generalist & Security Focus)
📍 On-site | New Lenox, IL
We're partnering with a well-established organization in the healthcare industry to hire a Network and Systems Engineer - a versatile, hands-on IT professional who can manage and secure the company's full technology environment. This role is 100% on-site at the New Lenox, IL headquarters and requires daily in-person support for users, hardware, and network infrastructure.
About the Role
As a key member of the IT team, the Network & Systems Engineer will design, maintain, and secure the company's network and server environment while providing Tier 1 and Tier 2 support across all systems. You'll manage everything from network security and database administration to ERP support and e-commerce integrations - perfect for someone who thrives as a technical “jack of all trades.”
Key Responsibilities
Provide Tier 1 and Tier 2 support for hardware, software, and user devices (desktops, laptops, mobile, peripherals).
Administer user accounts, Active Directory/Azure AD, and Windows systems.
Design, implement, and maintain LAN/WAN/Wi-Fi networks for performance and security.
Configure and manage firewalls, VPNs, IDS/IPS, and security policies.
Conduct network security audits, vulnerability assessments, and incident response.
Support and maintain the ERP system (Prophet 21 by Epicor) including reporting, data integrity, and performance.
Manage SQL Server and Microsoft Access databases - backups, tuning, and security hardening.
Develop and maintain reports using SAP Crystal Reports and SQL queries.
Assist with API integrations and reporting automation.
Support the technical and connectivity aspects of the BigCommerce e-commerce platform.
Oversee IT asset management, inventory, and hardware lifecycle.
Required Skills & Experience
Proven experience as a Network Engineer, Systems Engineer, or IT Generalist with a cybersecurity focus.
Strong knowledge of networking (TCP/IP, routing, switching, VLANs, VPNs, firewalls).
Hands-on experience with Windows OS (desktop and server) and Active Directory/Azure AD.
Proficiency in SQL and Microsoft Access for database management.
Experience with Prophet 21 (P21) and SAP Crystal Reports is required.
Familiarity with API integrations and e-commerce platforms (BigCommerce preferred).
Excellent troubleshooting, communication, and documentation skills.
Must be available to work fully on-site in New Lenox, IL.
Preferred Qualifications
Experience with Linux systems.
Familiarity with Power BI or Tableau for business intelligence.
Certifications such as CompTIA Network+, Security+, CCNA, or CISSP.
Knowledge of cloud networking (AWS, Azure, GCP).
Scripting experience with PowerShell or Python.
💡 Why Apply?
This is an exciting opportunity for a technically curious and self-driven IT professional who enjoys variety, autonomy, and making a direct impact. You'll play a vital role in maintaining secure, efficient, and modern systems that power critical operations every day.
Network Engineer
Security engineer job in Chicago, IL
Role: Network Engineer
Job Type: Full Time
About the role
We are seeking a highly skilled and motivated Network Engineer with hands-on experience in routing and swtiching. The ideal candidate will provide direct, on-site ("hands-on") support, troubleshoot complex network issues, and be an expert in routing and switching protocols.
Key responsibilities
Provide on-site, "hands-and-feet" support for network infrastructure, including physical racking, stacking, cabling, and hardware replacement for Arista switches and routers.
Configure, install, and support network hardware and software, ensuring seamless integration with our existing infrastructure.
Monitor network performance and proactively identify and resolve issues related to routing and switching.
Travel to other location when required for hands and feet support. ( 10%)
Serve as the primary on-site resource for network-related incidents, performing advanced troubleshooting and resolving critical issues with minimal downtime.
Knowledge of network routing protocols (e.g., OSPF, BGP) and advanced switching technologies (e.g., VXLAN, EVPN).
Plan and execute network maintenance, upgrades, and expansion projects with a focus on data center and campus environments.
Develop and maintain comprehensive technical documentation, including network diagrams, configurations, and standard operating procedures.
Collaborate with cross-functional IT teams and vendors to deliver new solutions, resolve issues, and ensure compliance with network standards.
Participate in an on-call rotation to provide 24/7 support for critical network issues.
Qualifications
Experience: 5+ years of hands-on experience in network engineering, with specific and in-depth experience configuring and troubleshooting routing and switching hardware and software
Knowledge of L2/L3 networking protocols, including BGP, OSPF, VLANs, and Spanning Tree.
Hands-On Skills: Proven experience with physical infrastructure tasks, such as server racking, cable management (copper and fiber), and hardware replacement.
Problem-Solving: Excellent analytical and troubleshooting skills, with the ability to diagnose and resolve complex network issues.
Disclaimer
HCL is an equal opportunity employer, committed to providing equal employment opportunities to all applicants and employees regardless of race, religion, sex, color, age, national origin, pregnancy, sexual orientation, physical disability or genetic information, military or veteran status, or any other protected classification, in accordance with federal, state, and/or local law. Should any applicant have concerns about discrimination in the hiring process, they should provide a detailed report of those concerns to ****************** for investigation.
Compensation and Benefits
A candidate's pay within the range will depend on their work location, skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year); and 10 paid holidays per year.
Network Security Engineer
Security engineer job in Oak Brook, IL
The Network Security Engineer will maintain and help deploy the Company's security platform and solution efforts as well as perform network and host threat assessments to identify, evaluate and mitigate security risks, threats and vulnerabilities. This position will primarily be responsible for the Palo Alto Firewalls, Fortigates, and F5 Load Balancers. The Network Security Engineer will work to develop action plans to mitigate identified vulnerabilities and promote security initiatives.
Essential Job Functions:
Work at the direction of the Security Manager to improve the security for the Company
Administration of all aspects of the Palo Alto Firewalls
Administration of all aspects of the FortiGate Firewalls and experience with FortiManager and FortiAnalyzer
Administration of all aspects of the F5 Load Balancers
Assist with the configuration and administration of security systems and tools
Respond to security incidents and report on incident handling and resolution
Assist with the enforcement of security policies and procedures by monitoring system activity
Review security violation reports and investigates possible security exceptions, updates, and maintains and documents security controls
After hours monitoring and on call support will also be required
Lead and mentor more junior network security engineers on projects and initiatives
Minimum Requirements:
Bachelor's Degree in Computer Science, Information Systems, or other related field
7+ years hands-on experience maintaining corporate firewalls (preferably with direct experience on Palo Alto Firewalls), Panorama Experience, Global Protect VPN configuration and management.
Hands-on experience maintaining corporate load balancers (preferably with direct experience on F5 load balancers)
Detailed knowledge of the OSI model and its application across corporate networks
Working knowledge of Windows, Red Hat Linux, and Oracle Linux operating systems
Proficient in Microsoft Word, Project, Excel, Access, Visio
Ability to manage multiple projects with competing priorities
Ability to work as part of a team
**
This is a full-time, W2 position with Hub Group - We are NOT able to provide sponsorship at this time
**
Salary Range:
$110,000 - $165,000/year base salary
+ bonus eligibility
**
This is an estimated range based on the circumstances at the time of posting, however, may change based on a combination of factors, including but not limited to skills, experience, education, market factors, geographical location, budget, and demand**
BEWARE OF FRAUD!
Hub Group Has Become Aware of Online Recruiting Related Scams in Which Individuals Who Are Not Affiliated with or Authorized by Hub Group Are Using Hub Group's Name in Fraudulent Emails, Job Postings, Or Social Media Messages. In Light of These Scams, Please Bear the Following in Mind
Hub Group will never solicit money or credit card information in connection with a Hub Group job application.
Hub Group does not communicate with candidates via online chatrooms such as Signal or Discord using email accounts such as Gmail or Hotmail.
Hub Group job postings are posted on our career site: ********************************
About Us
Hub Group is the premier, customer-centric supply chain company offering comprehensive transportation and logistics management solutions. Keeping our customers' needs in focus, Hub Group designs, continually optimizes and applies industry-leading technology to our customers' supply chains for better service, greater efficiency and total visibility. As an award-winning, publicly traded company (NASDAQ: HUBG) with $5 billion in revenue, our 6,000 employees and drivers across the globe are always in pursuit of "The Way Ahead" - a commitment to service, integrity and innovation. We believe the way you do something is just as important as what you do. For more information, visit ****************
Senior Security Engineer
Security engineer job in Chicago, IL
Salary: Open + Bonus
Hybrid: 3 days onsite, 2 days remote
*This role is open to H1B transfer*
Qualifications
Bachelors' degree including 6+ years of related experience
Experience in one or more of the following disciplines: security operations, development, engineering, or architecture
Experience supporting privileged access management and access controls programs.
Professional or personal experience using AI coding agents such as OpenAI Codex, Claude Code, or Gemini CLI.
Expertise in providing operational and engineering support for one or more of the following: CyberArk, HashiCorp Vault, Active Directory Certificate Services (ADCS), HSMs, and Public Key Infrastructure (PKI).
Expertise in scripting languages and developing in one or more of the following languages Golang, Bash, Python, PowerShell, Ansible, and/or Terraform.
Knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation.
Knowledge of application authentication and authorization systems (i.e., Active Directory, OAuth 2.0, OIDC, AWS IAM, App Role, k8s, LDAPS, Kerberos, Certificate)
Working knowledge of the cloud ecosystem and CI/CD deployments with Terraform, Ansible, and Jenkins pipelines.
Working knowledge of security architecture design and principles including confidentiality, integrity and availability.
Responsibilities
Manage privileged access systems that protect most critical assets, implement AI-based security capabilities, and help shape security architecture.
Provide 24x7 operational support for the suite of privileged management solutions (e.g., CyberArk, Hashi, PKI), including implementing hot fixes, resolving bugs, troubleshooting issues, performing break-fixes, managing secrets lifecycle, and delivering end-user support.
Maintain robust operational integrity of privileged access management infrastructure throughout its lifecycle (e.g., patching, version control, system upgrades, etc.). Provide organizational subject matter experts on secrets management and privileged access management architecture, establishing and enforcing security as code principles throughout the environment.
Develop and implement system enhancements to improve platform user experience and automated integrations, while designing long-term solutions to address operational issues through innovative technologies including artificial intelligence for faster detection and remediation of functional and technical problems.