Information Security Engineer
Chicago, IL ( Preffered ) - Remote
Conversion salary @120K -- not much flexibility.
Job Responsibilities:
- Conduct continuous identification and assessment of SaaS exposures, to include misconfigurations, permission sprawl, insecure integrations, and identity-centric risks across enterprise SaaS platforms.
- Analyze security findings and provider advisories to identify and prioritize corrective action(s) based on exposure, exploitability, and business criticality.
- Document and track SaaS security risks, remediation actions, and posture trends using automated risk registers, POA&Ms, and exception requests. Generate and brief technical and executive-level reports aligned to applicable regulatory and audit requirements.
- Develop, implement, and sustain security configuration baselines and hardening standards, mapped to organizationally mandated frameworks (CIS, NIST CSF, etc.).
- Partner with SaaS application owners and identity, GRC, and enterprise teams to coordinate remediation of customer-controlled SaaS risks.
- Plan and execute SaaS security posture assessments to measure connected application compliance and alignment across the SaaS portfolio.
- Participate in cross-functional risk and threat modeling activities and provide actionable recommendations for reduction or transference of risk.
- Develop, implement, and update vulnerability management policies, standards, and TTPs supporting SaaS vulnerability and exposure management processes.
- Utilize autonomous skills to leverage organizational Artificial Intelligence (AI) tools to effectively and efficiently assess exposure and risk at scale.
- Liaison with applications teams, business stakeholders, and vendor representatives to review security posture, remediation ownership, compensating controls, and contractual and regulatory compliance.
- Support and mature proactive cybersecurity strategies to include CTEM, SaaS Attack Surface Management, Identity Threat Detection and Response (ITDR), and zero-trust access models.
- Maintain up-to-date knowledge of emerging threats, vulnerabilities, and cybersecurity best practices.
- Assist with cybersecurity tool evaluation and implementation, and operation.
- Participate in organizational and third-party training and workshops to enhance professional knowledge and team performance.
Required Job Qualifications:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).
- Professional certification as Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP+), GIAC Security Leadership Certification (GSLC), or equivalent.
- Minimum 5 years of experience in cybersecurity, with at least 3 years focused on vulnerability management, compliance validation, or threat analysis.
- Experience with multiple operating systems to include Windows, MacOS, Linux, Cisco iOS, etc.
- Hands-on experience with SSPM, CASB, IAM, or equivalent SaaS vulnerability management tools (e.g., Wiz, Microsoft Defender, Netskope, Entra ID, Okta).
- Familiarity with prompt engineering and leveraging of AI tools to automate manual processes and supplement data analysis.
- A strong understanding of networking, infrastructure, application, and information concepts and associated security principles.
- Experience in risk assessment and mitigation processes, practices, and strategies.
- Strong analytical, documentation, and communication skills.
- Ability to lead cybersecurity engineering projects and effectively communicate with business partners.
- Excellent interpersonal and communications skills, with the ability to work collaboratively in a team environment.
- Ability to work under pressure and effectively handle multiple responsibilities in a fast-paced and critical health care environment.
Preferred Job Qualifications:
- Experience with business efficiency/intelligence tools (e.g., Power BI, Power Automate, Generative AI).
- Experience with industry cybersecurity frameworks (e.g., CIS, NIST, PCI DSS).
- Experience with Business Efficiency, Business Intelligence, or Generative AI products.
- Exposure to incident response and disaster recovery procedures.
- Exposure to virtualization and cloud platform security (e.g., Azure, AWS).
- Familiarity with DevSecOps practices and secure software development methodologies.