All Jobs Vacancy

Information Security Engineer

Posted 1 day ago by Cogent IBS, Inc

Information Security Engineer

Chicago, IL ( Preffered ) - Remote

Conversion salary @120K -- not much flexibility.

Job Responsibilities:

  • Conduct continuous identification and assessment of SaaS exposures, to include misconfigurations, permission sprawl, insecure integrations, and identity-centric risks across enterprise SaaS platforms.
  • Analyze security findings and provider advisories to identify and prioritize corrective action(s) based on exposure, exploitability, and business criticality.
  • Document and track SaaS security risks, remediation actions, and posture trends using automated risk registers, POA&Ms, and exception requests. Generate and brief technical and executive-level reports aligned to applicable regulatory and audit requirements.
  • Develop, implement, and sustain security configuration baselines and hardening standards, mapped to organizationally mandated frameworks (CIS, NIST CSF, etc.).
  • Partner with SaaS application owners and identity, GRC, and enterprise teams to coordinate remediation of customer-controlled SaaS risks.
  • Plan and execute SaaS security posture assessments to measure connected application compliance and alignment across the SaaS portfolio.
  • Participate in cross-functional risk and threat modeling activities and provide actionable recommendations for reduction or transference of risk.
  • Develop, implement, and update vulnerability management policies, standards, and TTPs supporting SaaS vulnerability and exposure management processes.
  • Utilize autonomous skills to leverage organizational Artificial Intelligence (AI) tools to effectively and efficiently assess exposure and risk at scale.
  • Liaison with applications teams, business stakeholders, and vendor representatives to review security posture, remediation ownership, compensating controls, and contractual and regulatory compliance.
  • Support and mature proactive cybersecurity strategies to include CTEM, SaaS Attack Surface Management, Identity Threat Detection and Response (ITDR), and zero-trust access models.
  • Maintain up-to-date knowledge of emerging threats, vulnerabilities, and cybersecurity best practices.
  • Assist with cybersecurity tool evaluation and implementation, and operation.
  • Participate in organizational and third-party training and workshops to enhance professional knowledge and team performance.

Required Job Qualifications:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).
  • Professional certification as Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP+), GIAC Security Leadership Certification (GSLC), or equivalent.
  • Minimum 5 years of experience in cybersecurity, with at least 3 years focused on vulnerability management, compliance validation, or threat analysis.
  • Experience with multiple operating systems to include Windows, MacOS, Linux, Cisco iOS, etc.
  • Hands-on experience with SSPM, CASB, IAM, or equivalent SaaS vulnerability management tools (e.g., Wiz, Microsoft Defender, Netskope, Entra ID, Okta).
  • Familiarity with prompt engineering and leveraging of AI tools to automate manual processes and supplement data analysis.
  • A strong understanding of networking, infrastructure, application, and information concepts and associated security principles.
  • Experience in risk assessment and mitigation processes, practices, and strategies.
  • Strong analytical, documentation, and communication skills.
  • Ability to lead cybersecurity engineering projects and effectively communicate with business partners.
  • Excellent interpersonal and communications skills, with the ability to work collaboratively in a team environment.
  • Ability to work under pressure and effectively handle multiple responsibilities in a fast-paced and critical health care environment.

Preferred Job Qualifications:

  • Experience with business efficiency/intelligence tools (e.g., Power BI, Power Automate, Generative AI).
  • Experience with industry cybersecurity frameworks (e.g., CIS, NIST, PCI DSS).
  • Experience with Business Efficiency, Business Intelligence, or Generative AI products.
  • Exposure to incident response and disaster recovery procedures.
  • Exposure to virtualization and cloud platform security (e.g., Azure, AWS).
  • Familiarity with DevSecOps practices and secure software development methodologies.
Rate:
Not specified
Location:
Remote
IR35 Status:
Outside
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Share job