Security Engineer
JR Recruiting Chicago, Illinois, United States
Staffing and Recruiting · 2-10 employees
About the role
The Security Engineer is responsible for designing, implementing, and operating technical controls to safeguard organizational systems, data, and staff. This includes managing security operations, incident response, vulnerability scanning, and ensuring compliance with regulatory standards like HIPAA and PCI DSS.
What they look for
Requirements
Candidates must have at least 3 years of hands-on experience in information security or security engineering. A bachelor's degree in a related field is required, along with proficiency in Microsoft 365 security, network fundamentals, and incident response.
Benefits
Full description
Our client is a large, well-established nonprofit that provides human services across the Chicago metropolitan area. Each year the organization serves hundreds of thousands of individuals and families through a network of food, housing, senior, family, mental health, immigration, and crisis programs delivered at dozens of sites across the region. Services are open to everyone regardless of faith or background, and the organization's culture is grounded in compassion, solidarity, and measurable impact. The client name will be shared with qualified candidates during the screening process.
Position Summary
The people this organization serves trust it with some of the most sensitive information in their lives: health records, immigration status, housing and financial histories, and the details of families in crisis. The Security Engineer is the hands-on owner of protecting that trust. You will design, implement, and operate the technical controls that safeguard its systems, data, and staff across headquarters, program sites, and residential communities, and you will help a mission-driven, largely non-technical workforce practice good security every day. This is a broad, high-ownership role on a small IT team, ideal for someone who wants their work to have a direct human impact.
Key Responsibilities
- Own day-to-day security operations: monitor alerts, triage and investigate incidents, lead response and containment, and document root cause and lessons learned.
- Administer and tune core security tooling, including endpoint detection and response, email security, identity and access management (MFA, SSO, conditional access), vulnerability scanning, and SIEM or log management.
- Secure the organization's Microsoft 365 / cloud environment, network infrastructure, and endpoints across dozens of distributed program sites.
- Run the vulnerability and patch management program: scan, prioritize by risk, coordinate remediation with IT and vendors, and track to closure.
- Design and enforce identity and access controls, including role-based access, least privilege, joiner/mover/leaver processes, and periodic access reviews.
- Support compliance with the regulations that apply to the organization's programs, including HIPAA, PCI DSS, state data-privacy laws,and government-grant security requirements; prepare evidence for audits and assessments.
- Assess the security of third-party vendors and SaaS platforms (case management, donor, HR, and financial systems) before and after onboarding.
- Build and deliver security awareness training and phishing simulations tailored to case workers, pantry and housing staff, volunteers, and leadership.
- Maintain and test business continuity, disaster recovery, and backup procedures so critical services stay available to the people served.
- Write and maintain security policies, standards, and run playbooks; help translate policy into practical guidance staff can follow.
- Provide security input on new projects, system implementations, and integrations from the start rather than after the fact.
- Track and report security metrics and risk posture to IT leadership and, as needed, to executive leadership and the board.
Requirements
Required Qualifications
- 3+ years of hands-on experience in information security, security engineering, or a security-focused systems/network administration role.
- Working knowledge of Microsoft 365 and Entra ID (Azure AD) security, Windows and endpoint security, and network fundamentals (firewalls, VPN, segmentation, Wi-Fi).
- Practical experience with at least several of the following: EDR, email security gateways, SIEM/log analysis, vulnerability scanners, MFA/SSO, backup and recovery tools.
- Experience leading or materially contributing to incident response.
- Familiarity with HIPAA Security Rule requirements and at least one security framework (NIST CSF, CIS Controls, or ISO 27001).
- Ability to explain security concepts clearly and patiently to non-technical colleagues and to build cooperative relationships across the organization.
- Strong documentation habits and the ability to work independently and prioritize in a small-team environment.
- Bachelor’s degree in computer science, information systems, or a related field, or equivalent practical experience.
Preferred Qualifications
- Security certification such as Security+, CySA+, GSEC, CISSP, or a Microsoft security certification (SC-200, SC-300, AZ-500).
- Experience in a nonprofit, healthcare, social services, or other resource-conscious, compliance-driven environment.
- Experience securing case-management, EHR, or donor/CRM platforms and working with grant or government-funded program requirements.
- Scripting ability (PowerShell, Python) for automation and reporting.
- Experience with PCI DSS scope reduction and payment-processing security.
Benefits
This position is based at the client's downtown Chicago headquarters with a hybrid schedule. Periodic travel to program sites across the greater Chicago area is required, as is occasional after-hours availability for incident response or planned maintenance. A valid driver’s license and reliable transportation are helpful. Employment is contingent on a background check consistent with the organization's commitment to protecting the vulnerable people it serves.
Why This Role
Your work will directly protect families, seniors, veterans, immigrants, and neighbors in crisis. Our client offers a competitive salary, a comprehensive benefits package including medical, dental, and vision coverage, retirement plan with employer contribution, generous paid time off and holidays, and support for professional development and certifications.
Similar roles
-
Lead Security Engineer, GRC
Anduril Industries Boston, Massachusetts, United States · $166K–$253K/yr
-
Information Security Engineer (R14207)
Oportun Mexico
-
Principal Application Security Specialist
Global Relay Vancouver, British Columbia, Canada · CA$125K–CA$160K/yr
-
HSM & PKI Security Engineer
CCDS Dammam, Eastern Province, Saudi Arabia
-
Security Engineer
Warp New York, New York, United States · $230K–$290K/yr
-
Product Security Engineer
YipitData (Alternative) United States · $180K/yr