J

Security Engineer

JR Recruiting Chicago, Illinois, United States

Staffing and Recruiting · 2-10 employees

19 h ago
security Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer is responsible for designing, implementing, and operating technical controls to safeguard organizational systems, data, and staff. This includes managing security operations, incident response, vulnerability scanning, and ensuring compliance with regulatory standards like HIPAA and PCI DSS.

What they look for

Security engineering Incident response Microsoft 365 security Entra ID Vulnerability management Endpoint detection and response Identity and access management Network security SIEM Compliance HIPAA PCI DSS Security awareness training Business continuity Disaster recovery Risk assessment

Requirements

Candidates must have at least 3 years of hands-on experience in information security or security engineering. A bachelor's degree in a related field is required, along with proficiency in Microsoft 365 security, network fundamentals, and incident response.

Benefits

Medical coverage Dental coverage Vision coverage Retirement plan with employer contribution Paid time off Paid holidays Professional development support

Full description

Our client is a large, well-established nonprofit that provides human services across the Chicago metropolitan area. Each year the organization serves hundreds of thousands of individuals and families through a network of food, housing, senior, family, mental health, immigration, and crisis programs delivered at dozens of sites across the region. Services are open to everyone regardless of faith or background, and the organization's culture is grounded in compassion, solidarity, and measurable impact. The client name will be shared with qualified candidates during the screening process.

Position Summary

The people this organization serves trust it with some of the most sensitive information in their lives: health records, immigration status, housing and financial histories, and the details of families in crisis. The Security Engineer is the hands-on owner of protecting that trust. You will design, implement, and operate the technical controls that safeguard its systems, data, and staff across headquarters, program sites, and residential communities, and you will help a mission-driven, largely non-technical workforce practice good security every day. This is a broad, high-ownership role on a small IT team, ideal for someone who wants their work to have a direct human impact.

Key Responsibilities

  • Own day-to-day security operations: monitor alerts, triage and investigate incidents, lead response and containment, and document root cause and lessons learned.
  • Administer and tune core security tooling, including endpoint detection and response, email security, identity and access management (MFA, SSO, conditional access), vulnerability scanning, and SIEM or log management.
  • Secure the organization's Microsoft 365 / cloud environment, network infrastructure, and endpoints across dozens of distributed program sites.
  • Run the vulnerability and patch management program: scan, prioritize by risk, coordinate remediation with IT and vendors, and track to closure.
  • Design and enforce identity and access controls, including role-based access, least privilege, joiner/mover/leaver processes, and periodic access reviews.
  • Support compliance with the regulations that apply to the organization's programs, including HIPAA, PCI DSS, state data-privacy laws,and government-grant security requirements; prepare evidence for audits and assessments.
  • Assess the security of third-party vendors and SaaS platforms (case management, donor, HR, and financial systems) before and after onboarding.
  • Build and deliver security awareness training and phishing simulations tailored to case workers, pantry and housing staff, volunteers, and leadership.
  • Maintain and test business continuity, disaster recovery, and backup procedures so critical services stay available to the people served.
  • Write and maintain security policies, standards, and run playbooks; help translate policy into practical guidance staff can follow.
  • Provide security input on new projects, system implementations, and integrations from the start rather than after the fact.
  • Track and report security metrics and risk posture to IT leadership and, as needed, to executive leadership and the board.

Requirements

Required Qualifications

  • 3+ years of hands-on experience in information security, security engineering, or a security-focused systems/network administration role.
  • Working knowledge of Microsoft 365 and Entra ID (Azure AD) security, Windows and endpoint security, and network fundamentals (firewalls, VPN, segmentation, Wi-Fi).
  • Practical experience with at least several of the following: EDR, email security gateways, SIEM/log analysis, vulnerability scanners, MFA/SSO, backup and recovery tools.
  • Experience leading or materially contributing to incident response.
  • Familiarity with HIPAA Security Rule requirements and at least one security framework (NIST CSF, CIS Controls, or ISO 27001).
  • Ability to explain security concepts clearly and patiently to non-technical colleagues and to build cooperative relationships across the organization.
  • Strong documentation habits and the ability to work independently and prioritize in a small-team environment.
  • Bachelor’s degree in computer science, information systems, or a related field, or equivalent practical experience.

Preferred Qualifications

  • Security certification such as Security+, CySA+, GSEC, CISSP, or a Microsoft security certification (SC-200, SC-300, AZ-500).
  • Experience in a nonprofit, healthcare, social services, or other resource-conscious, compliance-driven environment.
  • Experience securing case-management, EHR, or donor/CRM platforms and working with grant or government-funded program requirements.
  • Scripting ability (PowerShell, Python) for automation and reporting.
  • Experience with PCI DSS scope reduction and payment-processing security.

Benefits

This position is based at the client's downtown Chicago headquarters with a hybrid schedule. Periodic travel to program sites across the greater Chicago area is required, as is occasional after-hours availability for incident response or planned maintenance. A valid driver’s license and reliable transportation are helpful. Employment is contingent on a background check consistent with the organization's commitment to protecting the vulnerable people it serves.

Why This Role

Your work will directly protect families, seniors, veterans, immigrants, and neighbors in crisis. Our client offers a competitive salary, a comprehensive benefits package including medical, dental, and vision coverage, retirement plan with employer contribution, generous paid time off and holidays, and support for professional development and certifications.

Similar roles