Back to jobs

Security Engineer-W2

System Soft TechnologiesRosemont, ILPosted 3d ago
Security Engineer — Python, Privacy
Craft my tailored resume free

Free to start · No card

Job description

Job Summary The Cybersecurity Administrator is a hands-on technical role on the Information Security team, responsible for Administering, hardening, and operating security controls across a hybrid environment spanning Microsoft Azure, Microsoft Entra ID, Microsoft 365, and traditional infrastructure. This is not a policy-focused position. The ideal candidate is an accomplished Cybersecurity Administrator who can walk into an existing complex environment, quickly understand the architecture, and immediately contribute to incident response, identity and access hardening, cloud security engineering, and vulnerability remediation. Success in this role requires deep, current technical expertise in Information Security, Security Operations, Microsoft Ecosystem, a DevSecOps mindset, and fluency with automation and infrastructure-as-code / security-as-code practices. The organization operates in a highly regulated financial services environment, so the candidate must apply strong engineering discipline while meeting compliance obligations. Responsibilities Security Operations & Incident Response Operate, tune, and build detections in Microsoft Sentinel (KQL for analytics rules, hunting queries, workbooks) and Microsoft Defender XDR to detect, investigate, and respond to threats.Design and automate response with SOAR playbooks (Logic Apps / Sentinel automation rules) to reduce mean time to respond.Lead and coordinate hands-on incident response for events such as data breaches, malware outbreaks, and identity compromises, including containment, eradication, and root-cause analysis across cloud and on-premises systems.Partner with Security and Risk leadership to translate policies and frameworks into enforceable, technically implemented controls.Develop, test, and validate disaster recovery and resilience strategies from a security perspective. Access Management & Compliance Engineer and administer Microsoft Entra ID: Conditional Access, PIM, Privileged Access Groups, authentication methods, identity protection, and hybrid identity.Manage privileged access controls and conduct recurring, evidence-based access reviews across cloud and on-premises systems.Ensure technical controls map to financial industry regulatory and compliance requirements; produce audit-ready evidence and documentation.Coordinate with compliance officers on security-related regulatory requirements.Maintain asset inventory and system/component security documentation.Coordinate and oversee third-party penetration testing and remediate findings. Security Infrastructure Management Administer and continuously improve security solutions across our hybrid environment.Harden PaaS/IaaS workloads and partners with engineering teams on secure-by-design cloud implementations (e.g., network segmentation, private endpoints, Key Vault, managed identities, RBAC).Conduct regular security assessments and vulnerability scans; drive remediation to closure.Perform periodic access and configuration reviews of enterprise systems.Build automation and infrastructure-as-code solutions (PowerShell, Python, Bicep/ARM/Terraform) to deploy controls consistently and reliably.Recommend and implement improvements, upgrades, and modernization of the security stack. Leadership & Guidance Provide security architecture guidance for cloud and infrastructure initiatives.Mentor IT team members on security best practices and secure engineering patterns.Partner with network, application, and database teams to implement secure solutions. Qualifications 3-5+ of Information Technology experience, with at least 3 years focused on CybersecurityMinimum of 2 years on Microsoft technologies in hands-on administration, engineering or operations capacity.Advanced cybersecurity certifications in good standing (e.g., CEH, OSCP, AZ-500, SC-300, SC-200, SC-100).Deep, hands-on knowledge of Microsoft services such as Defender (Cloud/Endpoint/XDR), Intune, Sentinel, and Entra ID, sufficient to operate and troubleshoot in a live environment on day one.Extensive experience operating hybrid cloud security architecture and controls.Strong background in security tooling administration, configuration, and tuning.Proven experience with endpoint security and modern device management (Intune).Advanced knowledge of network security concepts, including VPNs, firewalls, and SASE.Demonstrated experience leading security monitoring, incident response, and day-to-day security operations

Prepare your application

Use the description above to assess your fit for System Soft Technologies. This checklist is guidance from Resumize, rather than additional requirements from the employer. Imported listings can be shortened or change after collection, so confirm the complete description and current availability before sending an application.

Match requirements to evidence

Identify the responsibilities and skills the employer explicitly names. For each important requirement, choose one example from your work, education, training, or projects. Explain what you did, how you did it, and what changed as a result. Include a measurable outcome when you can support it. If you lack a requirement, describe related experience accurately instead of adding an unfamiliar skill to your resume.

Put the most relevant examples near the top of your resume. Keep job titles, dates, qualifications, and contact details consistent across your application materials. Use the employer’s terminology when it describes your experience accurately; a copied list of keywords does not explain your contribution. A short, specific bullet is easier to review than a paragraph that mixes several unrelated duties.

Check the working arrangement

Confirm the location, schedule, employment type, and any eligibility requirements on the employer’s site. A remote label does not establish worldwide eligibility or flexible hours. If compensation, benefits, equipment, travel, or contract duration are missing from this listing, write down your questions for the recruiter. Do not assume details from another opening at the same company apply to this role.

Review before submitting

Follow the employer’s requested file format and application instructions. Open your exported resume and check that its text is selectable, its sections read in order, and its links work. Proofread names, dates, and contact information. Share confidential work samples only when you have permission, and use an anonymized example when necessary.

Submit through a trusted employer or recruiting destination. If the original listing has disappeared, search the employer’s careers page for the title rather than assuming the vacancy remains open. Save the application date, job reference, and the version of your resume you sent. Those details help you prepare for a later conversation and avoid submitting conflicting information through several job boards.

Review your resume for writing and readability feedback, or browse other openings if this opportunity is unavailable.