Job Title: Security Engineer Location: Chicago, IL (Hybrid)- Local Only Job Type: Full-Time Essential Functions:
- Responsible for threat and vulnerability management across the environment utilizing CrowdStrike, Qualys & Splunk.
- Research, implement and administer security infrastructure as required, including intrusion protection, security-related firewall configurations, endpoint solutions, and SIEM (Splunk), including tuning and custom alerts.
- Responsible for security event handling and security incident response processes, including documenting standard operating procedures and protocols and automating common tasks.
- Implement and document best-practice security procedures, standards, and guidelines.
- Identify security exposures and develop mitigation plans.
- Advocate security awareness and teach secure behaviour and methods.
- Perform technical risk assessments, triage security testing results, and manage security response actions.
- Work closely with IT on the development of security metrics, assisting in compliance audits, and continuous security improvements.
- Assist in compliance activities such as external audits from customers, regulatory compliance projects, and overall information security reviews.
Education/Experience/Skills:
- Minimum 5 years information security experience.
- Splunk Enterprise (on-prem) is the primary tool for analysis and the candidate must have setup and configuration experience to own and maintain the application and underlying Linux operating systems.
- Experience with the CrowdStrike Falcon platform is strongly preferred.
- Prior experience with internal auditing of security controls, PCI/SOX security audits
- Strong Microsoft security experience, particularly with Hybrid Azure/On-prem environments
- Strong vulnerability management background, including overseeing the scanning, penetration testing, and server / workstation / mobile device security hardening processes.
- In-depth experience identifying and protecting against web application and web service security vulnerabilities including those found in the OWASP Top 10 and CWE Top 25.
- Experience with firewalls and network segmentation.
- Strong written and oral communication skills are a must.
- Experience working in a team-oriented, collaborative environment.
- Proficiency in Microsoft Office including, but not limited to, Outlook, Word, Excel, PowerPoint and Visio