Information Security Engineer
- Location
- Chicago, IL
- Work type
- Full Time · Hybrid
- Posted
- 2026-09-15
Job description
DUTIES & RESPONSIBILITIES:
Monitor and manage technologies, including SIEM, endpoint protection, EDR, and other security platforms, to detect, analyze, investigate, mitigate, patch and respond to security threats and vulnerabilities.
Analyze cybersecurity threats and design, architect, implement, and maintain security solutions that protect the confidentiality, integrity, and availability of institutional data and systems.
Conduct vulnerability scanning and security assessments; analyze findings, document risks, and perform appropriate remediation actions.
Support and participate in incident response activities by investigating security alerts and incidents, determining impact, escalating issues as appropriate, and assisting with containment, eradication, recovery, and resolution efforts.
Implement and maintain access controls for sensitive, confidential, and high-security data while supporting identity and access management processes, least-privilege principles, authentication controls, and privileged access security.
Collaborate to design, implement, and maintain security controls across infrastructure, applications, endpoints, networks, and cloud environments.
Maintain and enforce information security policies, standards, procedures, and technical controls to ensure compliance with regulatory and institutional requirements.
Evaluate information security risks associated with new technologies, systems, and implementations and recommend or implement appropriate security controls to mitigate identified risks.
Manage and support third-party relationships and technology vendors by facilitating communication, evaluating security requirements, monitoring contract and compliance obligations, and assisting with the resolution of security-related issues.
Conduct or support third-party security risk assessments to evaluate vendor security practices, data protection measures, and compliance with institutional security requirements.
Support the development and delivery of information security awareness and training programs for faculty, staff, and students.
Track, analyze, and report on security incidents, vulnerabilities, trends, and metrics to identify areas for improvement and support the ongoing development of the Institution's information security program.
Stay current with emerging cybersecurity threats, vulnerabilities, technologies, regulatory requirements, and industry best practices, and assess their potential impact on the Institution.
Perform other related duties and/or responsibilities as assigned or required.
Bachelor’s degree in computer science, Information Systems, cybersecurity, or a related field, or an equivalent combination of education and relevant professional experience.
3-5 years of professional experience in information security, cybersecurity operations, IT operations, systems administration, or a related field.
Experience with Security Information and Event Management (SIEM) platforms such as Humio, Splunk, Microsoft Sentinel, QRadar, or similar security monitoring and log analysis solutions.
Experience with Endpoint Detection and Response (EDR) and endpoint protection platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or equivalent technologies.
Experience with vulnerability management and security assessment processes, including vulnerability scanning, risk assessment, remediation tracking, and risk prioritization.
Experience with identity and access management (IAM), multi-factor authentication (MFA), privileged access controls, least-privilege principles, and user identity lifecycle management.
Experience supporting and securing cloud and hybrid environments, including Microsoft 365, Microsoft Entra ID, and related Microsoft security technologies.
Experience with security monitoring, incident response, threat detection, investigation, containment, remediation, and recovery processes.
Knowledge of common cybersecurity threats, attack vectors, vulnerabilities, security controls, mitigation strategies, and information security frameworks and industry best practices, including the NIST Cybersecurity Framework, CIS Controls, and applicable regulatory and compliance requirements.
Ability to analyze security risks and implement or recommend appropriate technical and administrative controls to mitigate identified risks.
Strong analytical, troubleshooting, critical-thinking, and problem-solving skills, with the ability to investigate security events, assess vulnerabilities, diagnose complex security issues, and identify effective solutions.
Strong technical aptitude, written and verbal communication skills, and the ability to communicate technical risks, security requirements, and cybersecurity concepts effectively to both technical and non-technical stakeholders.
Strong organizational, documentation, project coordination, and time management skills, with the ability to manage multiple priorities while maintaining confidentiality and protecting sensitive institutional data.
Ability to collaborate effectively with technical and non-technical stakeholders across the organization and work with cross-functional teams to implement security solutions.
Experience evaluating security risks associated with third-party vendors, applications, cloud services, and technology implementations is preferred.
Experience with higher education information security, regulatory requirements, or compliance frameworks, including GLBA, is preferred.
Relevant industry certifications such as CompTIA Security+, CySA+, CEH, GSEC, SSCP, or equivalent certifications are preferred.
This job description is not intended to be a comprehensive list of all duties, responsibilities, or qualifications associated with the position. Duties and responsibilities may change at any time based on departmental and/or College needs.
Position Minimum Annual Salary: $86,034
Position Maximum Annual Salary: $106,897
The salary range provided in this posting reflects what we reasonably expect to pay for this position. Actual compensation offered or earned is dependent on experience, education and other factors including department budget.