J

Security Engineer

JR Recruiting Chicago, Illinois, United States

Staffing and Recruiting · 2-10 employees

Sep 12
security Mid (2-5 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Security Engineer is responsible for designing, implementing, and operating technical controls to safeguard organizational systems, data, and staff. This includes managing security operations, incident response, vulnerability scanning, and ensuring compliance with regulatory standards like HIPAA and PCI DSS.

What they look for

Security engineering Incident response Microsoft 365 security Entra ID Vulnerability management Endpoint detection and response Identity and access management Network security SIEM Compliance HIPAA PCI DSS Security awareness training Business continuity Disaster recovery Risk assessment

Requirements

Candidates must have at least 3 years of hands-on experience in information security or security engineering. A bachelor's degree in a related field is required, along with proficiency in Microsoft 365 security, network fundamentals, and incident response.

Benefits

Medical coverage Dental coverage Vision coverage Retirement plan with employer contribution Paid time off Paid holidays Professional development support

Full description

JR Recruiting is partnering with one of Chicago's largest mission-driven nonprofit organizations — a human-services institution operating dozens of locations across the region and supporting well over a thousand staff — to hire a Senior Director of Cybersecurity.

This is a hands-on leadership role, and we want to be clear about what that means. You will personally own the organization's security platforms and operations — not direct a large team that does it for you. You'll set direction, run the tooling, lead incident response, and build the metrics leadership takes to the board. You'll report to a technology executive with a deep cybersecurity background who built the current Zero Trust architecture and will be a genuine partner, not just an approver.

If you've spent years as a senior security engineer or security manager and you're ready for the title, the scope, and the seat at the table — without giving up the technical work you're good at — this is that role.

What you'll own

  • Administration, monitoring, and continuous improvement

of the security stack: endpoint protection, identity security, cloud security, SIEM/SOAR, and threat detection

  • Enterprise vulnerability management, AI-driven

penetration testing, security assessments, and remediation across servers, endpoints, mobile, cloud, and infrastructure

  • Hands-on security operations: threat monitoring,

incident response, investigations, cyber-recovery planning, and coordination with managed security providers, auditors, and IR partners

  • Partnership with infrastructure, applications, help

desk, data, and business teams to implement controls, meet compliance requirements, and secure new initiatives

  • Security metrics, operational dashboards, risk

reporting, and remediation tracking that give leadership and the board real visibility — and a clear case for future investment

  • Risk-based recommendations and technical guidance to IT

leadership

The environment

  • Microsoft-centered: Azure security services, Microsoft

365 Security, Microsoft Entra ID, Microsoft Defender

  • Endpoint and network security platforms including

CrowdStrike and Zscaler

  • SIEM, SOAR, EDR, and vulnerability management tooling;

24x7 managed SOC/MDR partnership

  • A Zero Trust architecture already in place — you'll

mature it, not build it from zero

  • A distributed footprint: many locations, a large and

varied user population, and real-world operational stakes

Who does well here

​

  • A player-coach. You want to lead and you want to

keep your hands on the keyboard. You'd be bored in a pure oversight role.

  • Calm under incident. You've run a response, made

decisions with incomplete information, and written the post-mortem.

  • A translator. You can explain risk to a CFO and

a board as clearly as you can to an engineer.

  • Mission-motivated. You want your work to protect

an organization that serves people who need it. The client is a faith-affiliated nonprofit; candidates of all backgrounds are welcome, and genuine respect for the mission matters.

Requirements

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer

Science, Information Systems, or related field

  • 10+ years of progressive cybersecurity experience,

including 5+ years leading security programs, operations, or teams

  • Hands-on depth in vulnerability management, penetration

testing, identity security, cloud security, and incident response

  • Direct experience with Microsoft Azure and M365

security, Entra ID, and enterprise EDR/SASE platforms (CrowdStrike and Zscaler experience strongly preferred)

  • Experience with SIEM, SOAR, and security monitoring

platforms

  • Clear written and verbal communication with technical

and non-technical audiences

Preferred

  • Master's degree; experience in nonprofit, healthcare,

social services, or mission-driven organizations

  • Experience implementing NIST CSF or CIS Controls;

managing audits, compliance assessments, and third-party risk

  • Executive metrics and board-level reporting; AI-driven

security tools and automated penetration testing

  • Certifications such as CISM, CCSP, GIAC, Microsoft

Cybersecurity Architect Expert, Azure Security Engineer Associate, CrowdStrike or Zscaler

Benefits

What's offered

  • $140,000–$150,000 base salary
  • Comprehensive medical, dental, and vision coverage;

employer-paid life and disability insurance

  • Paid parental leave; generous PTO, sick time, and 15

paid holidays

  • Retirement savings plan; tuition reimbursement and

professional development support

  • Hybrid schedule; a stable, well-established

organization; and work that matters

Similar roles