Security Engineer
JR Recruiting Chicago, Illinois, United States
Staffing and Recruiting · 2-10 employees
About the role
The Security Engineer is responsible for designing, implementing, and operating technical controls to safeguard organizational systems, data, and staff. This includes managing security operations, incident response, vulnerability scanning, and ensuring compliance with regulatory standards like HIPAA and PCI DSS.
What they look for
Requirements
Candidates must have at least 3 years of hands-on experience in information security or security engineering. A bachelor's degree in a related field is required, along with proficiency in Microsoft 365 security, network fundamentals, and incident response.
Benefits
Full description
JR Recruiting is partnering with one of Chicago's largest mission-driven nonprofit organizations — a human-services institution operating dozens of locations across the region and supporting well over a thousand staff — to hire a Senior Director of Cybersecurity.
This is a hands-on leadership role, and we want to be clear about what that means. You will personally own the organization's security platforms and operations — not direct a large team that does it for you. You'll set direction, run the tooling, lead incident response, and build the metrics leadership takes to the board. You'll report to a technology executive with a deep cybersecurity background who built the current Zero Trust architecture and will be a genuine partner, not just an approver.
If you've spent years as a senior security engineer or security manager and you're ready for the title, the scope, and the seat at the table — without giving up the technical work you're good at — this is that role.
What you'll own
- Administration, monitoring, and continuous improvement
of the security stack: endpoint protection, identity security, cloud security, SIEM/SOAR, and threat detection
- Enterprise vulnerability management, AI-driven
penetration testing, security assessments, and remediation across servers, endpoints, mobile, cloud, and infrastructure
- Hands-on security operations: threat monitoring,
incident response, investigations, cyber-recovery planning, and coordination with managed security providers, auditors, and IR partners
- Partnership with infrastructure, applications, help
desk, data, and business teams to implement controls, meet compliance requirements, and secure new initiatives
- Security metrics, operational dashboards, risk
reporting, and remediation tracking that give leadership and the board real visibility — and a clear case for future investment
- Risk-based recommendations and technical guidance to IT
leadership
The environment
- Microsoft-centered: Azure security services, Microsoft
365 Security, Microsoft Entra ID, Microsoft Defender
- Endpoint and network security platforms including
CrowdStrike and Zscaler
- SIEM, SOAR, EDR, and vulnerability management tooling;
24x7 managed SOC/MDR partnership
- A Zero Trust architecture already in place — you'll
mature it, not build it from zero
- A distributed footprint: many locations, a large and
varied user population, and real-world operational stakes
Who does well here
- A player-coach. You want to lead and you want to
keep your hands on the keyboard. You'd be bored in a pure oversight role.
- Calm under incident. You've run a response, made
decisions with incomplete information, and written the post-mortem.
- A translator. You can explain risk to a CFO and
a board as clearly as you can to an engineer.
- Mission-motivated. You want your work to protect
an organization that serves people who need it. The client is a faith-affiliated nonprofit; candidates of all backgrounds are welcome, and genuine respect for the mission matters.
Requirements
Qualifications
- Bachelor's degree in Cybersecurity, IT, Computer
Science, Information Systems, or related field
- 10+ years of progressive cybersecurity experience,
including 5+ years leading security programs, operations, or teams
- Hands-on depth in vulnerability management, penetration
testing, identity security, cloud security, and incident response
- Direct experience with Microsoft Azure and M365
security, Entra ID, and enterprise EDR/SASE platforms (CrowdStrike and Zscaler experience strongly preferred)
- Experience with SIEM, SOAR, and security monitoring
platforms
- Clear written and verbal communication with technical
and non-technical audiences
Preferred
- Master's degree; experience in nonprofit, healthcare,
social services, or mission-driven organizations
- Experience implementing NIST CSF or CIS Controls;
managing audits, compliance assessments, and third-party risk
- Executive metrics and board-level reporting; AI-driven
security tools and automated penetration testing
- Certifications such as CISM, CCSP, GIAC, Microsoft
Cybersecurity Architect Expert, Azure Security Engineer Associate, CrowdStrike or Zscaler
Benefits
What's offered
- $140,000–$150,000 base salary
- Comprehensive medical, dental, and vision coverage;
employer-paid life and disability insurance
- Paid parental leave; generous PTO, sick time, and 15
paid holidays
- Retirement savings plan; tuition reimbursement and
professional development support
- Hybrid schedule; a stable, well-established
organization; and work that matters
Similar roles
-
Information Security Engineer
MEDITECH Canton, Massachusetts, United States · $66K–$105K/yr
-
Information Security Engineer
RSC2 INC Aberdeen Proving Ground, Maryland, United States · $105K–$245K/yr
-
Cybersecurity Analyst
Saxton & Stump Manheim Township, Pennsylvania, United States
-
Electronic Security Engineer
CertiPath Inc Arlington, Virginia, United States · $110K–$125K/yr
-
Information Systems Security Engineer
Booz Allen Hamilton Warner Robins, Georgia, United States · $99K–$225K/yr
-
Cybersecurity, Engineering, and Technology Implementation Support Engineer
Booz Allen Hamilton North Charleston, South Carolina, United States · $87K–$198K/yr