Haystack
← Back to Jobs
Administrative

Baseline Security Configurations Engineer

RKMC Inc.Chicago, IL🇺🇸United StatesPosted 13 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Hybrid role in Chicago with 3 days onsite. Must be local or in neighboring state and must be available for in person interview

  • Security Engineering: Design, implement, and maintain security controls across enterprise infrastructure, endpoints, cloud, SaaS, and application environments. Work with engineering and technology teams to incorporate security requirements into new projects and provide security guidance during design and implementation.
  • Baseline Security Configurations: Develop, maintain, and improve secure baseline configurations for enterprise technologies. Work with technology owners to assess compliance, identify configuration gaps, recommend remediation, manage exceptions, and validate that security controls are properly implemented. Experience with CIS Benchmarks, DISA STIGs, NIST, and other security hardening standards is important.
  • Cloud & SaaS Security: Support security and governance initiatives across AWS, Azure, and SaaS platforms. Review cloud services and configurations against security standards, participate in security assessments, and help secure new cloud and SaaS technologies.
  • Security Tools & Automation: Administer and improve security and configuration management tools, monitor security control effectiveness, and look for opportunities to automate assessments, remediation, and reporting. Experience with PowerShell, Python, Bash, Ansible, or similar scripting technologies is preferred.
  • Risk & Compliance: Partner with security, infrastructure, application, and technology teams to identify and reduce security risks. Support vulnerability management, audits, risk assessments, regulatory requirements, and security compliance activities.
  • Documentation & Communication: Develop security standards, procedures, configuration guidelines, exception documentation, and compliance reports. Ability to communicate security requirements and technical risks clearly to both technical and business stakeholders.
  • Required Background: 5+ years of experience in security engineering, cybersecurity, systems administration, configuration management, or security architecture, with strong knowledge of Windows/Linux security, system hardening, vulnerability management, and security controls. Experience with tools such as Tenable, Qualys, SCCM/Intune, or similar platforms is a plus. Relevant certifications such as Security+, CISSP, CySA+, GIAC, AWS Security, or Azure Security are preferred.

Similar jobs