Haystack
← Back to Jobs
Technology
DO

Senior Security Engineer

dotSolvedNaperville, IL🇺🇸United StatesPosted 3 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Naperville, IL, United States
Posted
23 hours ago
AWSMFASOC 2AzureGDPRGoogle CloudHIPAAWAF

Job Description

Job Title: Senior Security Engineer

Location: Naperville, IL (Hybrid)

Employment Type: Contract

Client: Direct Client

Key Responsibilities

Strategic Leadership & Cyber Defense

  • Security Strategy & Architecture: Define, execute, and govern comprehensive information security programs across hybrid infrastructures (on-premises, multi-cloud AWS/Azure/Google Cloud Platform, and Linux/Windows environments).
  • Security Operations Center (SOC) Management: Oversee modern threat detection, vulnerability management, and automated response capabilities utilizing advanced XDR, EDR, NDR, SIEM, and SOAR platforms.
  • Incident Response & Crisis Management: Serve as the ultimate authority for enterprise crisis management, guiding rapid response, mitigation, and forensic investigations during critical security events to maximize resilience.

Risk Management, Governance & Compliance

  • Enterprise Risk Quantification: Build and scale a formalized cyber risk management program, leveraging threat modeling (such as STRIDE) and maintaining active enterprise risk registers.
  • Executive & Board Reporting: Establish executive reporting frameworks and board-level risk dashboards to provide real-time visibility into the organization s threat posture and prioritize security investments.
  • Regulatory Compliance: Guarantee continuous audit readiness and compliance across critical frameworks such as ISO 27001, SOC 2, NYDFS, NIST 800-53, GDPR, FFIEC, HIPAA, and SOX.
  • Vendor & 3rd-Party Risk Management: Oversee vendor governance frameworks, evaluating third-party risk profiles and establishing strict operational guidelines with Managed Security Service Providers (MSSPs).

Cross-Functional Integration & Culture

  • DevSecOps & Application Security: Partner with engineering and product teams to integrate automated application security assessments (SAST, DAST, SCA, CSPM) and threat modeling directly into product development pipelines.
  • Identity & Access Governance: Direct the enforcement of zero-trust Identity and Access Management (IAM) best practices, secure directory services (Azure AD), data classification, and multi-factor authentication (MFA).
  • Security Culture: Champion organization-wide cybersecurity awareness programs and continuous phishing simulations to foster a security-first culture across all global business units.

Required Skills & Qualifications

Technical Capabilities & Tooling Expertise

  • Security Platforms: Extensive experience deploying and managing industry-standard endpoint, cloud, and scanning platforms (e.g., CrowdStrike, Microsoft Defender, Qualys, Snyk).
  • Network & Cloud Security: Strong understanding of secure network architecture, including SD-WAN, Web Application Firewalls (WAF), secure edge solutions, and cloud-native perimeter controls (e.g., AWS Advanced Shield).
  • Infrastructure Depth: Solid grasp of infrastructure vulnerabilities across cloud infrastructure, enterprise email environments, identity providers, and critical operational technologies (OT/ICS) if applicable.

Leadership & Experience

  • Experience: 15+ years of progressive experience in cybersecurity, cloud security, or IT risk management, with at least 5+ years in a senior leadership or CISO advisory capacity managing large global security teams.
  • Communication: Elite communication skills with a proven ability to discuss technical architecture with engineers and abstract risk metrics for executive leadership and corporate boards.
  • Education: Bachelor s or master s degree in computer science, Cybersecurity, Information Technology, Engineering, or a related field.
  • Certifications: Active Certified Information Systems Security Professional (CISSP) designation is strictly required. Certified Information Security Manager (CISM) or CISA is highly desirable

Similar jobs