×
Register Here to Apply for Jobs or Post Jobs. X

Security Engineer, PEG Security Engineering; Information Security, Architecture and Engin

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Bain & Company
Full Time position
Listed on 2026-07-06
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Security Management & Operations, Systems Engineer
Salary/Wage Range or Industry Benchmark: 141000 - 169250 USD Yearly USD 141000.00 169250.00 YEAR
Job Description & How to Apply Below
Position: Staff Security Engineer, PEG Security Engineering (Information Security, Architecture and Engin[...]

Staff Security Engineer, PEG Security Engineering (Information Security, Architecture and Engineering)

Job

Work Areas:
Technology & Engineering

Employment Type:

Permanent Full-Time

Location(s):
Boston, Chicago

Description & Requirements

WHAT YOU'LL DO

Platform Security Engineering and Operations (80%)

  • Own and operate the platform’s security posture end-to-end across core controls:
    Hashi Corp Vault and/or Azure Key Vault, Istio mTLS, Cilium network policy, Pod Security Standards, and OPA/Gatekeeper policies.
  • Design and implement zero‑trust security architecture across the estate: defense in depth, least privilege, and explicit security boundary design.
  • Conduct lightweight threat modelling (STRIDE) for new services and major features before implementation; document risks, mitigations, and residual risk decisions.
  • Manage supply chain security controls: container image scanning, image signing, SBOM generation, and dependency vulnerability management.
  • Define and enforce identity and access controls: SAML/OIDC integration patterns, JWT/OAuth concepts, and practical enterprise IdP integration guidance (Okta/Entra).
  • Define and maintain data classification controls and enforce them at the platform layer (governed access patterns, masking/tokenization, and API‑layer enforcement).
  • Own runtime detection controls: operate Falco rules and escalation pathways; integrate relevant signals with the central SIEM and reduce alert noise to maintain usable signal.
  • Lead security incident response for the platform; drive containment, remediation, and post‑incident security reviews with clear follow‑up actions.
  • Run regular security reviews of the AI layer:
    Agent Gateway egress controls, prompt injection risks, PII handling, and data exfiltration controls for model interactions.
  • Maintain security runbooks and execute quarterly internal security reviews across teams; ensure controls are tested, auditable, and actively maintained.

Other (20%)

  • Embed in select PE squad ceremonies (refinement, planning, design reviews) to catch security concerns early and raise testability/operability requirements for security controls.
  • Partner with Platform Engineering on secure‑by‑default templates and guardrails (policy‑as‑code libraries, reusable CI checks, pre‑commit hooks) to reduce repeated effort across squads.
  • Collaborate with the Data Governance Lead on PII classification, tokenization policy, and regulatory/compliance requirements (SOC 2 Type II, ISO 27001, GDPR).
  • Embed in centralized Application security team to promote secure AI tooling to accelerate threat modelling, security policy drafting, and CVE triage; validate outputs with expert judgement before adoption.
  • Communicate security risks in business‑impact terms and prioritize controls that materially reduce risk.

ABOUT YOU

This role follows a hybrid model, requiring in‑office presence at least 1 day per week

  • Bachelor’s degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related field (or equivalent practical experience).
  • 6+ years of experience in security engineering, infrastructure security, SRE/Dev Ops with a security focus, or platform engineering roles with hands‑on security ownership.
  • Demonstrated experience implementing and operating security controls in Kubernetes‑based production environments (policy enforcement, workload isolation, network controls, and runtime detection).
  • Experience designing and operating secrets management and identity/access controls (Hashi Corp Vault and/or Azure Key Vault, PKI, OIDC/SAML patterns, enterprise IdP integration).
  • Experience implementing supply chain security practices (scanning, signing, SBOMs, dependency management) and integrating controls into CI/CD pipelines.
  • Experience leading or materially contributing to security incident response, including post‑incident review and follow‑up remediation planning.
  • Demonstrated ability to work cross‑functionally as an enabling partner, raising security standards without blocking delivery unnecessarily.

Security engineering/Platform security

  • Zero‑trust security architecture: defense in depth, least privilege, and explicit boundary design across services, networks, and data layers.
  • Hashi Corp…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary