Security Engineer, PEG Security Engineering; Information Security, Architecture and Engin
Job in
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-07-06
Listing for:
Bain & Company
Full Time
position Listed on 2026-07-06
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, Security Management & Operations, Systems Engineer
Job Description & How to Apply Below
Staff Security Engineer, PEG Security Engineering (Information Security, Architecture and Engineering)
Job
Work Areas:
Technology & Engineering
Employment Type:
Permanent Full-Time
Location(s):
Boston, Chicago
WHAT YOU'LL DO
Platform Security Engineering and Operations (80%)
- Own and operate the platform’s security posture end-to-end across core controls:
Hashi Corp Vault and/or Azure Key Vault, Istio mTLS, Cilium network policy, Pod Security Standards, and OPA/Gatekeeper policies. - Design and implement zero‑trust security architecture across the estate: defense in depth, least privilege, and explicit security boundary design.
- Conduct lightweight threat modelling (STRIDE) for new services and major features before implementation; document risks, mitigations, and residual risk decisions.
- Manage supply chain security controls: container image scanning, image signing, SBOM generation, and dependency vulnerability management.
- Define and enforce identity and access controls: SAML/OIDC integration patterns, JWT/OAuth concepts, and practical enterprise IdP integration guidance (Okta/Entra).
- Define and maintain data classification controls and enforce them at the platform layer (governed access patterns, masking/tokenization, and API‑layer enforcement).
- Own runtime detection controls: operate Falco rules and escalation pathways; integrate relevant signals with the central SIEM and reduce alert noise to maintain usable signal.
- Lead security incident response for the platform; drive containment, remediation, and post‑incident security reviews with clear follow‑up actions.
- Run regular security reviews of the AI layer:
Agent Gateway egress controls, prompt injection risks, PII handling, and data exfiltration controls for model interactions. - Maintain security runbooks and execute quarterly internal security reviews across teams; ensure controls are tested, auditable, and actively maintained.
Other (20%)
- Embed in select PE squad ceremonies (refinement, planning, design reviews) to catch security concerns early and raise testability/operability requirements for security controls.
- Partner with Platform Engineering on secure‑by‑default templates and guardrails (policy‑as‑code libraries, reusable CI checks, pre‑commit hooks) to reduce repeated effort across squads.
- Collaborate with the Data Governance Lead on PII classification, tokenization policy, and regulatory/compliance requirements (SOC 2 Type II, ISO 27001, GDPR).
- Embed in centralized Application security team to promote secure AI tooling to accelerate threat modelling, security policy drafting, and CVE triage; validate outputs with expert judgement before adoption.
- Communicate security risks in business‑impact terms and prioritize controls that materially reduce risk.
ABOUT YOU
This role follows a hybrid model, requiring in‑office presence at least 1 day per week
- Bachelor’s degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related field (or equivalent practical experience).
- 6+ years of experience in security engineering, infrastructure security, SRE/Dev Ops with a security focus, or platform engineering roles with hands‑on security ownership.
- Demonstrated experience implementing and operating security controls in Kubernetes‑based production environments (policy enforcement, workload isolation, network controls, and runtime detection).
- Experience designing and operating secrets management and identity/access controls (Hashi Corp Vault and/or Azure Key Vault, PKI, OIDC/SAML patterns, enterprise IdP integration).
- Experience implementing supply chain security practices (scanning, signing, SBOMs, dependency management) and integrating controls into CI/CD pipelines.
- Experience leading or materially contributing to security incident response, including post‑incident review and follow‑up remediation planning.
- Demonstrated ability to work cross‑functionally as an enabling partner, raising security standards without blocking delivery unnecessarily.
Security engineering/Platform security
- Zero‑trust security architecture: defense in depth, least privilege, and explicit boundary design across services, networks, and data layers.
- Hashi Corp…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×