×
Register Here to Apply for Jobs or Post Jobs. X

Security Engineer

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Sargent & Lundy LLC.
Part Time position
Listed on 2026-08-13
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant, Cloud Computing: Infrastructure & Operations
Job Description & How to Apply Below
Description

Sargent & Lundy is a leading consulting engineering firm specializing in the power and energy sectors. Since 1891, we have provided comprehensive engineering, design, and consulting services for both traditional and renewable power generation, grid modernization, nuclear power, and beyond. Our mission is to help clients achieve their energy goals effectively by leveraging advanced technologies and adopting sustainable practices.

Role Overview

We are looking to hire a senior fully technical, hands-on Security Engineer who can take a security requirement and turn it into a working control, then tune it, monitor it, and improve it over time. You will be responsible for operating the technical security controls and platforms that protect Sargent & Lundy, our clients, and our partners. This is not a security governance, policy-writing, or process management role.

You will work side by side with the IT Infrastructure, Cloud Engineering, Application teams, SOC, and GRC. Controls you build will support and enhance our security posture and aligns with ISO 27001, NIST 800-171, and CMMC 2, and protect sensitive data.

Key Responsibilities

Identity and Zero Trust
  • Establish, enforce and operate the full IAM lifecycle in Microsoft Entra: SSO, MFA, conditional access, lifecycle workflows, entitlement management, and privileged access integration.
  • Build and tune Zero Trust controls across identity, device, network, and application layers, including conditional access policies, and continuous verification.
  • Partner to integrate IAM with the rest of the security stack so that XSIAM, CASB, DLP, and EDR/XDR all see consistent identity signal.
  • Run technical access reviews and tighten entitlement design where you find drift.
Cloud Security:
Azure and Oracle Cloud
  • Establish and enforce cloud security controls in Azure and Oracle Cloud Infrastructure: landing zones, network security groups, identity, key management, encryption, logging, and workload protection.
  • Operate CSPM tooling against both clouds, triage findings, and provide secure configurations at the cloud resource level alongside the cloud engineering team.
  • Partner to build secure-by-default templates so cloud teams can deploy without round-tripping every change through security.
Palo Alto Security Platform
  • Understand and manage Prisma Access (SASE) for remote users and sites: tunnels, security policy, SSO integration, and traffic forwarding rules.
  • Understand and partner with SOC to tune Palo Alto XSIAM, including data source onboarding, parser tuning, correlation rules, detection content, and SOAR playbooks that feed Unit 42.
Data Protection and Microsoft Purview DLP
  • Implement Microsoft Purview at a deep technical level:
    Information Protection, DLP, Insider Risk Management, sensitivity labels, and auto-classification.
  • Author and tune DLP policies across endpoint, Outlook and Exchange, Teams, SharePoint, One Drive, and Egnyte. Reduce noise without missing real exposure.
  • Handle DLP incident triage, label troubleshooting, and policy iteration based on what production actually shows you.
AI Usage Security
  • Implement technical controls for safe AI usage across the company: data-exposure prevention for generative AI tools, prompt and usage monitoring, and integration with the existing DLP and CASB stack.
  • Evaluate emerging AI risks (prompt injection, model abuse, sensitive-data leakage, shadow AI) and design configurations that mitigate them in our environment.
  • Partner with product and engineering teams shipping AI-enabled features so the controls land at the right layer.
Architecture and Design Reviews
  • Review the security design of new SaaS, IaaS, PaaS, and in-house applications and produce specific, actionable findings.
  • Work with project teams early so controls are designed in, not retrofitted after go-live.
This position offers the flexibility of a hybrid schedule with the expectation of 3 days per week in our downtown Chicago office, and 2 days remote from home.

Qualifications

Required Experience
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field. Equivalent professional experience will be considered.
  • 5+ years of hands-on Security Engineering experience with demonstrated ownership of enterprise security platforms in production. Pure governance, audit, or policy-only backgrounds will not match the work in this role.
  • Deep, hands-on IAM lifecycle experience with Microsoft Entra (SSO, MFA, conditional access, lifecycle workflows) and applied Zero Trust implementation.
  • Hands-on cloud security experience with Microsoft Azure (required) and Oracle Cloud Infrastructure (strongly preferred), including technical configuration of native security services.
  • Hands-on configuration and operation of the Palo Alto security platform:
    Prisma (Access and Cloud), Cortex XDR, and XSIAM.
  • Implementation-level experience with Microsoft Purview for DLP, including policy authoring, classification, labeling, tuning, and incident handling.
  • Working knowledge of AI risks (data exposure,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary