SR INFRASTRUCTURE SECURITY ENGINEER
Now Foods · Bloomingdale, IL · 1 wk ago
Information TechnologyFull-time
Responsibilities
- Implement and maintain secure configurations across Windows Server, Active Directory, and Microsoft 365 using CIS benchmarks and industry best practices.
- Perform regular security posture assessments and remediate gaps.
- Lead security initiatives including:
- Tiered administration model (Tier 0/1/2)
- Removal of insecure protocols
- LAPS implementation and privileged credential protection
- Conduct ongoing Active Directory hygiene and security reviews:
- Privileged group membership audits
- AD ACL and delegation reviews
- Service account inventory
- Cleanup of stale objects
- Help implement Privileged Access Management (PAM) and least privilege models.
- Design and maintain Microsoft 365 / Entra ID security:
- Conditional Access policies and MFA enforcement
- Secure Score optimization
- Identity protection and sign-in risk policies
- Management and audit of app registrations, enterprise apps, and OAuth permissions
- Guest access and external collaboration settings
- Support configuration and tuning of Microsoft Purview DLP, sensitivity labels, and information protection controls.
- Lead infrastructure patching strategy, including:
- Windows Server updates (including emergency CVE patching)
- Hypervisor and firmware updates
- Third-party application patching
- Track and remediate vulnerability scan findings.
- Coordinate end-of-life remediation (OS, hardware, platforms).
- Ensure backups are successful and recoverable; lead restore/recovery testing and DR exercises.
- Validate immutable and air-gapped backup strategies.
- Maintain and improve DR runbooks aligned to RPO/RTO goals.
- Review and respond to infrastructure and identity-related security alerts; escalate to IT Security as appropriate.
- Tune alerts to reduce noise and increase actionable signals.
- Partner with IT Security team to investigate security events, support containment/remediation, and perform root cause analysis.
- Partner with Network Engineering and IT Security to review firewall rules, identify overly permissive access, and support remediation based on least privilege and segmentation principles.
- Reduce endpoint risk through:
- Removal of local admin rights
- Hardening endpoint configurations
- Define remediation plans with risk-based prioritization.
- Create and maintain security-focused runbooks and procedures.
- Conduct quarterly access reviews and participate in tabletop incident response exercises.
- Establish repeatable security operational processes, developing automation where possible.
- Act as the security subject matter expert for the infrastructure team; provide guidance and hands-on support for secure system builds, patch cycles, and incident remediation.
- Support change control processes, perform risk assessment of changes, define deployment plans, and coordinate deployments with cross-functional teams.
- Support a culture of safety; follow workplace health and safety procedures and ensure adherence to safety requirements.
Requirements
- 5+ years in Systems Administration, Infrastructure Engineering, or Security Engineering.
- Relevant certifications such as Security+, CISSP, SSCP, GSEC, AZ-500, SC-300, SC-200, MS-102, or equivalent are preferred but not required.
- Working knowledge of security frameworks and hardening standards such as NIST Cybersecurity Framework, CIS Controls, CIS Benchmarks, Microsoft Security Baselines, and ISO/IEC 27001/27002.
- Experience reviewing and remediating security findings from vulnerability scans, audits, or assessments.
- Strong problem determination and organizational skills.
- Ability to work effectively as a team member.
- Strong hands-on experience with:
- Active Directory (security & architecture)
- Microsoft 365 / Entra ID security
- Windows Server administration
- Windows Operating Systems
- Ability to translate security requirements into practical infrastructure changes.
- Experience implementing Conditional Access, MFA, identity security controls, and system hardening standards (CIS Benchmarks, DISA STIGs).
- Familiarity with SIEM/logging platforms, vulnerability management tools, and backup/DR solutions.
- Experience with Defender suite (Endpoint, Identity, Office), Intune, endpoint security controls, and PAM/PIM/JIT access models.
- Knowledge of Linux/UNIX Operating Systems, PowerShell or other scripting/automation tools.
- Knowledge of networking fundamentals, segmentation strategies, and hypervisors (VMware, Hyper-V).
- Ability to work effectively across IT Security, Infrastructure, Networking, Enterprise Applications, and business teams.
Qualifications
- Bachelor’s degree (B.A.) in Information Technology, Computer Science, Cybersecurity, or related field preferred; or equivalent combination of education, certifications, and experience.
- Minimum of 5–7 years of related experience in systems administration, infrastructure engineering, cybersecurity, or similar role.
- Strong hands-on experience with Windows Server, Active Directory, Microsoft 365, Entra ID, patching, vulnerability remediation, and infrastructure security is required.
- Relevant security or Microsoft certifications are preferred.
- Strong verbal and written communication skills, with the ability to clearly communicate technical information, security risks, and remediation recommendations to technical and non-technical audiences.
- Ability to read, interpret, apply, and improve technical documentation, procedures, standards, vendor documentation, and system architecture materials.
- Ability to work independently, prioritize competing demands, analyze complex technical and security issues, and recommend practical solutions.
- Sound judgment, strong troubleshooting skills, and the ability to proactively identify risks, process gaps, and improvement opportunities.
- Ability to assist in guiding junior systems administrators and support timely response to security incidents and critical vulnerabilities.
Schedule
Non-standard hours and/or extended work hours can be expected due to user/project requirements, deadlines, system or user issues, and workload backlog.