Security Engineer

JR RecruitingChicago, IL
Hybrid

About The Position

The Security Engineer is the hands-on owner of protecting the trust of individuals and families who rely on a large, well-established nonprofit for human services. This role involves designing, implementing, and operating technical controls to safeguard systems, data, and staff across various locations. The position also focuses on helping a mission-driven, largely non-technical workforce practice good security daily. It is a broad, high-ownership role on a small IT team, offering the opportunity for work with direct human impact.

Requirements

  • 3+ years of hands-on experience in information security, security engineering, or a security-focused systems/network administration role.
  • Working knowledge of Microsoft 365 and Entra ID (Azure AD) security, Windows and endpoint security, and network fundamentals (firewalls, VPN, segmentation, Wi-Fi).
  • Practical experience with at least several of the following: EDR, email security gateways, SIEM/log analysis, vulnerability scanners, MFA/SSO, backup and recovery tools.
  • Experience leading or materially contributing to incident response.
  • Familiarity with HIPAA Security Rule requirements and at least one security framework (NIST CSF, CIS Controls, or ISO 27001).
  • Ability to explain security concepts clearly and patiently to non-technical colleagues and to build cooperative relationships across the organization.
  • Strong documentation habits and the ability to work independently and prioritize in a small-team environment.
  • Bachelor’s degree in computer science, information systems, or a related field, or equivalent practical experience.

Nice To Haves

  • Security certification such as Security+, CySA+, GSEC, CISSP, or a Microsoft security certification (SC-200, SC-300, AZ-500).
  • Experience in a nonprofit, healthcare, social services, or other resource-conscious, compliance-driven environment.
  • Experience securing case-management, EHR, or donor/CRM platforms and working with grant or government-funded program requirements.
  • Scripting ability (PowerShell, Python) for automation and reporting.
  • Experience with PCI DSS scope reduction and payment-processing security.

Responsibilities

  • Own day-to-day security operations: monitor alerts, triage and investigate incidents, lead response and containment, and document root cause and lessons learned.
  • Administer and tune core security tooling, including endpoint detection and response, email security, identity and access management (MFA, SSO, conditional access), vulnerability scanning, and SIEM or log management.
  • Secure the organization's Microsoft 365 / cloud environment, network infrastructure, and endpoints across dozens of distributed program sites.
  • Run the vulnerability and patch management program: scan, prioritize by risk, coordinate remediation with IT and vendors, and track to closure.
  • Design and enforce identity and access controls, including role-based access, least privilege, joiner/mover/leaver processes, and periodic access reviews.
  • Support compliance with applicable regulations (HIPAA, PCI DSS, state data-privacy laws, government-grant security requirements) and prepare evidence for audits and assessments.
  • Assess the security of third-party vendors and SaaS platforms (case management, donor, HR, and financial systems) before and after onboarding.
  • Build and deliver security awareness training and phishing simulations tailored to various staff roles and volunteers.
  • Maintain and test business continuity, disaster recovery, and backup procedures.
  • Write and maintain security policies, standards, and run playbooks; translate policy into practical guidance for staff.
  • Provide security input on new projects, system implementations, and integrations.
  • Track and report security metrics and risk posture to IT leadership and executive leadership/board.

Benefits

  • Medical coverage
  • Dental coverage
  • Vision coverage
  • Retirement plan with employer contribution
  • Generous paid time off
  • Holidays
  • Support for professional development and certifications
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service