Security Engineer

Sargent & LundyChicago, IL
$78,016 - $119,191Hybrid

About The Position

Sargent & Lundy is seeking a senior, fully technical, hands-on Security Engineer to translate security requirements into functional controls, tune them, monitor them, and improve them over time. This role is responsible for operating technical security controls and platforms that protect Sargent & Lundy, its clients, and its partners. It is not a security governance, policy-writing, or process management role. The engineer will collaborate with IT Infrastructure, Cloud Engineering, Application teams, SOC, and GRC to enhance the company's security posture, aligning with ISO 27001, NIST 800-171, and CMMC 2, and protecting sensitive data.

Requirements

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
  • 5+ years of hands-on Security Engineering experience with demonstrated ownership of enterprise security platforms in production.
  • Deep, hands-on IAM lifecycle experience with Microsoft Entra (SSO, MFA, conditional access, lifecycle workflows) and applied Zero Trust implementation.
  • Hands-on cloud security experience with Microsoft Azure (required) and Oracle Cloud Infrastructure (strongly preferred), including technical configuration of native security services.
  • Hands-on configuration and operation of the Palo Alto security platform: Prisma (Access and Cloud), Cortex XDR, and XSIAM.
  • Implementation-level experience with Microsoft Purview for DLP, including policy authoring, classification, labeling, tuning, and incident handling.
  • Working knowledge of AI risks (data exposure, prompt injection, model misuse, shadow AI) and the controls used to mitigate them in an enterprise setting.
  • Comfort working across on-prem and cloud environments and across Windows, macOS, and Linux endpoints.
  • Familiarity with compliance frameworks (ISO 27001, NIST 800-171, CMMC Level 2, SOC 2) and the ability to translate a control requirement into a working configuration.
  • Certifications: CompTIA Security+ or (ISC)² SSCP or PCCSE (Palo Alto Networks Certified Cloud Security Engineer) or an equivalent foundational technical certification.

Nice To Haves

  • Microsoft Azure Security certification (AZ-500 or equivalent).
  • Microsoft Purview Information Protection and DLP certification or equivalent.
  • Oracle Cloud Infrastructure security credentials.
  • Microsoft Cybersecurity Architect (SC-100).
  • CISSP or CCSP.

Responsibilities

  • Establish, enforce, and operate the full IAM lifecycle in Microsoft Entra, including SSO, MFA, conditional access, lifecycle workflows, entitlement management, and privileged access integration.
  • Build and tune Zero Trust controls across identity, device, network, and application layers, including conditional access policies and continuous verification.
  • Partner to integrate IAM with the rest of the security stack (XSIAM, CASB, DLP, EDR/XDR) for consistent identity signal.
  • Run technical access reviews and tighten entitlement design.
  • Establish and enforce cloud security controls in Azure and Oracle Cloud Infrastructure, including landing zones, network security groups, identity, key management, encryption, logging, and workload protection.
  • Operate CSPM tooling against Azure and Oracle Cloud, triage findings, and provide secure configurations alongside the cloud engineering team.
  • Partner to build secure-by-default templates for cloud teams.
  • Understand and manage Palo Alto Prisma Access (SASE) for remote users and sites, including tunnels, security policy, SSO integration, and traffic forwarding rules.
  • Understand and partner with SOC to tune Palo Alto XSIAM, including data source onboarding, parser tuning, correlation rules, detection content, and SOAR playbooks.
  • Implement Microsoft Purview at a deep technical level, including Information Protection, DLP, Insider Risk Management, sensitivity labels, and auto-classification.
  • Author and tune DLP policies across endpoint, Outlook and Exchange, Teams, SharePoint, OneDrive, and Egnyte.
  • Handle DLP incident triage, label troubleshooting, and policy iteration.
  • Implement technical controls for safe AI usage, including data-exposure prevention for generative AI tools, prompt and usage monitoring, and integration with DLP and CASB.
  • Evaluate emerging AI risks and design configurations to mitigate them.
  • Partner with product and engineering teams on AI-enabled features to ensure controls are implemented at the right layer.
  • Review the security design of new SaaS, IaaS, PaaS, and in-house applications, producing specific, actionable findings.
  • Work with project teams early in the design phase to ensure controls are built-in, not retrofitted.

Benefits

  • Medical, Dental, Vision
  • Life & Accident Insurance
  • Disability Coverage
  • Employee Assistance Program (EAP)
  • Back-Up Daycare
  • FSA & HSA
  • 401(k)
  • Pre-Tax Commuter Account
  • Merit Scholarship Program
  • Employee Discount Program
  • Corporate Charitable Giving Program
  • Tuition Assistance
  • First Professional Licensure Bonus
  • Employee Referral Bonus
  • Paid Annual Personal/Sick Time (PST)
  • Paid Vacation
  • Paid Holidays
  • Paid Parental Leave
  • Paid Bereavement Leave
  • Flexible Work Arrangements
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service