SR INFRASTRUCTURE SECURITY ENGINEER

Now FoodsBloomingdale, IL
$121,500 - $152,000

About The Position

This role focuses on implementing and maintaining secure configurations across Windows Server, Active Directory, and Microsoft 365, utilizing CIS benchmarks and industry best practices. The position involves leading initiatives such as tiered administration models, removal of insecure protocols, and LAPS implementation. Key responsibilities include conducting AD hygiene and security reviews, designing and maintaining Microsoft 365/Entra ID security policies, managing patching and vulnerability remediation, ensuring backup recoverability and DR readiness, responding to security alerts, and collaborating with various IT teams to reduce endpoint and network risk. The role also involves documentation, process improvement, acting as a security subject matter expert for the infrastructure team, and supporting change management processes.

Requirements

  • 5+ years in Systems Administration, Infrastructure Engineering, or Security Engineering.
  • Working knowledge of security frameworks and hardening standards such as NIST Cybersecurity Framework, CIS Controls, CIS Benchmarks, Microsoft Security Baselines, and ISO/IEC 27001/27002, with the ability to translate control requirements into practical infrastructure and identity security improvements.
  • Experience reviewing and remediating security findings from vulnerability scans, audits, or assessments
  • Strong problem determination skills are required.
  • Good organizational skills are required.
  • Ability to work as an effective team member is a must.
  • Strong hands-on experience with Active Directory (security & architecture)
  • Strong hands-on experience with Microsoft 365 / Entra ID security
  • Strong hands-on experience with Windows Server administration
  • Strong hands-on experience with Windows Operating Systems
  • Ability to translate security requirements into practical infrastructure changes.
  • Experience implementing Conditional Access, MFA, identity security controls
  • Experience implementing System hardening standards (CIS Benchmarks, DISA STIGs)
  • Ability to work effectively across IT Security, Infrastructure, Networking, Enterprise Applications, and business teams.
  • Bachelor’s degree (B.A.) in Information Technology, Computer Science, Cybersecurity, or related field preferred; or equivalent combination of education, certifications, and experience.
  • Minimum of 5–7 years of related experience in systems administration, infrastructure engineering, cybersecurity, or similar role.
  • Strong hands-on experience with Windows Server, Active Directory, Microsoft 365, Entra ID, patching, vulnerability remediation, and infrastructure security is required.
  • Must possess strong verbal and written communication skills, with the ability to clearly communicate technical information, security risks, and remediation recommendations to technical and non-technical audiences.
  • Must be able to read, interpret, apply, and improve technical documentation, procedures, standards, vendor documentation, and system architecture materials.
  • Must be able to work independently, prioritize competing demands, analyze complex technical and security issues, and recommend practical solutions.
  • Must demonstrate sound judgment, strong troubleshooting skills, and the ability to proactively identify risks, process gaps, and improvement opportunities.
  • Must be able to assist in guiding junior systems administrators and support timely response to security incidents and critical vulnerabilities.

Nice To Haves

  • Relevant certifications such as Security+, CISSP, SSCP, GSEC, AZ-500, SC-300, SC-200, MS-102, or equivalent are preferred but not required.
  • Familiarity with SIEM/logging platforms
  • Familiarity with Vulnerability management tools
  • Familiarity with Backup/DR solutions
  • Experience with Defender suite (Endpoint, Identity, Office)
  • Experience with Intune and endpoint security controls
  • Experience with PAM/PIM/JIT access models
  • Experience with Linux/UNIX Operating Systems
  • Experience with PowerShell or other scripting/automation tools
  • Knowledge of Networking fundamentals and segmentation strategies
  • Knowledge of Hypervisors (VMware, Hyper-V)
  • Relevant security or Microsoft certifications are preferred.

Responsibilities

  • Implement and maintain secure configurations across Windows Server, Active Directory, and Microsoft 365 using CIS benchmarks and industry best practices.
  • Perform regular security posture assessments and remediate gaps.
  • Lead initiatives such as tiered administration model (Tier 0/1/2), removal of insecure protocols, and LAPS implementation and privileged credential protection.
  • Conduct ongoing AD hygiene and security reviews, including privileged group membership audits, AD ACL and delegation reviews, service account inventory, and cleanup of stale objects.
  • Help implement Privileged Access Management (PAM) and least privilege models.
  • Design and maintain Conditional Access policies and MFA enforcement in Microsoft 365 / Entra ID.
  • Improve tenant posture through Secure Score optimization, identity protection and sign-in risk policies.
  • Manage and audit App registrations, enterprise apps, and OAuth permissions.
  • Manage and audit guest access and external collaboration settings.
  • Support configuration and tuning of Microsoft Purview DLP, sensitivity labels, and information protection controls.
  • Lead infrastructure patching strategy, including Windows Server updates, hypervisor and firmware updates, and third-party application patching.
  • Track and remediate vulnerability scan findings.
  • Coordinate end-of-life remediation for OS, hardware, and platforms.
  • Ensure backups are successful and recoverable.
  • Lead restore/recovery testing and DR exercises.
  • Validate immutable and air-gapped backup strategies.
  • Maintain and improve DR runbooks aligned to RPO/RTO goals.
  • Review and respond to infrastructure and identity-related security alerts.
  • Tune alerts to reduce noise and increase actionable signals.
  • Partner with IT Security team to investigate infrastructure and identity-related security events, support containment/remediation actions, and perform root cause analysis.
  • Partner with Network Engineering and IT Security to review firewall rules, identify overly permissive access, and support remediation based on least privilege and segmentation principles.
  • Reduce endpoint risk by removing local admin rights and hardening endpoint configurations.
  • Define remediation plans with risk-based prioritization.
  • Create and maintain security-focused runbooks and procedures.
  • Conduct quarterly access reviews and participate in tabletop incident response exercises.
  • Help establish repeatable security operational processes, developing automation where possible.
  • Establishes and maintains operational procedures and practices.
  • Act as the security subject matter expert for the infrastructure team.
  • Provide guidance and hands-on support for secure system builds, patch cycles, and incident remediation.
  • Step in to assist with core sysadmin tasks during high-demand periods.
  • Support change control processes, perform risk assessment of changes before deploying to production, define deployment plans, and coordinate deployments with cross-functional teams.
  • Complies with safety and cGMP requirements.

Benefits

  • Supports a culture of safety; follows all workplace health and safety procedures.
  • Responsible for safety performance in respective area.
  • Ensures the implementation of, adherence to, and enforcement of workplace health and safety requirements.
  • Ensures activities are completed to promote and enforce safe behaviors by supervisors and employees.
  • Ensures injury prevention efforts are effectively implemented.
  • Fulfills responsibilities as outlined in the company safety management plan.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service