What are the responsibilities and job description for the Security Engineer - Hybrid in Chicago, IL (Must be local to chicago as there will be a in-person interview) position at TrustMinds, Inc.?
Interview Process - Video interview follwed by in-person interview
Must be local to Chicago, IL and go for final in-person interview
Job Description: Key Responsibilities
Security Engineering & Architecture Design, implement, and maintain technical security controls across infrastructure, cloud, SaaS, and endpoint platforms.
Evaluate emerging technologies, security capabilities, and vendor solutions.
Provide security consultation and design reviews for new projects and technology initiatives.
Collaborate with engineering teams to integrate security requirements into technology deployments.
Baseline Security Configuration (BSC) Program
Develop, maintain, and improve Baseline Security Configurations for enterprise technologies.
Partner with technology owners to assess compliance and remediate gaps.
Support control selection, implementation guidance, exception management, and validation activities.
Track remediation efforts and provide reporting on compliance posture.
Cloud & SaaS Security
Support security controls and governance within AWS, Microsoft Azure, and SaaS platforms.
Assess cloud services against security standards and best practices.
Participate in cloud security initiatives, security monitoring, and compliance assessments.
Assist with onboarding and securing new cloud and SaaS technologies.
Security Operations & Tool Administration
Administer and improve enterprise security tools and platforms.
Develop automation and operational efficiencies to enhance security processes.
Monitor security control effectiveness and identify improvement opportunities.
Assist with troubleshooting and resolving security-related technical issues.
Risk, Governance & CollaborationPartner with first, second, and third line teams to identify and reduce security risk.
Contribute to security standards, procedures, and technical documentation.
Support audits, risk assessments, and regulatory compliance activities.
Communicate technical security concepts clearly to both technical and non-technical audiences.