Sr. Infrastructure Security Engineer
Job Description
The Sr. Infrastructure Security Engineer will strengthen the security posture of on-premises Windows and Active Directory and the Microsoft 365 tenant, while providing hands-on support for core systems administration as needed. The role partners closely with IT Security, networking teams, and IT to prioritize and implement infrastructure and identity security improvements.
Key Responsibilities
- Implement and maintain secure configurations across Windows Server, Active Directory, and Microsoft 365 using CIS benchmarks and industry best practices.
- Conduct regular security posture assessments and remediate identified gaps.
- Lead initiatives including:
- Tiered administration model (Tier 0/1/2)
- Removal of insecure protocols
- LAPS implementation and privileged credential protection
- Perform ongoing Active Directory hygiene and security reviews, including:
- Privileged group membership audits
- AD ACL and delegation reviews
- Service account inventory
- Cleanup of stale objects
- Help implement Privileged Access Management (PAM) and least privilege models.
- Design and maintain Conditional Access policies and MFA enforcement.
- Improve tenant security posture through:
- Secure Score optimization
- Identity protection and sign-in risk policies
- Manage and audit Microsoft 365 identity and access configurations, including:
- App registrations, enterprise apps, and OAuth permissions
- Guest access and external collaboration settings
- Support configuration and tuning of Microsoft Purview DLP, sensitivity labels, and information protection controls in partnership with IT Security and compliance stakeholders.
- Lead infrastructure patching strategy in partnership with system owners, IT Security, and Operations, including Windows Server updates (including emergency CVE patching), hypervisor and firmware updates, and third-party application patching.
- Track and remediate vulnerability scan findings, and coordinate end-of-life remediation for OS, hardware, and platforms.
- Ensure backups are not only successful but recoverable, including restore/recovery testing and DR exercises.
- Validate immutable and air-gapped backup strategies and maintain DR runbooks aligned to RPO/RTO goals.
- Review and respond to infrastructure and identity-related security alerts, escalating to IT Security as appropriate; tune alerts to reduce noise and improve signal.
- Partner with IT Security to investigate infrastructure and identity security events, support containment and remediation, and perform root cause analysis.
- Partner with Network Engineering and IT Security to review firewall rules, identify overly permissive access, and support least-privilege and segmentation-based remediation.
- Reduce endpoint risk through removal of local admin rights and hardening endpoint configurations.
- Define remediation plans with risk-based prioritization and create and maintain security-focused runbooks and procedures.
- Conduct quarterly access reviews and participate in tabletop incident response exercises.
- Help establish repeatable security operational processes, including automation where possible, and maintain operational procedures and practices.
- Act as security subject matter expert for the infrastructure team, providing guidance and hands-on support for secure system builds, patch cycles, and incident remediation, and stepping in during high-demand periods for core sysadmin tasks.
- Support change control processes by performing risk assessments prior to production deployment, defining deployment plans, and coordinating deployments with cross-functional teams.
- Comply with safety and cGMP requirements.
Required Qualifications
- 5+ years in Systems Administration, Infrastructure Engineering, or Security Engineering.
- Strong hands-on experience with:
- Active Directory (security and architecture)
- Microsoft 365 / Entra ID security
- Windows Server administration
- Windows Operating Systems
- Patching and vulnerability remediation related to infrastructure security
- Experience implementing Conditional Access, MFA, and identity security controls.
- Experience implementing system hardening standards such as CIS Benchmarks and DISA STIGs.
- Familiarity with SIEM/logging platforms and vulnerability management tools.
- Familiarity with Backup/DR solutions and the ability to support backup recoverability and DR testing.
- Experience with the Defender suite (Endpoint, Identity, Office).
- Experience with Intune and endpoint security controls.
- Experience with PAM/PIM/JIT access models.
- Experience with Linux/UNIX Operating Systems.
- Experience with PowerShell or other scripting and automation tools.
- Knowledge of networking fundamentals and segmentation strategies.
- Knowledge of hypervisors (VMware, Hyper-V).
- Ability to translate security requirements into practical infrastructure changes.
- Ability to work effectively across IT Security, Infrastructure, Networking, Enterprise Applications, and business teams.
Preferred Qualifications
- Bachelor’s degree (B.A.) in Information Technology, Computer Science, Cybersecurity, or related field (preferred) or an equivalent combination of education, certifications, and experience.
- Relevant certifications such as Security+, CISSP, SSCP, GSEC, AZ-500, SC-300, SC-200, MS-102, or equivalent (preferred but not required).
Additional Skills and Work Style
- Strong verbal and written communication skills to communicate technical information, security risks, and remediation recommendations to both technical and non-technical audiences.
- Ability to read, interpret, apply, and improve technical documentation, procedures, standards, vendor documentation, and system architecture materials.
- Ability to work independently, prioritize competing demands, analyze complex technical and security issues, and recommend practical solutions.
- Sound judgment, strong troubleshooting skills, and the ability to proactively identify risks, process gaps, and improvement opportunities.
- Ability to assist in guiding junior systems administrators and support timely response to security incidents and critical vulnerabilities.
Location and Schedule
- Location: Bloomingdale, IL (onsite)
- Work schedule: Non-standard hours and/or extended work hours can be expected due to user/project requirements, deadlines, system or user issues, and workload backlog.
- Travel: Travel to different work sites may be required.
Compensation
USD 151,000 - 197,000 per year.
Safety Responsibilities
- Supports a culture of safety and follows workplace health and safety procedures.
- Ensures implementation, adherence to, and enforcement of workplace health and safety requirements.
- Ensures activities are completed to promote and enforce safe behaviors by supervisors and employees.
- Ensures injury prevention efforts are effectively implemented.
- Fulfills responsibilities as outlined in the company safety management plan.
Technologies
- Windows Server, Active Directory, Windows Operating Systems
- Microsoft 365, Microsoft Purview DLP, Sensitivity labels, Information protection controls
- Conditional Access, MFA, Entra ID, Secure Score
- Defender suite (Endpoint, Identity, Office)
- Intune
- PAM/PIM/JIT access models, Privileged Access Management (PAM), LAPS
- CIS benchmarks, CIS Controls, NIST Cybersecurity Framework, Microsoft Security Baselines
- ISO/IEC 27001/27002, DISA STIGs
- App registrations, enterprise apps, OAuth permissions, Guest access
- SIEM/logging platforms, vulnerability management tools
- Backup/DR solutions, RPO/RTO goals
- Hypervisors (VMware, Hyper-V)
- PowerShell, Linux/UNIX Operating Systems
- Tier 0/1/2
- Security and identity security runbooks and operational procedures (including DR runbooks)
Education
- Bachelor’s degree (B.A.) in Information Technology, Computer Science, Cybersecurity, or related field (preferred)