Staff Security Engineer, PEG Security Engineering (Information Security, Architecture and Engineering)
Senior
Api Security
Azure
Cloud
Cloud Platform
Cloud Platforms
Cloud Security Posture Management
Cybersecurity Tools
Data Security
DevOps
DevSecOps
Engineering
Identity and Access Management
Incident Response
Information Security
InfoSec
Platform Engineering
Policy As Code
Risk Governance
Risk Management
Security
Security As Code
Security Automation
Security Standards
Solution Architecture
Supply Chain Security
Zero Trust Architecture
Job Description
Bain & Co offers a collaborative, impact-driven environment with a strong focus on practical security outcomes. Employees enjoy comprehensive benefits, generous paid time off, and a path that blends rigorous security work with fast, delivery-focused engineering. This role is based in Chicago, IL with hybrid work options.
As a Staff Security Engineer in the PEG Security Engineering team, you will secure Bain’s PE platform estate on Azure AKS, embed security into the development lifecycle, define security standards and controls, and lead platform security engineering and incident response across cross-functional teams.
Responsibilities
- Own and operate the platform's security posture end to end across core controls including HashiCorp Vault or Azure Key Vault, Istio mTLS, Cilium network policy, Pod Security Standards, and OPA/Gatekeeper policies.
- Design and implement zero trust security architecture across the estate with defense in depth, least privilege, and explicit security boundary design.
- Perform lightweight threat modelling (STRIDE) for new services and major features prior to implementation; document risks, mitigations, and residual risk decisions.
- Manage supply chain security controls such as container image scanning, image signing, SBOM generation, and dependency vulnerability management.
- Define and enforce identity and access controls including SAML/OIDC integration patterns, JWT/OAuth concepts, and enterprise IdP guidance (Okta/Entra).
- Define and maintain data classification controls and enforce them at the platform layer through governed access patterns, masking/tokenization, and API-layer enforcement.
- Own runtime detection controls by operating Falco rules and escalation pathways; integrate signals with the central SIEM and minimize alert noise while preserving actionable insight.
- Lead security incident response for the platform, driving containment, remediation, and post-incident reviews with clear follow-up actions.
- Conduct regular security reviews of the AI layer, including Agent Gateway egress controls, prompt injection risks, PII handling, and data exfiltration controls for model interactions.
- Maintain security runbooks and execute quarterly internal security reviews across teams; ensure controls are tested, auditable, and actively maintained.
- Set and enforce security standards, build controls as code, and partner with Platform Engineering, Data Platform, Product Engineering, and the Agent / AI squad to reduce risk while enabling rapid delivery.
Requirements
- Bachelor’s degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related field, or equivalent practical experience.
- 6+ years of experience in security engineering, infrastructure security, SRE/DevOps with a security focus, or platform engineering roles with hands-on security ownership.
- Proven experience implementing and operating security controls in Kubernetes-based production environments (policy enforcement, workload isolation, network controls, and runtime detection).
- Experience designing and operating secrets management and identity/access controls (HashiCorp Vault and/or Azure Key Vault, PKI, OIDC/SAML patterns, enterprise IdP integration).
- Experience implementing supply chain security practices (scanning, signing, SBOMs, dependency management) and integrating controls into CI/CD pipelines.
- Experience leading or materially contributing to security incident response, including post-incident review and remediation planning.
- Demonstrated ability to work cross-functionally as an enabling partner, raising security standards without unnecessarily blocking delivery.
Technologies
- HashiCorp Vault, Azure Key Vault
- Istio, Cilium, Pod Security Standards, OPA, Gatekeeper
- Falco, Kubernetes, AKS
- SAML 2.0, OIDC, JWT, OAuth
- Okta, Entra, Azure AD
- Kyverno, Rego, Trivy, Cosign, Sigstore, Syft, Dependabot, Renovate
- Python, Bash
Benefits
- Bain pays 100% individual employee premiums for medical, dental and vision programs
- Generous paid time off, including parental leave, sick leave and paid holidays
- Fully vested 401(k) company contribution
- Paid Life and Long-Term Disability insurance
- Annual fitness reimbursements
Compensation and location
Location: Chicago, IL (hybrid)
Salary: USD 141,000 - 176,750 per year
Compensation by location
- Chicago, IL: $141,000 - $169,250
- Boston, MA: $147,250 - $176,750