{"id":1567252,"url":"https://alion.io/job/sargent-lundy-security-engineer","title":"Security Engineer","company":{"id":2048445,"name":"Sargent & Lundy","domain":"sargentlundy.com","url":"https://alion.io/company/sargentlundy","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"iCIMS","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Chicago, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":78016,"max":119191,"currency":"USD","period":"year","gross":null,"usd_annual":119191},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure","optional":false},{"name":"Cortex XDR","optional":false},{"name":"DLP","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Linux","optional":false},{"name":"NIST 800-171","optional":false},{"name":"OneDrive","optional":false},{"name":"Outlook","optional":false},{"name":"SharePoint","optional":false},{"name":"SOC 2","optional":false},{"name":"Windows","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-10-01T06:10:50Z","employer_posted_date":"2026-10-01","last_verified_at":"2026-10-01T06:10:50Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Responsibilities\nSargent & Lundy is a leading consulting engineering firm specializing in the power and energy sectors. Since 1891, we have provided comprehensive engineering, design, and consulting services for both traditional and renewable power generation, grid modernization, nuclear power, and beyond. Our mission is to help clients achieve their energy goals effectively by leveraging advanced technologies and adopting sustainable practices.\nRole Overview\nWe are looking to hire a senior fully technical, hands-on Security Engineer who can take a security requirement and turn it into a working control, then tune it, monitor it, and improve it over time. You will be responsible for operating the technical security controls and platforms that protect Sargent & Lundy, our clients, and our partners. This is not a security governance, policy-writing, or process management role.\nYou will work side by side with the IT Infrastructure, Cloud Engineering, Application teams, SOC, and GRC. Controls you build will support and enhance our security posture and aligns with ISO 27001, NIST 800-171, and CMMC 2, and protect sensitive data.\nKey Responsibilities\nIdentity and Zero Trust\nEstablish, enforce and operate the full IAM lifecycle in Microsoft Entra: SSO, MFA, conditional access, lifecycle workflows, entitlement management, and privileged access integration. \nBuild and tune Zero Trust controls across identity, device, network, and application layers, including conditional access policies, and continuous verification. \nPartner to integrate IAM with the rest of the security stack so that XSIAM, CASB, DLP, and EDR/XDR all see consistent identity signal. \nRun technical access reviews and tighten entitlement design where you find drift. \nCloud Security: Azure and Oracle Cloud\nEstablish and enforce cloud security controls in Azure and Oracle Cloud Infrastructure: landing zones, network security groups, identity, key management, encryption, logging, and workload protection. \nOperate CSPM tooling against both clouds, triage findings, and provide secure configurations at the cloud resource level alongside the cloud engineering team. \nPartner to build secure-by-default templates so cloud teams can deploy without round-tripping every change through security. \nPalo Alto Security Platform\nUnderstand and manage Prisma Access (SASE) for remote users and sites: tunnels, security policy, SSO integration, and traffic forwarding rules. \nUnderstand and partner with SOC to tune Palo Alto XSIAM, including data source onboarding, parser tuning, correlation rules, detection content, and SOAR playbooks that feed Unit 42. \nData Protection and Microsoft Purview DLP\nImplement Microsoft Purview at a deep technical level: Information Protection, DLP, Insider Risk Management, sensitivity labels, and auto-classification. \nAuthor and tune DLP policies across endpoint, Outlook and Exchange, Teams, SharePoint, OneDrive, and Egnyte. Reduce noise without missing real exposure. \nHandle DLP incident triage, label troubleshooting, and policy iteration based on what production actually shows you. \nAI Usage Security\nImplement technical controls for safe AI usage across the company: data-exposure prevention for generative AI tools, prompt and usage monitoring, and integration with the existing DLP and CASB stack. \nEvaluate emerging AI risks (prompt injection, model abuse, sensitive-data leakage, shadow AI) and design configurations that mitigate them in our environment. \nPartner with product and engineering teams shipping AI-enabled features so the controls land at the right layer. \nArchitecture and Design Reviews\nReview the security design of new SaaS, IaaS, PaaS, and in-house applications and produce specific, actionable findings. \nWork with project teams early so controls are designed in, not retrofitted after go-live. \nThis position offers the flexibility of a hybrid schedule with the expectation of 3 days per week in our downtown Chicago office, and 2 days remote from home.\nQualifications\nRequired Experience\nBachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field. Equivalent professional experience will be considered. \n5+ years of hands-on Security Engineering experience with demonstrated ownership of enterprise security platforms in production. Pure governance, audit, or policy-only backgrounds will not match the work in this role. \nDeep, hands-on IAM lifecycle experience with Microsoft Entra (SSO, MFA, conditional access, lifecycle workflows) and applied Zero Trust implementation. \nHands-on cloud security experience with Microsoft Azure (required) and Oracle Cloud Infrastructure (strongly preferred), including technical configuration of native security services. \nHands-on configuration and operation of the Palo Alto security platform: Prisma (Access and Cloud), Cortex XDR, and XSIAM. \nImplementation-level experience with Microsoft Purview for DLP, including policy authoring, classification, labeling, tuning, and incident handling. \nWorking knowledge of AI risks (data exposure, prompt injection, model misuse, shadow AI) and the controls used to mitigate them in an enterprise setting. \nComfort working across on-prem and cloud environments and across Windows, macOS, and Linux endpoints. \nFamiliarity with compliance frameworks (ISO 27001, NIST 800-171, CMMC Level 2, SOC 2) and the ability to translate a control requirement into a working configuration. \nCertifications: CompTIA Security+ or (ISC)² SSCP or PCCSE (Palo Alto Networks Certified Cloud Security Engineer) an equivalent foundational technical certification.\nPreferred Experience\nMicrosoft Azure Security certification (AZ-500 or equivalent). \nMicrosoft Purview Information Protection and DLP certification or equivalent. \nOracle Cloud Infrastructure security credentials. \nMicrosoft Cybersecurity Architect (SC-100), \nCISSP or CCSP. \nSoft Skills\nStrong written and verbal communication. You can walk an engineer through a config in one conversation and a business stakeholder through the impact in the next. \nBias for action. You would rather build a working control and iterate than spend weeks producing a perfect document. \nComfort with ambiguity. You can take a vague security ask and break it into a concrete configuration plan. \nCollaboration across teams. You will work daily with SOC, IT Infrastructure, Cloud, App Dev, and GRC, and the role only works if those partnerships do. \nOperational discipline. You document what you build, version your configurations, and leave the next engineer better than you found it. \nWe do not sponsor employees for work authorization in the U.S. for this position.\nTechnology & Innovation\nSargent & Lundy values the appropriate use of technology to improve how work gets done and deliver high-quality outcomes for our clients. Depending on the role, employees may use data, automation, artificial intelligence, and other digital tools to support research, analysis, engineering and design activities, workflow improvement, or other aspects of their work. We value candidates who demonstrate an interest in learning and effectively using emerging technologies where relevant to their role. Employees remain accountable for their work and are expected to apply appropriate professional judgment and review when using technology-assisted tools. Experience with AI, automation, programming, or similar technologies is valued where relevant but is not required unless specifically identified elsewhere in the job description.\nAbout Sargent & Lundy\nAt Sargent & Lundy, we care about the health and well-being of our employees. Our commitment extends beyond the workplace, offering comprehensive healthcare plans and generous paid time off to support our team members in every aspect of their lives. We understand the importance of work-life balance, which is why we are proud to provide competitive, award-winning benefits. Our dedication to employee satisfaction has earned us the prestigious Top Workplaces Culture Excellence Award for compensation and benefits in 2022, 2023, and 2024.\nHealth & WellnessFinancial BenefitsWork-Life BalanceHealth Plans: Medical, Dental, Vision\nLife & Accident Insurance\nDisability Coverage\nEmployee Assistance Program (EAP)\nBack-Up Daycare\nFSA & HSA\n401(k)\nPre-Tax Commuter Account\nMerit Scholarship Program\nEmployee Discount Program\nCorporate Charitable Giving Program\nTuition Assistance\nFirst Professional Licensure Bonus\nEmployee Referral Bonus\nPaid Annual Personal/Sick Time (PST)\nPaid Vacation\nPaid Holidays\nPaid Parental Leave\nPaid Bereavement Leave\nFlexible Work Arrangements\nCompensation Range\n$78,016 - $119,191Transparency Statement\nSargent & Lundy discloses compensation ranges that comply with all local and state regulations. The total compensation package for eligible positions will include a base salary or an hourly rate and a comprehensive benefits package, reflecting our commitment to rewarding performance and supporting the overall well-being of our employees. Individuals may also be eligible to participate in our yearly discretionary bonus.Equal Opportunity\nSargent & Lundy is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any protected status as defined by applicable law.","description_format":"text","description_chars":9402,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Flexible schedule","Parental leave"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Energy & Utilities"],"lifecycle":[{"event":"open","at":"2026-10-01T06:10:50Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":24,"reasons":["conf:6","win:early","comp:brand"],"computed_at":"2026-10-01T12:42:28Z"},"pay":{"stated_usd_annual":119191,"is_top_pay":false},"html_url":"https://alion.io/job/sargent-lundy-security-engineer","json_url":"https://alion.io/job/sargent-lundy-security-engineer.json","meta":{"generated_at":"2026-10-01T12:42:28Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4095,"day_limit":5000,"remaining_today":905,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}