Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
NH
Now Health Group, Inc.
SR INFRASTRUCTURE SECURITY ENGINEER
Career Insights for Cyber Security Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Illinois data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.
$109,450 / year median in Illinois
+8% projected growth
Job Description
ESSENTIAL DUTIES AND RESPONSIBILITIES
include but are not limited to the following. Security & Hardening (Primary Focus) Implement and maintain secure configurations across Windows Server, Active Directory, and Microsoft 365 using CIS benchmarks and industry best practices. Perform regular security posture assessments and remediate gaps. Lead initiatives such as, but not limited to: Tiered administration model (Tier 0/1/2) Removal of insecure protocols LAPS implementation and privileged credential protection Identity & Active Directory SecuritConduct ongoing AD hygiene and security reviews, including: Privileged group membership audits AD ACL and delegation reviews Service account inventory Cleanup of stale objects Help implement Privileged Access Management (PAM) and least privilege models. Microsoft 365 / Entra ID Security Design and maintain Conditional Access policies and MFA enforcement.Improve tenant posture through:
Secure Score optimization Identity protection and sign-in risk policies.Manage and audit:
App registrations, enterprise apps, and OAuth permissions. Guest access and external collaboration settings. Support configuration and tuning of Microsoft Purview DLP, sensitivity labels, and information protection controls in partnership with IT Security and compliance stakeholders. Patching, Vulnerability, & Lifecycle Management Lead infrastructure patching strategy in partnership with system owners, IT Security, and Operations teams, including: Windows Server updates (including emergency CVE patching) Hypervisor and firmware updates Third-party application patching Track and remediate vulnerability scan findings. Coordinate end-of-life remediation (OS, hardware, platforms). Backup, Recovery, & Resilience Ensure backups are not only successful, but recoverable. Lead restore/recovery testing and DR exercises. Validate immutable and air-gapped backup strategies. Maintain and improve DR runbooks aligned to RPO/RTO goals. Monitoring, Detection & Response Review and respond to infrastructure and identity-related security alerts, escalating to IT Security as appropriate. Tune alerts to reduce noise and increase actionable signals. Partner with IT Security team to investigate infrastructure and identity-related security. events, support containment/remediation actions, and perform root cause analysis. Endpoint & Network Security Partner with Network Engineering and IT Security to review firewall rules, identify overly permissive access, and support remediation based on least privilege and segmentation principles.Reduce endpoint risk:
Removal of local admin rights Hardening endpoint configurations Documentation & Process Improvement Define remediation plans with risk-based prioritization. Create and maintain security-focused runbooks and procedures. Conduct quarterly access reviews and participate in tabletop incident response exercises. Help establish repeatable security operational processes, developing automation where possible. Establishes and maintains operational procedures and practices. Collaboration with System Admin Team Act as the security subject matter expert for the infrastructure team. Provide guidance and hands-on support for: Secure system builds Patch cycles Incident remediation Step in to assist with core sysadmin tasks during high-demand periods. Change Management Support change control processes, perform risk assessment of changes before deploying to production, define deployment plans, and coordinate deployments with cross-functional teams. Complies with safety and cGMP requirements.SAFETY RESPONSIBILITY STATEMENT
Supports a culture of safety; follows all workplace health and safety procedures. Responsible for safety performance in respective area. Ensures the implementation of, adherence to, and enforcement of workplace health and safety requirements. Ensures activities are completed to promote and enforce safe behaviors by supervisors and employees. Ensures injury prevention efforts are effectively implemented. Fulfills responsibilities as outlined in the company safety management plan.QUALIFICATIONS
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions.- 5+ years in Systems Administration, Infrastructure Engineering, or Security Engineering.
- Relevant certifications such as Security+, CISSP, SSCP, GSEC, AZ-500, SC-300, SC-200, MS-102, or equivalent are preferred but not required.
- Working knowledge of security frameworks and hardening standards such as NIST Cybersecurity Framework, CIS Controls, CIS Benchmarks, Microsoft Security Baselines, and ISO/IEC 27001/27002, with the ability to translate control requirements into practical infrastructure and identity security improvements.
- Experience reviewing and remediating security findings from vulnerability scans, audits, or assessments
- Strong problem determination skills are required.
- Good organizational skills are required.
- Ability to work as an effective team member is a must.
Strong hands-on experience with:
o Active Directory (security & architecture) o Microsoft 365 / Entra ID security o Windows Server administration o Windows Operating Systems- Ability to translate security requirements into practical infrastructure changes.