Sonoma Consulting Inc. Logo

Sonoma Consulting Inc.

Security Engineer

Posted 7 Days Ago
Be an Early Applicant
In-Office
Glenview, IL, USA
Senior level
In-Office
Glenview, IL, USA
Senior level
Designs, deploys, and maintains information security systems (firewalls, SIEM, IDS/IPS, WAF), performs audits, incident response, vulnerability management and penetration testing, develops access controls and BCP/DR plans, and advises stakeholders on security risks and remediation.
The summary above was generated by AI
Company Description

Sonoma Consulting is one of the fastest growing national IT Consulting and Executive Search company in the United States, which was founded in 2011 by Mark McGee, the President and CEO. Sonoma Consulting has two business divisions - IT Consulting Services & Executive Search to serve its 150 national clients which range from entrepreneurial start-ups to Global Fortune 500.

Job Description

Job Description:

The Senior Information Security Engineer works with members of Information Security, Infrastructure Technology and Business Systems teams to design and manage appropriate security measures for the protection of corporate information assets. The Senior Information Security Engineer is responsible for the complex and detailed technical work necessary to establish and maintain information security systems such as firewalls and intrusion prevention systems. In addition, the Senior Information Security Engineer redesigns and reengineers internal information handling processes so that information is appropriately protected from a wide variety of problems including unauthorized disclosure, unauthorized use, inappropriate modification, premature deletion, and unavailability.

This position occasionally requires some weekend and evening work as well as off-hours for on-call support rotation.

Description:

•The Senior Information Security Engineer's responsibilities include: • Assessing, building, and supporting security solutions and controls including: SEIM, network firewalls, ACLs, IPS, internet content filtering, Identity and Access Management, web application firewalls(WAF), vulnerability scanners, penetration tests, incident response, Active Directory group policies(GPOs), and logical access controls • Researching and deploying new technologies • Performing internal security audits and monitoring systems to ensure that appropriate access levels are maintained • Preparing for and responding to security incidents • Serving as an internal Information Security consultant to the organization • Communicating threats and countermeasures to management and staff to promote security awareness and compliance throughout the organization • Developing and/or maintaining BCP/DR plans for security systems and participating in tests • Collaborating with IS management, legal, human resources and law enforcement agencies to manage security vulnerabilities or investigations

Qualifications

Qualifications: 

 • The idea candidates will have: 

• Strong interpersonal, communication, and leadership skills, including the ability to effectively communicate to both technical and non-technical audiences, in both a one on one as well as in a group environment

• An intimate knowledge of the TCP/IP networking protocol suite 

 • Strong understanding of LAN/WAN technologies; experience configuring FTP services, DNS and SMTP architectures. 

• Experience with network protocol analysis 

• Three or more years of experience in the design and deployment of network security and operating system solutions and information security infrastructure elements such as Firewalls, VPN, DMZ, Security Event Monitoring systems, IDS/IPS, and Directory Services. 

 • Strong understanding of common network and system exploits and vulnerabilities. 

 • Excellent analytical and problem solving skills. Ability to troubleshoot complex networks and design network security solutions

 • A solid understanding and work experience with virtualization technologies and host operating systems, including Windows and Linux 

• Experience with Digital Certificates, SSL, IPSEC, and other encryption technologies. 

 • A strong understanding of authentication and authorization methodologies, including knowledge of network authentication protocols including TACACS and RADIUS. 

 • Experience with scripting languages • Experience with security auditing tools such as COPS, Tripwire, Nessus, etc.

 • BS in a Technology related field or an equivalent work experience 

 The following experience and certifications are a plus: 

• Technical Certifications such as CCNA, CCNP, CCSA, CCSE, SANS GIAC series 

• Professional Certifications such as CISSP • An understanding of application security and OWASP 

• Experience designing and developing security countermeasures for Web and e-commerce environments.

Additional Information

Titles: Security Engineer, Information Security Engineer, Senior Security Engineer, Security Consultant, Security Manager

Skills :Identity and Access Management, web application firewalls(WAF), vulnerability scanners, penetration tests, incident response, Active Directory group policies(GPOs



Similar Jobs

2 Days Ago
Remote or Hybrid
USA
120K-180K Annually
Entry level
120K-180K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Designs and engineers secure network and cloud architectures across AWS, GCP, Azure, and physical data centers. Responsibilities include threat modeling, network segmentation, monitoring, alerting, automation, attack-surface reduction, and secure connection patterns. The role drives strategic security improvements, partners with product and infrastructure teams, communicates architectural decisions, and mentors engineers. Candidates need deep hybrid networking and cloud security expertise, protocol knowledge, scripting ability, independent problem-solving skills, and strong communication.
Top Skills: AIApplied CryptographyAWSAzureCi/CdDnsGCPGoHttp/SHybrid Cloud NetworkingPrivate EndpointsPythonService MeshesShell ScriptingTcp/IpTlsTransit GatewaysVpcsZero Trust Architecture
4 Days Ago
Remote or Hybrid
United States
80K-120K Annually
Mid level
80K-120K Annually
Mid level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Secure LLMs, generative AI systems, ML infrastructure, training pipelines, and AI applications. Responsibilities include threat modeling, architecture reviews, security controls, hardening, vulnerability remediation, data privacy, incident response runbooks, vendor reviews, governance, policy development, and AI security training. The role also supports proof-of-concept security solutions and monitors emerging AI threats.
Top Skills: AnsibleBashETLGdprGenerative AiGoInfrastructure As CodeKubernetesLarge Language ModelsPythonPyTorchScikit-LearnSoc 2TensorFlowTerraform
4 Days Ago
Hybrid
Chicago, IL, USA
110K-140K Annually
Senior level
110K-140K Annually
Senior level
Agency • Gaming • Marketing Tech • Mobile • Analytics
Evaluates and secures AI tools, SaaS applications, marketing technology platforms, integrations, and third-party plugins. Conducts secure code reviews, SAST/DAST testing, threat modeling, architecture assessments, and vendor risk reviews. Develops AI security standards, reference architectures, policies, and playbooks while partnering with engineering, procurement, legal, marketing, and digital teams. Supports compliance with security and privacy requirements and coordinates risk, compliance, and audit initiatives.
Top Skills: Adobe Experience CloudArcherAWSAzureBurp SuiteCheckmarxCi/CdDastGCPGoHubspotJavaScriptOauth 2.0OnetrustPythonRapid7SalesforceSAMLSastScaSemgrepSnykTypescriptZengrc

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account