Cybersecurity Program Lead
Job Description
This role is based in McHenry, IL (hybrid) with a salary range of USD 120,000 to 130,000 per year.
Responsibilities
- Act as the primary incident responder for security events across cloud, endpoint, and network environments.
- Partner with the Rapid7 SOC to validate alerts, tune detections, and streamline response workflows.
- Perform threat hunting and telemetry analysis using SentinelOne and other security platforms.
- Lead containment and remediation efforts in collaboration with Infrastructure, Networking, and Application teams.
- Develop and refine detection logic, response playbooks, and escalation procedures.
- Design and implement security controls for Azure workloads, identity, and cloud-native services.
- Collaborate with Application Development to embed secure coding practices, API security, and threat modeling into the SDLC.
- Set standards for secure use of AI tools, including logging, access controls, and data protection requirements.
- Support security considerations for business application modernization initiatives.
- Evaluate and recommend cloud and application security tools, patterns, and architectures.
- Lead configuration, tuning, and continuous improvement of security technologies including SentinelOne, Microsoft Defender, Purview, Action1, and SIEM integrations.
- Develop and maintain security baselines for servers, endpoints, and cloud resources.
- Ensure endpoint coverage and agent health across the environment, coordinating with the Service Desk for deployment and remediation.
- Implement automation and scripting to enhance security operations and reduce manual effort.
- Own the vulnerability management lifecycle using Rapid7, including scan tuning, prioritization, and reporting.
- Identify and escalate critical vulnerabilities requiring immediate remediation.
- Coordinate with Infrastructure, Networking, and Development teams to track and validate remediation progress.
- Provide actionable guidance to reduce risk across cloud, endpoint, and network environments.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related discipline, or equivalent training/professional experience.
- 5+ years of hands-on experience in cybersecurity engineering, cloud security, application security, or related technical security roles preferred; exceptional candidates with fewer years but strong aptitude or development/security capability will be considered.
- Strong written and verbal communication skills with the ability to collaborate across Infrastructure, Networking, Development, and Legal/Governance teams.
- 3+ years of experience securing cloud environments, preferably Microsoft Azure including Entra ID, Defender, Purview, workload protection, and identity governance.
- Demonstrated experience with application security concepts, including secure coding practices, API security, threat modeling, and direct collaboration with development teams.
- Familiarity with AI/ML security considerations, including data protection, access controls, logging, and responsible use of AI tools in enterprise environments.
- Experience with vulnerability management platforms (Rapid7 preferred), including scan tuning, prioritization, and remediation workflows.
- Strong understanding of identity and access management, authentication technologies, role-based authorization, and zero-trust principles.
- Working knowledge of risk assessment methodologies, threat modeling, and security control frameworks (NIST CSF, CIS Controls, SOC 2).
- Ability to translate business requirements and risks into secure technical solutions and actionable remediation guidance.
- Technical proficiency with endpoint protection, cloud security tools, scripting/automation, and hybrid infrastructure environments.
- Experience collaborating with third-party providers, SOC partners, auditors, or managed service providers.
- Self-driven, highly motivated, and able to manage multiple priorities in a fast-moving environment.
- Strong analytical, troubleshooting, and problem-solving skills with a team-oriented mindset.
- Demonstrated ability to operate as a Lead/IC, owning security engineering, incident response, and cross-functional coordination in a lean IT environment.
- Experience supporting security considerations during business application modernization initiatives.
- On-call availability 24/7 is required.
- AZ 500, AZ 104, CCSK/CCSP, Security+, CySA+, CISSP, or equivalent cloud/security credentials highly preferred.
Technologies
- Rapid7
- SentinelOne
- Microsoft Defender
- Purview
- Action1
- SIEM
- Azure
- Entra ID