CybersecurityJobs.io
← Back to all jobs

Job Description

NOW Health Group INC is looking for a Senior Infrastructure Security Engineer to strengthen the security posture of its on-premises Windows and Active Directory environment and the Microsoft 365 tenant. This onsite role in Bloomingdale, IL focuses on practical hardening, identity security improvements, and resilience planning, with close partnership across IT Security, networking, and IT.

Salary: USD 151,000 to 197,000 per year. Experience: 5+ years required.

What you’ll contribute

In this position, you’ll implement and maintain secure configuration standards across key infrastructure and identity platforms, using CIS benchmarks and industry best practices. You’ll also help drive ongoing security posture assessments and remediation, with leadership on initiatives that reduce risk across privileged access, protocol exposure, and account hygiene.

  • Implement and maintain secure configurations across Windows Server, Active Directory, and Microsoft 365 using CIS benchmarks and best practices.
  • Conduct regular security posture assessments and remediate gaps.
  • Lead initiatives including Tier 0/1/2 administration model and removal of insecure protocols.
  • Drive LAPS implementation and privileged credential protection.
  • Perform AD hygiene and security reviews, including privileged group membership audits, AD ACL and delegation reviews, service account inventory, and cleanup of stale objects.
  • Support PAM and least privilege models.
  • Design and maintain Conditional Access policies and MFA enforcement.
  • Improve tenant posture through Secure Score optimization, plus identity protection and sign-in risk policies.
  • Manage and audit app registrations, enterprise apps, and OAuth permissions, including guest access and external collaboration settings.
  • Support configuration and tuning of Microsoft Purview DLP, sensitivity labels, and information protection controls in partnership with IT Security and compliance stakeholders.

Resilience, patching, and security operations

You’ll lead patching and vulnerability remediation across infrastructure and lifecycle boundaries, and help ensure recovery readiness through testing and robust DR practices.

  • Lead infrastructure patching strategy with system owners, IT Security, and Operations, including Windows Server updates (including emergency CVE patching), hypervisor and firmware updates, and third-party application patching.
  • Track and remediate vulnerability scan findings.
  • Coordinate end-of-life remediation (OS, hardware, platforms).
  • Ensure backups are successful and recoverable, including restore/recovery testing and DR exercises.
  • Validate immutable and air-gapped backup strategies.
  • Maintain DR runbooks aligned to RPO/RTO goals.
  • Review and respond to infrastructure and identity security alerts and escalate to IT Security as appropriate.
  • Tune alerts to reduce noise and increase actionable signals.
  • Partner with IT Security to investigate infrastructure and identity-related security events, support containment/remediation, and perform root cause analysis.
  • Partner with Network Engineering and IT Security to review firewall rules, identify overly permissive access, and support remediation using least privilege and segmentation principles.

Security-focused endpoint improvements and process leadership

  • Reduce endpoint risk through removal of local admin rights and hardening endpoint configurations.
  • Define remediation plans with risk-based prioritization.
  • Create and maintain security-focused runbooks and procedures.
  • Conduct quarterly access reviews and participate in tabletop incident response exercises.
  • Help establish repeatable security operational processes, developing automation where possible.
  • Act as the security subject matter expert for the infrastructure team, providing guidance and hands-on support for secure system builds, patch cycles, and incident remediation.
  • Assist with core sysadmin tasks during high-demand periods.

Change management and compliance

  • Support change control processes, including performing risk assessment of changes before production deployment, defining deployment plans, and coordinating deployments with cross-functional teams.
  • Comply with safety and cGMP requirements.

Qualifications

  • 5+ years in Systems Administration, Infrastructure Engineering, or Security Engineering.
  • Bachelor’s degree (B.A.) in Information Technology, Computer Science, Cybersecurity, or related field (preferred).
  • Strong hands-on experience with Active Directory (security & architecture), Microsoft 365 / Entra ID security, and Windows Server administration, plus Windows Operating Systems.
  • Ability to translate security requirements into practical infrastructure changes.
  • Experience implementing Conditional Access, MFA, and identity security controls.
  • Experience implementing system hardening standards such as CIS Benchmarks and DISA STIGs.
  • Familiarity with SIEM/logging platforms and vulnerability management tools.
  • Familiarity with Backup/DR solutions and experience with DR practices and testing.
  • Experience with Defender suite (Endpoint, Identity, Office), Intune, and endpoint security controls.
  • Experience with PAM/PIM/JIT access models.
  • Experience with Linux/UNIX Operating Systems and PowerShell (or other scripting/automation tools).
  • Knowledge of networking fundamentals and segmentation strategies; familiarity with hypervisors (VMware, Hyper-V).
  • Strong problem determination, organizational, and troubleshooting skills; ability to work effectively as part of a team and across IT Security, Infrastructure, Networking, Enterprise Applications, and business teams.
  • Communication skills to explain technical information, security risks, and remediation recommendations to both technical and non-technical audiences.
  • Must be able to read, interpret, apply, and improve technical documentation, procedures, standards, vendor documentation, and system architecture materials.
  • Preferred certifications include Security+, CISSP, SSCP, GSEC, AZ-500, SC-300, SC-200, MS-102, or equivalent.

Work requirements and environment

  • Non-standard hours and/or extended work hours may be expected due to user/project requirements, deadlines, system or user issues, and workload backlog.
  • Regularly required to remain at a stationary work location; occasionally to move within the work facility.
  • Regularly required to use the telephone and computer, and required to travel to different work sites.

Similar Jobs