Sr.Manager, Information Security Engineer
Manager
Senior
Application Security
Cloud Platforms
Cybersecurity Tools
Data Security
DevSecOps
Engineer
Identity and Access Management
Information Security
InfoSec
Management
Security Architecture
Security Automation
Security Compliance
Security Standards
Security Standards And Frameworks
Solution Architecture
Job Description
The Federal Home Loan Bank of Chicago is seeking a senior security engineering leader to guide the design, engineering, implementation, and ongoing lifecycle management of technical security controls across the Bank’s environment. This hybrid role in Chicago supports the protection of systems, identities, applications, data, cloud services, and customer-facing capabilities while aligning engineering priorities to established standards, risk expectations, and regulatory needs.
As Senior Manager, Information Security Engineering, you will connect technical execution to the NIST Cybersecurity Framework (CSF), Bank policy, risk appetite, architecture standards, and measurable outcomes.
What you’ll do
- Lead the end-to-end engineering of technical security controls that safeguard systems, identities, applications, data, cloud services, and customer-facing capabilities.
- Manage a blended team of employees and contractors, set engineering priorities and standards, and convert security requirements into scalable and supportable solutions.
- Align the security tool portfolio and engineering roadmap to NIST CSF, Bank policy, risk appetite, architecture standards, and applicable regulatory expectations.
- Build and maintain a defense-in-depth control environment spanning on-premises and cloud platforms including AWS and Microsoft Azure, along with SaaS, endpoint, network, identity, application, and data platforms.
- Translate cybersecurity risk, policy, and architecture requirements into practical technical controls, engineering patterns, automation, and operational guardrails.
- Improve control effectiveness, reliability, coverage, and transparency using disciplined engineering practices and outcome-oriented metrics.
- Develop security engineering talent by setting clear accountability across employees, contractors, vendors, and technology partners.
- Drive risk reduction and regulatory readiness through modern capabilities, automation, and governance aligned with industry and regulatory standards.
- Own security engineering strategy and execution, including a multi-year roadmap, backlog, budget inputs, workforce plan, vendor relationships, and delivery commitments.
- Maintain traceability from risks and requirements to control design, implementation, evidence, ownership, and measurement aligned to NIST CSF functions and categories.
- Partner with teams across Security Architecture, Security Operations, Threat and Incident Response, Identity and Access Management, Security Advisory and Analytics, IT Risk and Compliance, Enterprise Architecture, Infrastructure, Cloud, Network, and Application.
- Support incidents, investigations, vulnerability remediation, audit findings, risk acceptances, and penetration testing by coordinating engineering analysis and corrective actions.
- Provide engineering leadership across security technologies covering endpoint and workload protection, identity and privileged access, cloud security, network security, monitoring and logging, data protection, vulnerability management, application security, and security automation.
- Direct security engineering for AWS and Microsoft Azure, including secure configuration baselines, native security services, identity and access controls, logging and monitoring, encryption and key management, network segmentation, and automated policy enforcement.
- Establish standards for security tool selection, configuration, integration, lifecycle management, resilience, supportability, and decommissioning, including overlap and gap identification.
- Define engineering quality practices such as peer review, change control, infrastructure as code, testing, documentation, release readiness, rollback planning, and handoff to operational support.
- Create metrics and dashboards to measure control coverage, control health and effectiveness, engineering delivery, reliability, automation, technical debt, risk reduction, and service performance.
- Provide concise reporting to security and technology leadership on roadmap progress, risks, exceptions, dependencies, constraints, control performance, and recommended decisions.
- Escalate and support complex security control and tooling decisions, including coordination of off-hours support when required for critical incidents or significant production changes.
- Perform other duties as assigned.
How success will be measured
- Improved security-control coverage, health, effectiveness, reliability, and evidence quality.
- Timely delivery of prioritized engineering roadmap commitments and sustainable remediation of material risks and findings.
- Reduced manual effort, repeated incidents, tool overlap, unsupported configurations, and security technical debt through standardization and automation.
- Clear NIST CSF traceability for the security engineering portfolio and technical controls.
- Actionable metrics that support risk-based decisions and demonstrate security and operational outcomes.
- Effective workforce capacity, talent development, contractor performance, vendor accountability, and stakeholder satisfaction.
What you’ll need
- Bachelor’s degree in cybersecurity, information technology, engineering, computer science, or a related discipline, or equivalent relevant experience.
- Typically 8 or more years of progressive experience in cybersecurity, security engineering, cloud security, infrastructure engineering, or a related technology field, including leadership of technical teams and complex initiatives.
- Experience managing a blended workforce of employees, contractors, consultants, and technology vendors.
- Hands-on or leadership experience designing, implementing, and operating security controls in AWS and Microsoft Azure environments.
- Experience aligning security capabilities or controls to the NIST CSF and translating risk, policy, or regulatory requirements into implementable technical solutions.
- Experience developing security metrics, control-health reporting, executive dashboards, and evidence for risk, audit, or regulatory processes.
- Financial services or other regulated-industry experience preferred.
- Industry certifications such as CISSP, CISM, CCSP, GIAC, AWS Security Specialty, or Microsoft cybersecurity certifications preferred.
- Strong knowledge of security architecture and engineering principles, including defense in depth, zero trust, cloud shared-responsibility models, secure configuration, and secure system lifecycle practices.
- Working knowledge of AWS and Azure security services, cloud identity, workload protection, logging and monitoring, encryption and key and secrets management, network security, and policy automation.
- Broad familiarity with security platforms and capabilities including SIEM, EDR/XDR, CSPM/CNAPP, vulnerability management, PAM, IAM, DLP, CASB/SSE, WAF, email security, certificate management, secrets management, SAST/DAST/SCA, and breach-and-attack simulation.
- Ability to evaluate technical control design and effectiveness, identify root causes and dependencies, and create practical remediation roadmaps.
- Ability to develop measures that distinguish activity, service performance, control coverage, control health, risk exposure, and business outcomes.
- Experience with automation and scripting, APIs, infrastructure as code, CI/CD pipelines, and DevSecOps practices preferred.
- Strong program, portfolio, vendor, financial, and workforce management skills.
- Excellent communication skills including written, verbal, presentation, visualization, listening, negotiation, and stakeholder management.
- Sound judgment, attention to detail, personal accountability, and ability to lead through ambiguity, competing priorities, incidents, and change.
Technologies you may work with
- NIST Cybersecurity Framework (CSF)
- AWS
- Microsoft Azure
- SaaS
- SIEM
- EDR/XDR
- CSPM/CNAPP
- PAM, IAM, DLP, CASB/SSE, WAF
- SAST/DAST/SCA
- DevSecOps, CI/CD pipelines, infrastructure as code
- Endpoint, network, identity, application, data
- Email security, certificate and secrets management, breach-and-attack simulation
Compensation and location
- Location: Chicago, IL (hybrid)
- Salary range: USD 151,025 - 265,525 per year
Benefits
- Retirement program (401k and Pension)
- Medical, dental and vision insurance
- Lifestyle Spending Account
- Competitive PTO plan
- 11 paid holidays per year
- Highly competitive compensation and bonus package
- Access to a comprehensive benefits program designed to meet the needs of employees
Similar Jobs
T
B