CybersecurityJobs.io
← Back to all jobs

Job Description

Bain & Company seeks a seasoned Staff Security Engineer to advance the PEG Security Engineering program. The role centers on securing Bain’s PE platform estate on Azure AKS, weaving security into the software development lifecycle, and leading platform security engineering and incident response across cross-functional teams. Based in Chicago with a hybrid work model, this position collaborates closely with Platform Engineering, Data Platform, Product Engineering, and the Agent/AI squads to reduce risk while enabling rapid delivery.

Responsibilities

  • Own and operate the platform’s security posture end-to-end across core controls, including HashiCorp Vault and/or Azure Key Vault, Istio mTLS, Cilium network policy, Pod Security Standards, and OPA/Gatekeeper policies.
  • Design and implement a zero-trust security architecture across the estate, emphasizing defense in depth, least privilege, and explicit security boundary design.
  • Perform lightweight threat modeling (STRIDE) for new services and major features prior to implementation; document risks, mitigations, and residual risk decisions.
  • Manage supply chain security controls such as container image scanning, image signing, SBOM generation, and dependency vulnerability management.
  • Define and enforce identity and access controls, including SAML/OIDC integration patterns, JWT/OAuth concepts, and practical enterprise IdP integration guidance (Okta/Entra).
  • Define and maintain data classification controls and enforce them at the platform layer (governed access patterns, masking/tokenization, and API-layer enforcement).
  • Own runtime detection controls by operating Falco rules and escalation pathways; integrate signals with the central SIEM and reduce alert noise to maintain usable signal.
  • Lead security incident response for the platform, driving containment, remediation, and post-incident security reviews with clear follow-up actions.
  • Conduct regular security reviews of the AI layer, including Agent Gateway egress controls, prompt injection risks, PII handling, and data exfiltration controls for model interactions.
  • Maintain security runbooks and conduct quarterly internal security reviews across teams; ensure controls are tested, auditable, and actively maintained.
  • Set and enforce security standards, build controls as code, and partner with Platform Engineering, Data Platform, Product Engineering, and the Agent/AI squad to reduce risk while enabling rapid delivery.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related field, or equivalent practical experience.
  • Six or more years of security engineering, infrastructure security, SRE/DevOps with a security focus, or platform engineering roles with hands-on security ownership.
  • Hands-on experience implementing and operating security controls in Kubernetes-based production environments (policy enforcement, workload isolation, network controls, and runtime detection).
  • Experience designing and operating secrets management and identity/access controls (HashiCorp Vault and/or Azure Key Vault, PKI, OIDC/SAML patterns, enterprise IdP integration).
  • Experience implementing supply chain security practices (scanning, signing, SBOMs, dependency management) and integrating controls into CI/CD pipelines.
  • Experience leading or materially contributing to security incident response, including post-incident review and remediation planning.
  • Ability to work cross-functionally as an enabling partner, raising security standards without unnecessarily blocking delivery.

Technologies

  • HashiCorp Vault, Azure Key Vault
  • Istio, Cilium, Pod Security Standards, OPA, Gatekeeper
  • Falco, Kubernetes, AKS
  • SAML 2.0, OIDC, JWT, OAuth
  • Okta, Entra, Azure AD
  • Kyverno, Rego, Trivy, Cosign, Sigstore, Syft, Dependabot, Renovate
  • Python, Bash

Benefits

  • Bain pays 100% of individual employee premiums for medical, dental, and vision programs
  • Generous paid time off, including parental leave, sick leave, and paid holidays
  • Fully vested 401(k) company contribution
  • Paid Life and Long-Term Disability insurance
  • Annual fitness reimbursements

Location and work arrangement

Chicago, IL, hybrid

Salary and compensation

USD 141,000 - 176,750 per year

Education and experience

  • Bachelor’s degree or equivalent practical experience
  • 6+ years of related security engineering, infrastructure security, SRE/DevOps with security focus, or platform engineering with security ownership

U.S. compensation information

In Chicago, IL, the good-faith, reasonable annualized full-time salary range for this role is between $141,000 and $169,250; placement within this range varies by experience, education, training, and skill level. In Boston, MA, the range is $147,250 to $176,750; placement within this range also reflects experience and qualifications.

Similar Jobs