Principal Security Engineer


Chicago
Permanent
USD145200 - USD236700
Cybersecurity
PR/578387_1770230671
Principal Security Engineer

About the Role

Our recruitment team is partnering with a major enterprise organization to identify an experienced Security Engineering leader with deep expertise in privileged access and secrets management. Our client is a well‑established organization in the financial services sector, supporting critical operations within the broader trading and investment ecosystem

This position plays a critical role in advancing core identity security controls, enhancing automation, and drivingAI‑enabled improvements across a large and complex environment.

We are supporting our client in finding a professional who can provide operational leadership, influence architectural direction, and drive modernization across privileged access platforms. If you thrive in sophisticated enterprise environments and enjoy tackling difficult security challenges, this opportunity offers substantial impact and long‑term growth.


What You'll Do

  • Provide 24x7 operational support and subject matter expertise for enterprise privileged access management (PAM) platforms and secrets management solutions (e.g., CyberArk, HashiCorp Vault, PKI, HSMs).
  • Deliver break‑fix activities, troubleshoot platform issues, apply patches and hotfixes, and manage platform lifecycle tasks such as upgrades, version control, and configuration alignment with internal security standards.
  • Serve as a primary technical authority for secrets management and PAM architecture, ensuring strong security‑as‑code practices across the environment.
  • Build and enhance integrations between PAM systems and enterprise tooling, improving user experience and operational efficiency.
  • Develop long-term engineering solutions leveraging automation and AI‑based approaches for faster detection, triage, and remediation of functional or technical issues.
  • Collaborate with security architecture, cloud, and infrastructure teams to strengthen identity and access controls across on‑prem and cloud platforms.

Qualifications

Required Knowledge & Skills

  • Strong understanding of authentication and authorization technologies (e.g., Active Directory, OAuth 2.0, OIDC, IAM, Kerberos, LDAP/LDAPS, certificates, Kubernetes access models).
  • Working knowledge of cloud environments and CI/CD tooling such as Terraform, Ansible, and Jenkins.
  • Solid grounding in security architecture concepts: confidentiality, integrity, availability.

Technical Expertise

  • Hands‑on experience supporting or engineering one or more of the following:
    • CyberArk
    • HashiCorp Vault
    • PKI / ADCS
    • Hardware Security Modules (HSMs)
  • Advanced scripting or engineering skills in Go, Python, Bash, PowerShell, Terraform, or Ansible.
  • Deep understanding of PAM methodologies for both on‑prem and cloud-based implementations.

Experience

  • Background in security engineering, operations, software development, or security architecture.
  • Experience supporting privileged access or secrets management programs.
  • Familiarity with AI-assisted development tools (OpenAI-based agents, Claude Code, Gemini CLI, etc.).

Work Environment & Growth

  • Highly collaborative culture with strong cross-team engagement.
  • Exposure to modern security tools, enterprise-scale architecture, and emerging technologies.
  • Opportunity to lead major automation initiatives and platform modernization efforts.

FAQs

Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your resume and details on file so when we see similar roles or see skillsets that drive growth in organizations, we will always reach out to discuss opportunities.

Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.

We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business. 

That's why we recommend registering your resume so you can be considered for roles that have yet to be created. 

Yes, we help with resume and interview preparation. From customized support on how to optimize your resume to interview preparation and compensation negotiations, we advocate for you throughout your next career move.

Handpicked roles for you