Skip to content
All jobs

Security Engineer

3M Company

Job
30736
Posted
Location
Chicago, IL
Work type
Full Time
Tax terms
W2, Yearly
Experience
Experience open
Rate
$160,000 to $180,000 (Annum)
Openings
1 opening

Skills

  • Security Engineering
  • Retail
  • Finance
  • Financing
  • Mortgage
  • Underwriting
  • Marketing
  • Organized
  • Information Technology
  • Accountability
  • ProVision
  • Vendor Relationships
  • Sprint
  • Articulate
  • Network Design
  • Network Protocols
  • Routing
  • Agile
  • DevOps
  • Directory Services

About the job

Rate is one of the nation's top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate's Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology - including Same Day Mortgage, the Rate App, FlashClose , MyAccount and the Language Access Program - has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain's Chicago Business. Learn more at rate.com.

Job Profile:

Security Engineer

Job Description Summary:

We are committed to providing a competitive and equitable total rewards package. The compensation for this role is designed to attract, retain, and motivate top talent.

The expected base salary range for this position is $160,000 to $180,000 annually

Job Description:

Why Rate is the BEST Place to Work

Rate is one of the nation's top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate's Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology - including Same Day Mortgage, the Rate App, FlashClose , MyAccount and the Language Access Program - has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain's Chicago Business. Learn more at rate.com.

What Makes Our Team Awesome

We are a gritty group of passionate technologists on a mission to dominate the mortgage world!

The Information Technology Team within Rate passionately and consistently puts our customers first. We are building the latest technology to help create the best mortgage experience on the planet and get your mortgage, your way, anytime, anywhere. Whether that is improving our digital mortgage platform, automating loan coordination and underwriting processes, or building out the latest marketing and customer engagement platform, we're doing it all. We build high-performing, self-organized, cross-functional agile teams that operate with minimal hierarchy. Information Technology team members hold themselves and others accountable and live and breathe the tenets of autonomy, mastery, and purpose.

What's the Role?

We are seeking a Security Engineer with a primary focus on cloud security and infrastructure. This generalist security role will be responsible for developing, architecting, and deploying security solutions across multiple technology domains including cloud infrastructure, network security, endpoint detection and response (EDR), data loss protection (DLP), and container environments. The Security Engineer will report to the Security Director and be a key member of the larger security engineering team, collaborating with other security engineers and application security engineers to solve objectives both independently and together. The role requires subject matter expertise in cloud security while maintaining a broad understanding of enterprise security technologies and the ability to work autonomously as well as within a team environment.

Responsibilities:

  • Take ownership of security projects and initiatives from objective to completion; work independently and with minimal oversight to identify problems, evaluate solutions, and implement fixes.
  • Self-manage workload and priorities; track work in sprints, articulate progress and blockers, and provide clear written and oral communication of detailed steps needed to accomplish security objectives.
  • Collaborate with other security engineers and application security engineers to solve complex security challenges; contribute to team initiatives while maintaining autonomous responsibility for assigned projects.
  • Design, architect, and implement secure infrastructure and security controls across multiple technology domains with emphasis on cloud deployments.
  • Develop and deploy Infrastructure as Code using Terraform to provision and manage secure cloud environments while maintaining security posture.
  • Proactively identify security gaps and deficiencies in existing security designs, propose plans for improvement and implementation across all security domains.
  • Lead vendor evaluation, selection, and engagement for security tools and platforms; manage vendor relationships and coordinate implementations.
  • Provide subject matter expertise in cloud security while maintaining competency across network security, EDR, DLP, SIEM, and other security technologies depending on organizational needs.
  • Manage security logging infrastructure; identify critical log sources, configure SIEM to capture essential security events, troubleshoot logging issues, and provide recommendations for log architecture and retention.
  • Develop and maintain security policies, standards, procedures, and documentation to ensure consistency and compliance across the organization.
  • Lead the evaluation, deployment, and management of security tools and platforms across cloud and on-premises environments.
  • Collaborate with DevOps, infrastructure, development, and business teams to identify security needs, propose solutions, and integrate security controls into Infrastructure as Code, CI/CD pipelines, and deployments.
  • Monitor and respond to security incidents and alerts; use SIEM and logging infrastructure to investigate and remediate threats and vulnerabilities across all security domains within defined SLAs.
  • Manage identity and access controls across platforms; ensure implementation of least privilege, RBAC principles, and security best practices.
  • Maintain knowledge of current security trends, emerging threats, and best practices across multiple technology domains; communicate findings to management and stakeholders.
  • Assist other security team members with broader security initiatives, providing cross-training and subject matter expertise.

Qualifications:

  • 5+ years' experience in security engineering with emphasis on infrastructure security, cloud security, or equivalent combination of roles solving security problems in large-scale systems.
  • Self-Direction, Workload Management & Communication
  • Demonstrated ability to self-task and work independently to identify, analyze, and solve complex security problems with minimal oversight; comfort taking ownership of projects from objective to completion.
  • Ability to self-manage workload and priorities; comfort tracking work in sprint-based environments and providing regular updates on progress, blockers, and completion status.
  • Strong written and oral communication skills with ability to document and clearly articulate detailed steps, plans, and requirements needed to accomplish security objectives.
  • Experience working with vendors; ability to evaluate, select, and manage vendor solutions for security tools and platforms.

Cloud Security & Infrastructure

  • Proficiency with Infrastructure as Code, specifically Terraform, for deploying and managing infrastructure with security considerations.
  • Proficiency with at least one major cloud platform (AWS, Azure, or Google Cloud Platform) and understanding of multi-cloud security considerations.
  • Experience designing and securing containerized environments and Kubernetes clusters in production.
  • Demonstrated experience with cloud network architecture, VPCs, security groups, firewalls, and network segmentation.
  • Cloud security posture management and experience implementing security controls and compliance frameworks (SOC 2, PCI-DSS, NIST, or CIS).

Logging & Security Monitoring

  • Hands-on experience with Security Information and Event Management (SIEM) and next-generation SIEM technologies; comfort with log searching, filtering, and analysis.
  • Demonstrated ability to troubleshoot logging infrastructure, identify critical log sources for security investigations, and provide recommendations for log retention and architecture.

Network & Endpoint Security

  • Strong understanding of network protocols, routing, firewalls, VLANs, and VPN technologies.
  • Hands-on experience with Endpoint Detection and Response (EDR) tools and strategies, including threat detection and incident response.
  • Hands-on experience implementing and managing Data Loss Prevention (DLP) solutions and policies.

Application Security & Development Support

  • Experience supporting application security initiatives and collaborating with development and AppSec teams.
  • Familiarity with agile development processes and experience integrating security practices and guardrails into DevOps and CI/CD workflows.

General Security & Professional Skills

  • Experience with identity and access management (IAM), directory services, and role-based access control.
  • Proficiency in at least one scripting language (Python, Bash, PowerShell, or equivalent) for automation and tooling.
  • Strong interpersonal and communication skills with ability to effectively influence stakeholders and work across technical and non-technical teams.
  • Excellent ability to communicate complex technical information to diverse audiences in clear, authoritative, and actionable terms.

Preferred Experience:

Cloud Security & Infrastructure

  • Designing, implementing, and maintaining cloud infrastructure security in large-scale, multi-cloud environments (AWS, Azure, Google Cloud Platform, or equivalent).
  • Proficiency with Infrastructure as Code (IaC), specifically Terraform, for deploying and managing secure cloud infrastructure.
  • Cloud security fundamentals including identity and access management (IAM), network segmentation, encryption, and data protection across cloud platforms.
  • Building and securing containerized environments including Kubernetes, Docker, container registries, and orchestration platforms.
  • Cloud security posture management and compliance frameworks including industry standards such as NIST and CIS benchmarks.
  • Implementing and managing cloud security tools and services such as cloud access security brokers (CASB) and cloud workload protection platforms (CWPP).
  • BONUS: Experience with third-party Cloud Security Posture Management (CSPM) tools such as Wiz, Lacework, or equivalent.

Logging & Security Monitoring

  • Experience with Security Information and Event Management (SIEM) and next-generation SIEM (SIEM+) technologies; comfort with log searching, filtering, and analysis.
  • Ability to troubleshoot logging infrastructure issues, identify critical log sources for security investigations, and provide recommendations for log retention and architecture.
  • System monitoring and security alerting; ability to correlate logs and events across multiple platforms to identify and remediate threats.

Network & Endpoint Security

  • Network security architecture and implementation including VLANs, VPNs, firewalls, network segmentation, and routing protocols.
  • Endpoint Detection and Response (EDR) tools and strategies, including threat detection, incident response, and endpoint hardening.
  • Data Loss Prevention (DLP) solutions and strategies, including implementation of DLP policies, monitoring, and compliance controls.

Application Security & Development Support

Similar jobs

See all jobs