Avatar for NOW Foods
NOW Foods
Actively Hiring
Manufactures natural health products and supplements

SR INFRASTRUCTURE SECURITY ENGINEER

Posted: 3 weeks ago
Job Location
Remote Work Policy

In office

Visa Sponsorship

Not Available

RelocationAllowed
Skills
IT Security
Network Engineering
Enterprise Applications
Written Communication Skills
Active Directory
Identity Protection
Audits
Windows Server
Good Organizational Skills
Incident Remediation
Troubleshooting Skills
Assessments
NIST Cybersecurity Framework
Microsoft 365
Active Directory Security
Verbal Communication Skills
Vulnerability Scans
Cis Controls
Change Control Processes
Conditional Access Policies
Endpoint Hardening
Automation Development
Independent Work
CIS Benchmarks
Privileged Access Management (PAM)
Operational Procedures
DISA STIGs
Sensitivity Labels
Compliance Stakeholders
Sound Judgment
Microsoft Purview DLP
App Registrations
Firmware Updates
Security Procedures
Backup Recovery
Business Teams
Deployment Plans
Operational Practices
Enterprise Apps
cGMP Requirements
Least Privilege Models
Remediation Plans
Operations Teams
Restore Testing
DR Runbooks
Alert Tuning
Technical Documentation Interpretation
Active Directory Architecture
Guest Access
DR Exercises
Patch Cycles
Security Operational Processes
MFA Enforcement
Windows Operating Systems Administration
System Hardening Standards
Secure System Builds
System Owners
Standards Interpretation
Information Protection Controls
ISO/IEC 27001/27002
Third-Party Application Patching
Security Findings Remediation
Firewall Rules Review
Prioritize Competing Demands
Segmentation Principles
Entra ID Security
External Collaboration Settings
Procedures Interpretation
Microsoft Security Baselines
End-of-Life Remediation
Sign-in Risk Policies
Analyze Complex Technical Issues
LAPS Implementation
Privileged Credential Protection
AD Hygiene
AD Security Reviews
Privileged Group Membership Audits
AD ACL Reviews
AD Delegation Reviews
Service Account Inventory
Secure Score Optimization
OAuth Permissions
Infrastructure Patching
Windows Server Updates
Emergency CVE Patching
Hypervisor Updates
Vulnerability Scan Findings Remediation
Immutable Backup Strategies
Air-Gapped Backup Strategies
RPO/RTO Goals
Infrastructure Security Alerts
Identity Security Alerts
Infrastructure Security Events Investigation
Identity Security Events Investigation
Endpoint Risk Reduction
Removal of Local Admin Rights
Security-Focused Runbooks
Quarterly Access Reviews
Tabletop Incident Response Exercises
Core Sysadmin Tasks
Risk Assessment of Changes
Strong Problem Determination Skills
Vendor Documentation Interpretation
System Architecture Interpretation
Analyze Complex Security Issues
Practical Solutions Recommendation
Proactively Identify Risks
Proactively Identify Process Gaps
Proactively Identify Improvement Opportunities
Guiding Junior Systems Administrators
Timely Response to Security Incidents
Timely Response to Critical Vulnerabilities

About the job

ESSENTIAL DUTIES AND RESPONSIBILITIES include but are not limited to the following.

  • Security & Hardening (Primary Focus)
  • Implement and maintain secure configurations across Windows Server, Active Directory, and Microsoft 365 using CIS benchmarks and industry best practices.
  • Perform regular security posture assessments and remediate gaps.

Lead initiatives such as, but not limited to:

  • Tiered administration model (Tier 0/1/2)
  • Removal of insecure protocols
  • LAPS implementation and privileged credential protection

Identity & Active Directory SecuritConduct ongoing AD hygiene and security reviews, including:

  • Privileged group membership audits
  • AD ACL and delegation reviews
  • Service account inventory
  • Cleanup of stale objects
  • Help implement Privileged Access Management (PAM) and least privilege models.
  • Microsoft 365 / Entra ID Security
  • Design and maintain Conditional Access policies and MFA enforcement.

Improve tenant posture through:

  • Secure Score optimization
  • Identity protection and sign-in risk policies.

Manage and audit:

  • App registrations, enterprise apps, and OAuth permissions.
  • Guest access and external collaboration settings.
  • Support configuration and tuning of Microsoft Purview DLP, sensitivity labels, and information protection controls in partnership with IT Security and compliance stakeholders.
  • Patching, Vulnerability, & Lifecycle Management

Lead infrastructure patching strategy in partnership with system owners, IT Security, and Operations teams, including:

  • Windows Server updates (including emergency CVE patching)
  • Hypervisor and firmware updates
  • Third-party application patching
  • Track and remediate vulnerability scan findings.
  • Coordinate end-of-life remediation (OS, hardware, platforms).
  • Backup, Recovery, & Resilience
  • Ensure backups are not only successful, but recoverable.
  • Lead restore/recovery testing and DR exercises.
  • Validate immutable and air-gapped backup strategies.
  • Maintain and improve DR runbooks aligned to RPO/RTO goals.
  • Monitoring, Detection & Response
  • Review and respond to infrastructure and identity-related security alerts, escalating to IT Security as appropriate.
  • Tune alerts to reduce noise and increase actionable signals.
  • Partner with IT Security team to investigate infrastructure and identity-related security. events, support containment/remediation actions, and perform root cause analysis.
  • Endpoint & Network Security
  • Partner with Network Engineering and IT Security to review firewall rules, identify overly permissive access, and support remediation based on least privilege and segmentation principles.

Reduce endpoint risk:

  • Removal of local admin rights
  • Hardening endpoint configurations
  • Documentation & Process Improvement
  • Define remediation plans with risk-based prioritization.
  • Create and maintain security-focused runbooks and procedures.
  • Conduct quarterly access reviews and participate in tabletop incident response exercises.
  • Help establish repeatable security operational processes, developing automation where possible.
  • Establishes and maintains operational procedures and practices.
  • Collaboration with System Admin Team
  • Act as the security subject matter expert for the infrastructure team.

Provide guidance and hands-on support for:

  • Secure system builds
  • Patch cycles
  • Incident remediation
  • Step in to assist with core sysadmin tasks during high-demand periods.
  • Change Management
  • Support change control processes, perform risk assessment of changes before deploying to production, define deployment plans, and coordinate deployments with cross-functional teams.
  • Complies with safety and cGMP requirements.

SAFETY RESPONSIBILITY STATEMENT

Supports a culture of safety; follows all workplace health and safety procedures. Responsible for safety performance in respective area. Ensures the implementation of, adherence to, and enforcement of workplace health and safety requirements. Ensures activities are completed to promote and enforce safe behaviors by supervisors and employees. Ensures injury prevention efforts are effectively implemented. Fulfills responsibilities as outlined in the company safety management plan.

QUALIFICATIONS

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions.

· 5+ years in Systems Administration, Infrastructure Engineering, or Security Engineering.

· Relevant certifications such as Security+, CISSP, SSCP, GSEC, AZ-500, SC-300, SC-200, MS-102, or equivalent are preferred but not required.

· Working knowledge of security frameworks and hardening standards such as NIST Cybersecurity Framework, CIS Controls, CIS Benchmarks, Microsoft Security Baselines, and ISO/IEC 27001/27002, with the ability to translate control requirements into practical infrastructure and identity security improvements.

· Experience reviewing and remediating security findings from vulnerability scans, audits, or assessments

· Strong problem determination skills are required.

· Good organizational skills are required.

· Ability to work as an effective team member is a must.

Strong hands-on experience with:

o Active Directory (security & architecture)

o Microsoft 365 / Entra ID security

o Windows Server administration

o Windows Operating Systems

· Ability to translate security requirements into practical infrastructure changes.

Experience implementing:

o Conditional Access, MFA, identity security controls

o System hardening standards (CIS Benchmarks, DISA STIGs)

Familiarity with:

o SIEM/logging platforms

o Vulnerability management tools

o Backup/DR solutions

Experience with:

o Defender suite (Endpoint, Identity, Office)

o Intune and endpoint security controls

o PAM/PIM/JIT access models

o Linux/UNIX Operating Systems

o PowerShell or other scripting/automation tools

Knowledge of:

o Networking fundamentals and segmentation strategies

o Hypervisors (VMware, Hyper-V)

Ability to work effectively across IT Security, Infrastructure, Networking, Enterprise Applications, and business teams.

EDUCATION and/or EXPERIENCE

Bachelor’s degree (B.A.) in Information Technology, Computer Science, Cybersecurity, or related field preferred; or equivalent combination of education, certifications, and experience. Minimum of 5–7 years of related experience in systems administration, infrastructure engineering, cybersecurity, or similar role. Strong hands-on experience with Windows Server, Active Directory, Microsoft 365, Entra ID, patching, vulnerability remediation, and infrastructure security is required. Relevant security or Microsoft certifications are preferred.

LANGUAGE SKILLS

Must possess strong verbal and written communication skills, with the ability to clearly communicate technical information, security risks, and remediation recommendations to technical and non-technical audiences. Must be able to read, interpret, apply, and improve technical documentation, procedures, standards, vendor documentation, and system architecture materials.

REASONING ABILITY

Must be able to work independently, prioritize competing demands, analyze complex technical and security issues, and recommend practical solutions. Must demonstrate sound judgment, strong troubleshooting skills, and the ability to proactively identify risks, process gaps, and improvement opportunities. Must be able to assist in guiding junior systems administrators and support timely response to security incidents and critical vulnerabilities.

PHYSICAL DEMANDS

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

The employee is regularly required to remain at stationary work location and occasionally to move from place to place within work facility. Employee is regularly required to use the telephone and computer. Employee will be required to travel to different work sites.

WORK ENVIRONMENT

Non-standard hours and/or extended work hours can be expected due to user/project requirements and/or deadlines, system or user issues as well as workload backlog. The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

About the company

NOW Foods company logo

NOW Foods

Actively Hiring
Manufactures natural health products and supplements501-1000 Employees
Company Location
Bloomingdale
Company Size
501-1000
Learn more about NOW Foods image

Similar Jobs

Astranis company logo
Astranis
Building next-generation internet satellites to get the world online
Scale AI company logo
Scale AI
Accelerate the development of AI applications
Glide company logo
Glide
Helping financial institutions modernize
Maple company logo
Maple
Voice AI for Local Businesses
Orchard Robotics company logo
Orchard Robotics
Securing America's food supply by building the AI farmer that automates our nation's farms
EliseAI company logo
EliseAI
Building AI agents that transform complex healthcare and housing systems
EliseAI company logo
EliseAI
Building AI agents that transform complex healthcare and housing systems