> Markdown version of [/jobs/ext/3014467-information-security-lead](https://www.wearedevelopers.com/jobs/ext/3014467-information-security-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Lead - **Company:** Hendrickson USA, L.L.C. - **Location:** Schaumburg, IL, United States - **Experience:** Expert - **Salary:** $115,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Active Directory, Microsoft Antivirus, Cyber Security, Information Systems, Information Leak Prevention, Identity and Access Management, Networking Hardware, Network Security, Networking Basics, Routing, Network Segmentation, Phishing, Software Vulnerability Management, Wireless Access Point, Microsoft InTune, Information Technology, Patch Management - **Published:** September 20, 2026 - **Apply:** https://www.jofdav.com/jobs/59801311-information-security-lead ## About the Role * Bachelor's Degree in Information Security, Computer Science, or Information Systems. * ISC², GIAC, ISACA, SANS, CompTIA, Offensive Security, or CISSP security certification is preferred., * 5-10+ years of hands-on experience in systems, network engineering, or security engineering roles. * Proven ability to design and implement security solutions from scratch, not just support or monitor existing environments. * Demonstrated experience owning and driving large-scale projects independently * Deep understanding of: * Networking fundamentals (firewalls, segmentation, routing) * Identity systems (Active Directory / Entra ID) * Endpoint security and EDR tools * Vulnerability management and patching strategies Strong experience with incident response and forensic analysis, including root cause investigation (not just remediation). Ability to operate without heavy reliance on MSSPs or external vendors. Physical Demands * Lift up to 50 lbs. Environmental Conditions * Up to 10% travel is required. Behavioral Traits * Strong security-first mindset, balancing business needs without compromising controls. * Thrives in a highly autonomous environment with minimal oversight. * Comfortable pushing through organizational resistance and change-management challenges. * Highly curious with a strong desire to understand how systems work, not just tools. * Excellent communication skills across technical and non-technical stakeholders. * Ability to prioritize and execute multiple concurrent initiatives. ## Description Working directly with the Vice President of Information Security, this role is designed for a highly autonomous security leader who combines strong technical depth with the ability to independently own and execute large-scale security initiatives. Operating within a lean corporate team, you will serve as the primary technical project owner for the security program across multiple operating companies. This is a builder role, not a maintenance or oversight position. You will be expected to architect, implement, and troubleshoot security controls from a blank canvas, while navigating business constraints across both corporate offices and 24/7 manufacturing environments. Success in this position requires an exceptional engineer who can own projects end-to-end, enforce a strict security framework mindset, and remain fully hands-on at the keyboard. Essential Functions: * Enterprise Tool Ownership: Take complete engineering ownership of the core security stack, including Microsoft 365, Microsoft Defender, Intune (MDM/MAM), Entra ID (Identity & Access Management), Rapid7, and Proofpoint. * Strategic Security Architecture: Serve as an expert in security technologies and controls, driving decisions across infrastructure, identity, endpoint, and network security. * Project Leadership: Own and lead end-to-end security projects to independently scope requirements, define and track project timelines, manage vendor relationships, coordinate with IT teams, and ensure on-time delivery without disrupting business operations. * Incident Response & Root Cause Analysis: Investigate and perform root-cause analysis of issues including but not limited to: malware infections, data leakage, internal/external network abuse, and phishing attempts. * Vulnerability Management & Remediation: Drive the internal vulnerability management program utilizing Rapid7, actively identifying, prioritizing, and remediating potential security exposures, misconfigurations, and noncompliance issues across the enterprise. * Security Frameworks & Playbooks: Build and maintain security playbooks, standards, and procedures, acting as a creator of frameworks, not just a follower. * Continuous Auditing: Perform technical audits on patch management, privileged access, endpoint detection and response, network devices, wired/wireless access, and user access. Additional Responsibilities: * Provide hands-on support across Active Directory, Entra, endpoint systems, network segmentation, and access control rules as needed. * Support and mature security awareness and phishing simulation programs. * Stay current on threat landscape, tooling, and security frameworks, applying knowledge directly to the environment. * Act as a trusted technical advisor to leadership across security and infrastructure decisions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)