Sr. Information Security Engineer

Job Locations US-IL-Chicago
ID
2026-4694
Category
Information Technology
Position Type
Full Time

Overview

Founded in 1898 and headquartered in Chicago, IL, GATX Corporation (NYSE: GATX) is an industry leader with 125+ years of success—success that is powered by our people.

 

At GATX, we hire the best and offer our employees a dynamic, energetic, collaborative environment to enable them to make an impact from day one. Enjoy the perks and benefits of a global company with the close-knit culture and community of a much smaller one. In the same way we strive to empower our customers to propel the world forward, we are dedicated to providing our people with the tools and resources they need to advance in their careers.

 

GATX is seeking a Senior Information Security Engineer to provide technical leadership for cybersecurity initiatives that protect the organization's data, systems, and cloud environments. This role partners across IT and the business to reduce cyber risk, strengthen security controls, and advance the maturity of the cybersecurity program.

Responsibilities

  • Develop and maintain security standards and guidelines that protect company systems, data, and networks. Manage security tools, software, and the implementation of new controls, including the design and maintenance of complex cybersecurity controls throughout the system lifecycle. Support initiatives that reduce evolving cyber risk by applying a strong understanding of the organization’s threat landscape.
  • Partner with cross-functional teams to develop incident response plans and protocols. Oversee vulnerability assessments and penetration testing to identify system and network weaknesses and coordinate with IT teams to remediate issues.  Monitor networks and systems for security incidents, take action to reduce the risk of data loss or unauthorized access, and investigate events by analyzing data, coordinating response efforts, and reporting findings to management and IT teams.
  • Lead the development and deployment of advanced identity protection capabilities in Entra IAM to strengthen security and align with best practices. Improve authentication security in alignment with Zero Trust principles and increase resilience against identity-based threats. Own administration of BeyondTrust PAM, Entra IAM, including secure configuration, timely updates, and user support. Partner with IT teams to expand identity platform integrations and improve efficiency in identity and privileged access management.
  • AWS Security Administration
    • Security Management: Implement IAM policies, manage access controls, and ensure compliance with security best practices
    • Automation & Scripting: Automate routine tasks using tools like AWS CLI, CloudFormation, or Terraform
    • Collaboration: Work with development teams to support CI/CD pipelines and scalable application deployments in a secure manner.
  • Collaborate in securely implementing Microsoft Azure Solutions in a multi-tenant cloud environment. Working closely with LAN Administrators responsible for building and maintaining various technical systems, subscriptions, projects and knowledge bases across local and cloud environments to ensure operational and support teams have access to highly secure and highly available tools and systems necessary for business operations.  Utilize experience and knowledge to better secure Microsoft and Unix/Linux technologies such as SharePoint, Exchange, Active Directory, Microsoft Server Operating Systems, Intune, Windows 10/11, IBM AIX and Red Hat solutions.
  • Research and remain current on technical and industry practices for securing operating systems, hardware, and infrastructure services. Implement security best practices where appropriate and advise the Global Head of IT Security and Senior Manager of Information Security on security technology strategies.
  • Technical subject matter expert who can coach and mentor others to assist in their development.

Qualifications

  • Bachelor's degree or equivalent experience.
  • 7+ years of information security experience and 5+ years supporting network or infrastructure technologies.
  • Experience with IAM technologies, including Entra ID, Conditional Access, MFA, and privileged access management.
  • Experience securing AWS and/or Azure cloud environments.
  • Strong understanding of cybersecurity principles, network security, vulnerability management, and incident response.
  • Experience with scripting, automation, and modern DevOps/CI-CD environments.
  • Ability to communicate technical concepts to non-technical audiences and build strong cross-functional relationships.
  • CISSP, CISM, CRISC, or equivalent certification required or in progress.
  • AWS Security Specialty certification preferred.

Posting Duration

This posting will remain open until the role is filled.

 

As of the post date, the salary range for this position is:

Min

USD $92,700.00/Yr.

Max

USD $160,000.00/Yr.

 

This role may be eligible to participate in the Company’s short-term incentive plan, the details of which will be provided to the applicant upon hire.

 

This range is a reasonable estimate and takes into account several factors that are considered in making compensation decisions, including, but not limited to, geographic location, skill set, experience, education, training, internal equity, and other business needs.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed