- Salary
- $151k – $266k
- Location
- Chicago, United States of America
- Workplace
- Remote, Onsite
- Type
- Full-time
- Department
- Engineering
- Seniority
- Manager
- Source
- Workday
Description
At the Federal Home Loan Bank of Chicago, employees come first - that’s why we offer a highly competitive compensation and bonus package, and access to a comprehensive benefits program designed to meet the needs of our employees.
Collaborative, in-office operating model
Retirement program (401k and Pension)
Medical, dental and vision insurance
Lifestyle Spending Account
Competitive PTO plan
11 paid holidays per year
Who we are
Our mission at FHLBank Chicago: To partner with our members in Illinois and Wisconsin to provide them competitively priced funding, a reasonable return on their investment, and support for their community investment activities.
Simply said, we're a bank for banks and other financial institutions, focused on being a strategic partner for our members and working together to reinvest in our communities, from urban centers to rural areas. Created by Congress in 1932, FHLBank Chicago is one of 11 Federal Home Loan Banks, government sponsored in support of mortgage lending and community investment.
What it’s like to work here
At FHLBank Chicago, we bring people together. We are committed to a high performing, engaged workforce, and to supporting the communities we serve across Illinois and Wisconsin. Our Buddy Program pairs new hires with tenured employees to guide their onboarding. Our professional development and training opportunities through upskilling, mentorship programs, and tuition reimbursement allow employees to grow their career with us. Our collaborative, in-office operating model brings teams together to foster innovation, connection, and shared success. To support balance and flexibility, employees are provided an allocation of remote days to use as needed throughout the year.
What you’ll do
The Senior Manager, Information Security Engineering leads the design, engineering, implementation, and lifecycle management of technical security controls that protect the Bank’s systems, identities, applications, data, cloud services, and customer-facing capabilities. The role reports to the Chief Information Security Officer, and manages a blended team of employees and contractors, establishes engineering priorities and standards, and translates security requirements into scalable, supportable, and measurable technology solutions. The position aligns the security tool portfolio and engineering roadmap to the NIST Cybersecurity Framework (CSF), Bank policy, risk appetite, architecture standards, and applicable regulatory expectations.
How you’ll make an impact
- Builds and sustains a resilient defense-in-depth control environment across on-premises, AWS, Microsoft Azure, SaaS, endpoint, network, identity, application, and data platforms.
- Converts cybersecurity risk, policy, and architecture requirements into practical technical controls, engineering patterns, automation, and operational guardrails.
- Improves control effectiveness, reliability, coverage, and transparency through disciplined engineering practices and outcome-oriented metrics.· Develops security engineering talent and creates clear accountability across employees, contractors, vendors, and technology partners.
- Enhances the Bank’s resilience by delivering secure, scalable, and reliable security controls that protect critical systems, data, and customer services.
- Drives risk reduction and regulatory readiness through the implementation of modern security capabilities, automation, and governance aligned with industry and regulatory standards.
- Accelerates security maturity and operational excellence by leading high-performing engineering teams, optimizing security investments, and providing measurable improvements in control effectiveness and business protection.
What you can expect
- Lead, coach, and develop security engineering employees and contractors. Set clear objectives, allocate work, manage capacity, provide feedback, support performance and career development, and promote an inclusive, accountable, and collaborative culture.
- Own the security engineering strategy, operating model, multi-year roadmap, backlog, budget inputs, workforce plan, vendor relationships, and delivery commitments. Balance strategic initiatives, control maintenance, technical debt, and urgent risk reduction.
- Align security engineering capabilities, tools, and technical controls to the NIST CSF functions and categories. Maintain traceability from risks and requirements to control design, implementation, evidence, ownership, and measurement.
- Partner with Security Architecture, Security Operations, Threat and Incident Response, Identity and Access Management, Security Advisory and Analytics, IT Risk and Compliance, Enterprise Architecture, Infrastructure, Cloud, Network, and Application teams to design and implement effective controls.
- Assist control owners and engineering teams with the development, documentation, implementation, testing, and continuous improvement of preventive, detective, responsive, and recovery-oriented technical controls.
- Provide engineering leadership for security technologies supporting endpoint and workload protection, identity and privileged access, cloud security, network security, security monitoring and logging, data protection, vulnerability management, application security, certificate and secrets management, email and collaboration security, and security automation.
- Direct security engineering for AWS and Microsoft Azure environments, including secure configuration baselines, native security services, identity and access controls, logging and monitoring, encryption and key management, network segmentation, workload protection, and automated policy enforcement.
- Establish standards for security tool selection, architecture, configuration, integration, lifecycle management, resilience, supportability, and decommissioning. Identify tool overlap, coverage gaps, operational dependencies, and opportunities for consolidation or automation.
- Define engineering quality practices, including peer review, change control, infrastructure as code, testing, documentation, secure configuration, release readiness, rollback planning, and handoff to operational support teams.
- Develop and maintain technical standards, baseline security configurations, reference architectures, procedures, engineering runbooks, control narratives, and evidence required for governance, risk, audit, and regulatory review.
- Develop meaningful metrics and dashboards that measure control coverage, control health and effectiveness, engineering delivery, reliability, automation, technical debt, risk reduction, and service performance. Use results to prioritize investment and drive continuous improvement.
- Provide concise reporting to security and technology leadership on roadmap progress, material risks, exceptions, dependencies, resource constraints, control performance, and recommended decisions.
- Support security incidents, investigations, vulnerability remediation, audit findings, risk acceptances, penetration testing, and threat-driven improvements by coordinating engineering analysis and sustainable corrective actions.
- Participate in technology planning and design reviews to ensure security requirements are incorporated early and implemented in a manner that supports business objectives and customer needs.
- Provide technical escalation and decision support for complex security control and tooling issues. Coordinate off-hours support when required for critical incidents or significant production changes.
- Perform other duties as assigned.
What you’ll bring
- Bachelor’s degree in cybersecurity, information technology, engineering, computer science, or a related discipline, or equivalent relevant experience.
- Typically 8 or more years of progressive experience in cybersecurity, security engineering, cloud security, infrastructure engineering, or a related technology field, including demonstrated leadership of technical teams and complex initiatives.
- Experience managing a blended workforce of employees, contractors, consultants, and technology vendors.
- Hands-on or leadership experience designing, implementing, and operating security controls in AWS and Microsoft Azure environments.
- Experience aligning security capabilities or controls to the NIST CSF and translating risk, policy, or regulatory requirements into implementable technical solutions.
- Experience developing security metrics, control-health reporting, executive dashboards, and evidence used to support risk, audit, or regulatory processes.
- Financial services or other regulated-industry experience preferred.
- Industry certification such as CISSP, CISM, CCSP, GIAC, AWS Security Specialty, or Microsoft cybersecurity certification preferred.
- Strong knowledge of security architecture and engineering principles, defense in depth, zero trust, cloud shared-responsibility models, secure configuration, and secure system lifecycle practices.
- Working knowledge of AWS and Azure security services, cloud identity, workload protection, logging, monitoring, encryption, key and secrets management, network security, and policy automation.
- Broad familiarity with security platforms and capabilities such as SIEM, EDR/XDR, CSPM/CNAPP, vulnerability management, PAM, IAM, DLP, CASB/SSE, WAF, email security, certificate management, secrets management, SAST/DAST/SCA, and breach-and-attack simulation.
- Ability to evaluate technical control design and effectiveness, identify root causes and dependencies, and create practical remediation roadmaps.
- Ability to develop measures that distinguish activity, service performance, control coverage, control health, risk exposure, and business outcomes.
- Experience with automation and scripting, APIs, infrastructure as code, CI/CD pipelines, and DevSecOps practices preferred.· Strong program, portfolio, vendor, financial, and workforce management skills.
- Excellent written, verbal, presentation, visualization, listening, negotiation, and stakeholder-management skills.
- Ability to communicate complex technical and risk topics clearly to technical teams, business leaders, auditors, and executive stakeholders.
- Sound judgment, attention to detail, personal accountability, and the ability to lead through ambiguity, competing priorities, incidents, and change.
Leadership Expectations
- Sets a clear direction and connects team priorities to enterprise strategy, security risk, and measurable outcomes.
- Creates role clarity and effective ways of working across employees, contractors, vendors, and partner teams.
- Develops talent through coaching, stretch assignments, succession planning, recognition, and timely constructive feedback.
- Promotes engineering discipline, psychological safety, responsible challenge, documentation, knowledge sharing, and continuous learning.
- Demonstrates integrity, risk ownership, customer focus, collaboration, and responsible stewardship of Bank resources.
Success Measures
- Improved security-control coverage, health, effectiveness, reliability, and evidence quality.
- Timely delivery of prioritized engineering roadmap commitments and sustainable remediation of material risks and findings.· Reduced manual effort, repeated incidents, tool overlap, unsupported configurations, and security technical debt through standardization and automation.
- Clear NIST CSF traceability for the security engineering portfolio and technical controls.
- Actionable metrics that enable risk-based decisions and demonstrate security and operational outcomes.
- Effective workforce capacity, talent development, contractor performance, vendor accountability, and stakeholder satisfaction.
Salary Range:
$151,025.00 - $265,525.00The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we may also consider your experience, and other job-related factors. In addition to the base salary, we offer a comprehensive benefits package which can be found here: https://hrportal.ehr.com/fhlbc