Sr. Information Security Engineer

gatx· Information Technology
Apply Now ↗
📍 Chicago, IL, USOTHER

About this role

Overview

Founded in 1898 and headquartered in Chicago, IL, GATX Corporation (NYSE: GATX) is an industry leader with 125+ years of success—success that is powered by our people.

 

At GATX, we hire the best and offer our employees a dynamic, energetic, collaborative environment to enable them to make an impact from day one. Enjoy the perks and benefits of a global company with the close-knit culture and community of a much smaller one. In the same way we strive to empower our customers to propel the world forward, we are dedicated to providing our people with the tools and resources they need to advance in their careers.

 

GATX is seeking a Senior Information Security Engineer to provide technical leadership for cybersecurity initiatives that protect the organization's data, systems, and cloud environments. This role partners across IT and the business to reduce cyber risk, strengthen security controls, and advance the maturity of the cybersecurity program.

Responsibilities

  • Develop and maintain security standards and guidelines that protect company systems, data, and networks. Manage security tools, software, and the implementation of new controls, including the design and maintenance of complex cybersecurity controls throughout the system lifecycle. Support initiatives that reduce evolving cyber risk by applying a strong understanding of the organization’s threat landscape.
  • Partner with cross-functional teams to develop incident response plans and protocols. Oversee vulnerability assessments and penetration testing to identify system and network weaknesses and coordinate with IT teams to remediate issues.  Monitor networks and systems for security incidents, take action to reduce the risk of data loss or unauthorized access, and investigate events by analyzing data, coordinating response efforts, and reporting findings to management and IT teams.
  • Lead the development and deployment of advanced identity protection capabilities in Entra IAM to strengthen security and align with best practices. Improve authentication security in alignment with Zero Trust principles and increase resilience against identity-based threats. Own administration of BeyondTrust PAM, Entra IAM, including secure configuration, timely updates, and user support. Partner with IT teams to expand identity platform integrations and improve efficiency in identity and privileged access management.
  • AWS Security Administration
    • Security Management: Implement IAM policies, manage access controls, and ensure compliance with security best practices
    • Automation & Scripting: Automate routine tasks using tools like AWS CLI, CloudFormation, or Terraform
    • Collaboration: Work with development teams to support CI/CD pipelines and scalable application deployments in a secure manner.
  • Collaborate in securely implementing Microsoft Azure Solutions in a multi-tenant cloud environment. Working closely with LAN Administrators responsible for building and maintaining various technical systems, subscriptions, projects and knowledge bases across local and cloud environments to ensure operational and support teams have access to highly secure and highly available tools and systems necessary for business operations.  Utilize experience and knowledge to better secure Microsoft and Unix/Linux technologies such as SharePoint, Exchange, Active Directory, Microsoft Server Operating Systems, Intune, Windows 10/11, IBM AIX and Red Hat solutions.
  • Research and remain current on technical and industry practices for securing operating systems, hardware, and infrastructure services. Implement security best practices where appropriate and advise the Global Head of IT Security and Senior Manager of Information Security on security technology strategies.
  • Technical subject matter expert who can coach and mentor others to assist in their development.

Qualifications

  • Bachelor's degree or equivalent experience.
  • 7+ years of information security experience and 5+ years supporting network or infrastructure technologies.
  • Experience with IAM technologies, including Entra ID, Conditional Access, MFA, and privileged access management.
  • Experience securing AWS and/or Azure cloud environments.
  • Strong understanding of cybersecurity principles, network security, vulnerability management, and incident response.
  • Experience with scripting, automation, and modern DevOps/CI-CD environments.
  • Ability to communicate technical concepts to non-technical audiences and build strong cross-functional relationships.
  • CISSP, CISM, CRISC, or equivalent certification required or in progress.
  • AWS Security Specialty certification preferred.

Posting Duration

This posting will remain open until the role is filled.

 

As of the post date, the salary range for this position is:

Min

USD $92,700.00/Yr.

Max

USD $160,000.00/Yr.

 

This role may be eligible to participate in the Company’s short-term incentive plan, the details of which will be provided to the applicant upon hire.

 

This range is a reasonable estimate and takes into account several factors that are considered in making compensation decisions, including, but not limited to, geographic location, skill set, experience, education, training, internal equity, and other business needs.

Responsibilities

- Develop and maintain security standards and guidelines that protect company systems, data, and networks. Manage security tools, software, and the implementation of new controls, including the design and maintenance of complex cybersecurity controls throughout the system lifecycle. Support initiatives that reduce evolving cyber risk by applying a strong understanding of the organization’s threat landscape.
- Partner with cross-functional teams to develop incident response plans and protocols. Oversee vulnerability assessments and penetration testing to identify system and network weaknesses and coordinate with IT teams to remediate issues.  Monitor networks and systems for security incidents, take action to reduce the risk of data loss or unauthorized access, and investigate events by analyzing data, coordinating response efforts, and reporting findings to management and IT teams.
- Lead the development and deployment of advanced identity protection capabilities in Entra IAM to strengthen security and align with best practices. Improve authentication security in alignment with Zero Trust principles and increase resilience against identity-based threats. Own administration of BeyondTrust PAM, Entra IAM, including secure configuration, timely updates, and user support. Partner with IT teams to expand identity platform integrations and improve efficiency in identity and privileged access management.
- AWS Security Administration
- Security Management: Implement IAM policies, manage access controls, and ensure compliance with security best practices
- Automation & Scripting: Automate routine tasks using tools like AWS CLI, CloudFormation, or Terraform
- Collaboration: Work with development teams to support CI/CD pipelines and scalable application deployments in a secure manner.
- Collaborate in securely implementing Microsoft Azure Solutions in a multi-tenant cloud environment. Working closely with LAN Administrators responsible for building and maintaining various technical systems, subscriptions, projects and knowledge bases across local and cloud environments to ensure operational and support teams have access to highly secure and highly available tools and systems necessary for business operations.  Utilize experience and knowledge to better secure Microsoft and Unix/Linux technologies such as SharePoint, Exchange, Active Directory, Microsoft Server Operating Systems, Intune, Windows 10/11, IBM AIX and Red Hat solutions.
- Research and remain current on technical and industry practices for securing operating systems, hardware, and infrastructure services. Implement security best practices where appropriate and advise the Global Head of IT Security and Senior Manager of Information Security on security technology strategies.
- Technical subject matter expert who can coach and mentor others to assist in their development.

Frequently Asked Questions

Is the salary disclosed for the Sr. Information Security Engineer position at gatx?
The salary for this Sr. Information Security Engineer role at gatx is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Sr. Information Security Engineer position at gatx located?
This Sr. Information Security Engineer role at gatx is based in Chicago, IL, US. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Sr. Information Security Engineer role at gatx full-time or part-time?
This is listed as a OTHER position. It is posted as a Sr. Information Security Engineer role in the Information Technology department at gatx.
Which team or department does the Sr. Information Security Engineer at gatx belong to?
This Sr. Information Security Engineer position is part of the Information Technology department at gatx. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Sr. Information Security Engineer position at gatx?
Click the "Apply Now" button on this page. You will be redirected to gatx's official application portal hosted on icims where you can submit your application directly.
When was the Sr. Information Security Engineer job at gatx posted?
This Sr. Information Security Engineer position at gatx was posted on Sep 11, 2026. Apply as soon as possible — early applications are often reviewed first.
Sr. Information Security Engineer
gatx
Apply for this role ↗

You'll be redirected to gatx's official application page on icims.