GATX Corp

Sr. Information Security Engineer

GATX Corp$92K — $160K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience.
  • 7+ years of information security experience, with 5+ years supporting network or infrastructure technologies.
  • Experience with IAM technologies, including Entra ID, Conditional Access, MFA, and privileged access management.
  • Experience securing AWS and/or Azure cloud environments.
  • Strong understanding of cybersecurity principles, network security, vulnerability management, and incident response.
  • Experience with scripting, automation, and modern DevOps/CI-CD environments.
  • CISSP, CISM, CRISC, or equivalent certification required or in progress.

Responsibilities

  • Develop and maintain security standards and guidelines for the organization.
  • Partner with teams to create incident response plans and conduct vulnerability assessments.
  • Lead advanced identity protection initiatives in Entra IAM, focusing on Zero Trust principles.
  • Implement security management practices for IAM and ensure compliance with best practices.
  • Collaborate on securing Microsoft Azure solutions in a multi-tenant environment.
  • Research and implement industry best practices for securing infrastructures and systems.
  • Mentor team members to enhance their technical skill sets.

Benefits

  • Opportunity to lead impactful cybersecurity initiatives that affect the entire organization.
  • Work in a dynamic environment partnering with diverse IT and business teams.
  • Exposure to advanced identity protection technologies and modern cloud environments.
  • Access to ongoing training and professional development opportunities.
  • Involvement in shaping security technology strategies at an organizational level.
Full Job Description
Overview

GATX is seeking a Senior Information Security Engineer to provide technical leadership for cybersecurity initiatives that protect the organization's data, systems, and cloud environments. This role partners across IT and the business to reduce cyber risk, strengthen security controls, and advance the maturity of the cybersecurity program.

Responsibilities
  • Develop and maintain security standards and guidelines that protect company systems, data, and networks. Manage security tools, software, and the implementation of new controls, including the design and maintenance of complex cybersecurity controls throughout the system lifecycle. Support initiatives that reduce evolving cyber risk by applying a strong understanding of the organization’s threat landscape.
  • Partner with cross-functional teams to develop incident response plans and protocols. Oversee vulnerability assessments and penetration testing to identify system and network weaknesses and coordinate with IT teams to remediate issues. Monitor networks and systems for security incidents, take action to reduce the risk of data loss or unauthorized access, and investigate events by analyzing data, coordinating response efforts, and reporting findings to management and IT teams.
  • Lead the development and deployment of advanced identity protection capabilities in Entra IAM to strengthen security and align with best practices. Improve authentication security in alignment with Zero Trust principles and increase resilience against identity-based threats. Own administration of BeyondTrust PAM, Entra IAM, including secure configuration, timely updates, and user support. Partner with IT teams to expand identity platform integrations and improve efficiency in identity and privileged access management.
  • AWS Security Administration
    • Security Management: Implement IAM policies, manage access controls, and ensure compliance with security best practices
    • Automation & Scripting: Automate routine tasks using tools like AWS CLI, CloudFormation, or Terraform
    • Collaboration: Work with development teams to support CI/CD pipelines and scalable application deployments in a secure manner.
  • Collaborate in securely implementing Microsoft Azure Solutions in a multi-tenant cloud environment. Working closely with LAN Administrators responsible for building and maintaining various technical systems, subscriptions, projects and knowledge bases across local and cloud environments to ensure operational and support teams have access to highly secure and highly available tools and systems necessary for business operations. Utilize experience and knowledge to better secure Microsoft and Unix/Linux technologies such as SharePoint, Exchange, Active Directory, Microsoft Server Operating Systems, Intune, Windows 10/11, IBM AIX and Red Hat solutions.
  • Research and remain current on technical and industry practices for securing operating systems, hardware, and infrastructure services. Implement security best practices where appropriate and advise the Global Head of IT Security and Senior Manager of Information Security on security technology strategies.
  • Technical subject matter expert who can coach and mentor others to assist in their development.
Qualifications
  • Bachelor's degree or equivalent experience.
  • 7+ years of information security experience and 5+ years supporting network or infrastructure technologies.
  • Experience with IAM technologies, including Entra ID, Conditional Access, MFA, and privileged access management.
  • Experience securing AWS and/or Azure cloud environments.
  • Strong understanding of cybersecurity principles, network security, vulnerability management, and incident response.
  • Experience with scripting, automation, and modern DevOps/CI-CD environments.
  • Ability to communicate technical concepts to non-technical audiences and build strong cross-functional relationships.
  • CISSP, CISM, CRISC, or equivalent certification required or in progress.
  • AWS Security Specialty certification preferred.
Posting DurationThis posting will remain open until the role is filled. As of the post date, the salary range for this position is: MinUSD $92,700.00/Yr. MaxUSD $160,000.00/Yr. This role may be eligible to participate in the Companys short-term incentive plan, the details of which will be provided to the applicant upon hire. This range is a reasonable estimate and takes into account several factors that are considered in making compensation decisions, including, but not limited to, geographic location, skill set, experience, education, training, internal equity, and other business needs.

About GATX Corp

GATX Corporation leases, operates, manages, and remarkets assets in the rail, marine, and industrial equipment markets. The company operates through four segments: Rail North America, Rail International, Portfolio Management, and American Steamship Company (ASC). The Rail North America segment primarily leases railcars and locomotives. The Rail International segment leases railcars, as well as operates and manages railcars and fleets for third-party investors. The Portfolio Management segment provides leasing, asset remarketing, and management solutions for aircraft, railcars, and marine assets. The ASC segment operates a fleet of vessels that provide waterborne transportation of dry bulk commodities, such as iron ore, coal, limestone aggregates, and metallurgical limestone for steel makers, automobile manufacturing, electricity generation, and non-residential construction markets. GATX Corporation was founded in 1898 and is headquartered in Chicago, Illinois.
Learn more about GATX Corp
Size
1,863 employees
Market Cap
$3.8 billion
Industry
Net Income
$151.3 million
Founded
1898
5 Year Trend
-2.4%
Revenue
$1.2 billion
NASDAQ

Similar Jobs

More Jobs at GATX Corp

More Information Technology Jobs

Find similar Sr. Information Security Engineer jobs: