2

Remote Security Control Assessor Jobs in Illinois

Senior Security Engineer

Chicago, IL · Remote

$118K - $161K/yr

... a fully remote, SaaS- and cloud-native healthcare platform -- and you'll do it as a hands-on ... control flaw classes (IDOR, broken access control, exposed secrets, insecure upload) that matter ...

This position will be based out of Lake Forest, IL, Charlotte, NC, or remote. As Security Solutions ... Participate in governance committees and support control adherence documentation. CrossFunctional ...

This position will be based out of Lake Forest, IL, Charlotte, NC, or remote. As Security Solutions ... Participate in governance committees and support control adherence documentation. CrossFunctional ...

This position will be based out of Lake Forest, IL, Charlotte, NC, or remote. As Security Solutions ... Participate in governance committees and support control adherence documentation. CrossFunctional ...

Information Security Architect

Springfield, IL · On-site +1

$61.43 - $92.15/hr

Corporate Services o Schedule: Full Time o Location: 100% remote, accepting applicants that can ... Certified in Risk and Information Systems Control (CRISC); Cloud security certifications (AWS ...

... security, and compliance standards. What your impact will be: Project Planning, Scope Management ... Demonstrate outstanding project control, ensuring that project plans/schedules, project budgets ...

... security, and compliance standards. What your impact will be: Project Planning, Scope Management ... Demonstrate outstanding project control, ensuring that project plans/schedules, project budgets ...

RACF Mainframe Security Engineer

Chicago, IL · On-site +1

$70K - $140K/yr

Description This position is a remote position. Summary: The RACF Mainframe Security Engineer is accountable for delivery and implementation of IAM technologies across the bank. Duties ...

RACF Mainframe Security Engineer

Chicago, IL · On-site +1

$70K - $140K/yr

Description This position is a remote position. Summary: The RACF Mainframe Security Engineer is accountable for delivery and implementation of IAM technologies across the bank. Duties ...

Showing results 41-60

Remote Security Control Assessor information

See Illinois salary details

$8

$56

$75

How much do remote security control assessor jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for remote security control assessor in Illinois is $56.95, according to ZipRecruiter salary data. Most workers in this role earn between $48.89 and $65.91 per hour, depending on experience, location, and employer.

What is a remote security control assessor?

A Remote Security Control Assessor evaluates and ensures that an organization's security controls comply with industry standards and regulations. They perform risk assessments, analyze security policies, and recommend improvements to enhance cybersecurity. Working remotely, they assess systems, review documentation, and collaborate with internal teams and stakeholders. Their goal is to identify vulnerabilities and ensure that security frameworks align with compliance requirements such as NIST, ISO 27001, or FedRAMP.

What does a remote security control assessor do?

A Remote Security Control Assessor typically reviews security policies, analyzes technical controls, and conducts risk assessments to ensure compliance with industry standards and client requirements. Daily tasks often include evaluating documentation, coordinating virtual meetings with stakeholders, preparing assessment reports, and recommending remediation actions for identified vulnerabilities. You’ll collaborate with IT teams, compliance officers, and management to gather evidence and share assessment findings. Strong organizational and communication skills are essential, as much of the work is self-directed and relies on effective remote coordination with clients and internal teams.

What are the key skills and qualifications needed to thrive as a remote security control assessor?

To thrive as a Remote Security Control Assessor, you need expertise in information security frameworks, risk assessment methodologies, and IT auditing, typically supported by a bachelor's degree in cybersecurity or a related field. Familiarity with assessment tools (like Nessus or NIST compliance checklists), experience with GRC (governance, risk, compliance) platforms, and relevant certifications such as CISSP or CISA are highly valued. Excellent analytical skills, attention to detail, and strong written and verbal communication abilities help remote assessors excel, especially when working independently or with cross-functional teams. These skills are critical for accurately evaluating security controls, ensuring regulatory compliance, and communicating findings effectively in a remote work environment.

What are popular job titles related to Remote Security Control Assessor jobs in Illinois?

For Remote Security Control Assessor jobs in Illinois, the most frequently searched job titles are:

What job categories do people searching Remote Security Control Assessor jobs in Illinois look for?

The top searched job categories for Remote Security Control Assessor jobs in Illinois are:

What cities in Illinois are hiring for Remote Security Control Assessor jobs?

Cities in Illinois with the most Remote Security Control Assessor job openings:

Infographic showing various Remote Security Control Assessor job openings in Illinois as of August 2026, with employment types broken down into 62% Full Time, 29% Part Time, and 9% Contract. Highlights an 100% Remote job distribution, with an average salary of $118,450 per year, or $56.9 per hour.

Senior Security Engineer

Oshi Health

Chicago, IL • Remote

$118K - $161K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 7 days ago


Job description

Senior Security Engineer

Are you a security engineer who wants to build a program from the foundation up — not inherit and babysit someone else's?

Do you thrive in a fast-paced, AI-native environment where security's job is to enable speed safely, not slow it down out of fear?

Are you energized by the idea that the systems you protect hold the most sensitive health data of real people trying to get their lives back from chronic GI conditions?

If so, you might be a perfect fit for our team of professionals dedicated to eliminating the impact of digestive health conditions through innovative GI care.

The Role

As Oshi Health's first dedicated Senior Security Engineer, you will own the technical security of a fully remote, SaaS- and cloud-native healthcare platform — and you'll do it as a hands-on builder, not a policy desk. Reporting to the Sr. Director, Security & IT, you will set the security architecture standards for our product and AWS environments, harden how we manage identity and secrets, and build security into our engineering and AI workflows from the start.

This is a uniquely forward-looking role. Oshi is transitioning to an agentic software development lifecycle in which AI agents help plan, build, review, and eventually deploy code against a data platform that touches regulated data. You will design the guardrails that make that transition safe: the security gates in the pipeline, the controls on agent-written code, and the lifecycle management for the non-human identities those agents use. You'll partner closely with Product & Engineering to keep the path paved — moving fast with confidence rather than slow out of fear — and with the Sr. Director on HIPAA, SOC 2, and audit readiness. If you want a security role where the work is genuinely novel and your fingerprints are on the foundation, this is it.

What you'll do
  •     Own application and product security: threat modeling, secure design review, and secure code review, with a focus on the authorization and access-control flaw classes (IDOR, broken access control, exposed secrets, insecure upload) that matter most for a member-facing healthcare app and its APIs.
  •     Make our existing tooling do real work: enforce and tune GitHub Advanced Security (CodeQL, secret scanning, push protection) as required status checks, with branch protection and CODEOWNERS-enforced human review on security-sensitive paths.
  •     Design and own the security architecture for our agentic SDLC — phase-gate criteria for each stage of the AI transition, deterministic out-of-band controls so that agent-written code is never its own security gate of record, and tested "clawback" procedures for when risk spikes.
  •     Build and run non-human identity (NHI) and secrets management at scale: service accounts, scoped tokens, OAuth grants, and machine credentials — provisioning, rotation, least privilege, and decommissioning across our SaaS and AWS estate.
  •     Secure our AWS environment: IAM/IC, network segmentation, logging, configuration baselines, encryption, and workload protection across S3, EKS and Terraform (and supporting services in coordination with our DevOps team)
  •     Run security review of AI and third-party vendor integrations before they touch PHI — evaluating data flows, retention, and data-loss-prevention needs, and applying healthy skepticism to AI-native vendors' security claims.
  •     Stand up and tune detection and response Leverage AI and build behavioral baselines and anomaly detection for identity, SaaS, AWS, and AI/agent usage logs.
  •     Support HIPAA Security Rule technical safeguards in partnership with the Sr. Director — encryption at rest, audit controls and activity logging, vulnerability scanning, and asset inventory.
  •     Own the vulnerability management and penetration-testing cadence: Own the relationship with an external pen tester, drive findings to closure, shrink time-to-remediation, and move recurring issues left into the development process.
  •     Reduce attack surface through SaaS and identity rationalization, and write the security policies, standards, and runbooks the program needs as it matures.
  •     Build automation (scripting, infrastructure-as-code) so that a small security function operates with outsized leverage.
Who you are
  •     6+ years in security engineering, with demonstrated depth in application/product security and cloud security (AWS). Experience in healthcare, fintech, or another regulated, data-sensitive environment is a strong plus.
  •     Hands-on with secure SDLC tooling: SAST/DAST, GitHub Advanced Security / CodeQL, secret scanning, and software supply-chain / dependency security.
  •     Strong in identity and access management: Okta, OAuth/OIDC, SAML, phishing-resistant MFA, and the management of non-human identities and secrets (e.g., AWS Secrets Manager, or equivalents).
  •     Familiarity with — or genuine drive to go deep on — securing AI/LLM and agentic systems: prompt injection, agent authorization and over-permissioning, NHI sprawl, and model/supply-chain risk. You don't need to have done it for a decade; almost no one has. You do need to be the kind of engineer who runs toward a problem the industry hasn't solved yet.
  •     Comfortable being the sole security specialist on a small, cross-functional team — you prioritize ruthlessly by risk, you're pragmatic about cost, and you can explain a tradeoff to both an engineer and a non-technical executive without changing the truth of it.
  •     Working knowledge of the HIPAA Security Rule, SOC 2, and the NIST Cybersecurity Framework. Experience operating a compliance-automation platform is a plus.
  •     Proficient with scripting and automation (Python and at least one shell) to scale yourself.
  •     A curious, builder's mindset — you'd rather pave a safe path than post a "do not enter" sign, and you find the right technology to increase both security and velocity.
  •     Bachelor's degree in Computer Science or equivalent practical experience.

Certifications (nice to have, not required): one or more of OSCP, GIAC (e.g., GWAPT, GCSA, GCLD), AWS Certified Security – Specialty, CISSP, or Okta Certified Professional.

We make healthcare more equitable and accessible:

  • Mission-driven organization focused on innovative digestive care.
  • Thrive on diversity with monthly DEIB discussions and activities.
  • Virtual-first culture: Work from home anywhere in the U.S.
  • Live our core values: Own the outcome, Do the right thing, Be direct & open, Learn & improve, Team, Thrive on diversity.

We take care of our people:

  • Competitive compensation and meaningful equity.
  • Employer-sponsored medical, dental, and vision plans.
  • Access to a "Life Concierge" through Overalls, because we know life happens.
  • Tailored professional development opportunities to help you grow.

We rest, recharge, and re-energize:

  • Flexible paid time off — take what you need, when you need it.
  • 13 paid company holidays to power down.
  • Team events, such as virtual cooking classes, games, and more.
  • Recognition of professional and personal accomplishments.

Oshi Health's Core Values:

  1. Own the Outcome
  2. Do the Right Thing
  3. Be Direct & Open
  4. Learn & Improve
  5. TEAM - Together Everyone Achieves More
  6. Thrive on Diversity

If you're ready to lead Oshi Health's security and IT operations and help revolutionize healthcare technology, we'd love to hear from you!

Oshi Health is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Compensation Range
$170,000—$190,000 USD

Note: This job description serves as a general overview and may be subject to change based on organizational needs and requirements.

Oshi Health is an equal opportunity employer that is committed to creating a diverse work environment. To do that, we champion a workplace where each and every person is treated with dignity and respect and is valued for their unique perspective and contributions.
Oshi Health's policy is to maintain a working environment that encourages mutual respect, promotes harmonious and congenial relationships between employees, and is free from all forms of discrimination and harassment of any employee (or applicant for employment or service provider) by anyone, including supervisors, co-workers, vendors, or clients. Harassment and discrimination in any manner or form is expressly prohibited. There is no tolerance for discrimination or unequal treatment of any kind on the basis of race, color, religion, creed, gender, sex, sexual orientation, gender identity or expression, pregnancy, sexual and reproductive health decisions, national origin, age, disability, genetic information, marital status or civil partnership/union status, familial status, military or veteran status, predisposition or carrier status, domestic violence victim status, alienage or citizenship status, unemployment status, sexual violence or stalking victim status, caregiver status, or any other characteristic protected by law.

This practice applies to all terms, conditions and privileges of employment including, but not limited to, recruitment, selection, promotion, demotion, transfer, layoff, rehire, termination of employment, development and training, compensation, benefits and retirement.

For more information, visit us at www.oshihealth.com  

Oshi Health will never contact job candidates via text message or any other messaging platform including WhatsApp, Signal, and Telegram. All official correspondence will occur through email. We will never ask you to share bank account information, cash a check from us, or purchase software or equipment as part of your interview or hiring process. If you have concerns, please reach out to careers@oshihealth.com, and we'll confirm whether you're engaging with one of our Oshi teammates!