Security architect jobs in Brockton, MA - 288 jobs
All
Security Architect
Security System Engineer
Information Security Director
Senior Security Engineer
Information Systems Security Officer
Information Security Manager
Senior Security Engineer
Flexcar
Security architect job in Boston, MA
Title: Senior Security Engineer Type: Full‑time exempt, 50 hours per week Compensation: $112.5K-$155K* + 15% bonus + Full Benefits day one
Who Are We
We are fiercely disrupting the concept of automobile ownership. Flexcar is on a mission to replace car ownership for the majority of car owners. We are currently operational in 4 markets and continuing to grow. Our goal is to offer a flexible alternative to car ownership that puts our members in the driver's seat of their budget and their vehicle. Flexcar covers all maintenance costs, insurance costs, registration costs, and more, to provide the flexible ownership alternative that is simple and seamless for our members.
Flexcar empowers all walks of life to have the flexibility of a car of their own without the hassles of traditional car ownership.
Role Overview
Flexcar is seeking a dedicated Security Engineer as an individual contributor responsible for safeguarding a broad attack surface that includes Flexcar's web and mobile applications, physical locations, and its remote team members. This is a highly collaborative role that will require working across all facets of the Flexcar organization.
You will be expected to champion the development and implementation of proactive defense measures across the entire organization, collaborating across multiple teams to maintain our high security standards, and educating members of the organization in the realms of general security awareness as well as best practices when it comes to delivering software.
This role requires a candidate who is a self‑starter and capable of managing multiple requests from various teams within the Flexcar organization.
Key Requirements Web Application Security
Hands‑on experience with managing a Web Application Firewall, including the creation of custom rules, rate limiting, and managing vendor rulesets.
Must understand the current OWASP Top 10 and demonstrate the ability to educate others on how to identify and mitigate associated risks.
Must have experience with deploying and managing defensive measures, aka “Blue Teaming”.
Must have experience organizing and managing third‑party penetration tests and ensuring that all findings are addressed in a timely manner.
Hands‑on experience with threat modeling.
Experience leading tabletop sessions with members of the engineering team as well as non‑technical members of the organization.
Demonstrated ability to conduct Open‑Source Intelligence (OSINT) against the organization and its resources.
Demonstrated ability to conduct internal offensive security campaigns against Flexcar's web application and the organization itself.
Secure Infrastructure & Tooling
Experience creating CI/CD workflows and utilizing open‑source security tools.
Experience with static analysis tools for code, dependencies, and container images.
Familiarity with AWS security tools and resources.
Familiarity with Terraform.
Experience with hardening Microsoft Entra (Azure AD) and O365.
Proven experience with Identity and Access Management.
Experience with administration of common Managed Detection and Response (MDR) solutions.
Hands‑on experience with scripting languages like Python.
Incident Management
Proven ability to serve as a Security Incident Commander.
Ability to use the tools available for leading forensic analyses and guiding investigative efforts.
Demonstrated ability to conduct threat hunting based on new threats as they are discovered or disclosed by the larger security community.
Governance, Risk, and Compliance
Familiarity with maintaining compliance with frameworks such as PCI, CCPA, and US Data Privacy.
Familiarity with compliance automation platforms.
Experience creating and maintaining foundational security policies.
Ability to manage Flexcar's third‑party vendor assessment process.
Ability to create both general security awareness content for the organization as well as targeted training for a variety of individual teams.
What Tops Off the Tank
Rest & Relax! Flexible Paid Time Off and Sick Time
Save for Your Future! 401(k) with company match from day one of hire
Benefits: Excellent, low‑cost healthcare coverage including medical, dental, vision, eligibility day one
Drive a Flexcar! Discounted employee rate on Flexcar products and no annual membership fee
Weekly Pay
and other amazing perks!
*Actual compensation will vary depending on geographic location, job‑related knowledge, skills, experience, and market conditions.
Disclaimer
This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at any time at the sole discretion of the Employer.
Flexcar is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. Flexcar provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
#J-18808-Ljbffr
$112.5k-155k yearly 5d ago
Looking for a job?
Let Zippia find it for you.
Senior Security Engineer: Secure Data Platforms
Intersystems Corporation 4.7
Security architect job in Boston, MA
A leading data technology provider in Boston is seeking a Senior Security Engineer. In this key role, you will enhance the security of data platforms while collaborating with cross-functional teams. Responsibilities include designing securearchitectures, analyzing vulnerabilities, and mentoring staff. A Bachelor's in a technical discipline and substantial experience in security engineering are required. This role offers a competitive salary range of $112,000 - $160,000 USD and substantial benefits including health insurance and 401(k) contributions.
#J-18808-Ljbffr
$112k-160k yearly 5d ago
Principal Cloud Security Architect
Labelbox 4.3
Security architect job in Boston, MA
Role OverviewThe Principal Cloud SecurityArchitect evaluates cloud architectures, identity models, permissions, and security controls across large-scale environments. This role focuses on identifying architectural risks, misconfigurations, and long-term security design gaps.
What You'll Do- Assess cloud architectures (AWS, Azure, GCP) for security gaps - Review IAM configurations, network segmentation, and resource policies - Identify misconfigurations, privilege risks, and insecure patterns - Summarize architectural flaws and provide structured mitigation guidance - Validate alignment with security frameworks and best practices - Support recurring assessments of cloud environments and deployment patterns What You BringMust-Have:- Deep experience in cloud securityarchitecture - Strong understanding of IAM, network design, and cloud service models - Ability to document complex architectures in clear, structured form Nice-to-Have:- Experience with multi-cloud, zero-trust, or high-compliance environments
360 IT Professionals is a Software Development Company based in Fremont, California that offers complete technology services in Mobile development, Web development, Cloud computing and IT staffing. Merging Information Technology skills in all its services and operations, the company caters to its globally positioned clients by providing dynamic feasible IT solutions. 360 IT Professionals work along with its clients to deliver high-performance results, based exclusively on the one of a kind requirement.
Job Description
We are looking to fill multiple full time positions as Information SecurityArchitects in Cumberland RI.
Qualifications
A minimum of 5+ years of relevant security domain experience.
3+ years of hands on technical experience in network and perimeter security
A minimum of 3 years in an architecture role and be able to lead/step up as needed
Demonstrated expertise in integrating/developing security solutions in a 7x24 production environment
Prior experience in defining the technology strategy for a large, global organization, and the ability to influence and persuade peers and colleagues in other reporting structures
Strong Plus Skills:
Industry recognized certifications such as CISA, CISM, CISSP, or SANS GIAC are a plus
Virtualization Security experience is a strong plus (VMware ESX 6.x, Hytrust, Hypervisor, in-hypervisor malware control. Virtual NIC, NSX or equivalent.)
Knowledge of risk assessment methodologies, IT policies and standards
Knowledge of vulnerability identification tools, Qualys, Veracode, Qualys WAS.
Additional Information
In person interview is acceptable.
$104k-135k yearly est. 60d+ ago
Google Cloud Security Architect
Slalom 4.6
Security architect job in Boston, MA
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies
As a Consultant or Senior Consultant, you will collaborate with cross-functional teams, including IT, security, and business units, to design and implement Google Cloud-based application innovation solutions. You will work alongside experienced cloud architects, data scientists, and other specialists, ensuring the successful delivery of scalable, cloud-native applications and AI-powered solutions.
What You'll Do
* Stay current with security trends, technologies, and best practices around Google Cloud solutions, leveraging tools like Cloud IAM, Cloud Security Command Center, BeyondCorp, and Cloud Armor.
* Define and guide transformational security strategies for Google Cloud environments, ensuring alignment with Google's Zero Trust and BeyondCorp principles.
* Translate complex regulatory requirements (e.g., GDPR, SOC 2, HIPAA) and technology standards into actionable functional and technical requirements for cloud and hybrid environments, ensuring security and compliance.
* Lead teams through various phases of gap analyses, including security assessments, remediation planning, roadmap development, and implementation of remediation actions using Google Cloud-native tools.
* Deliver on the vision, architecture, execution, and quality assurance of security projects on Google Cloud, driving initiatives that secure enterprise workloads and data.
* Guide stakeholders and senior leaders on aligning security solutions with broader business goals, ensuring the architecture follows Google Cloud's security best practices and roadmap.
* Establish securityarchitecture patterns based on Google Cloud security frameworks and industry standards to meet the unique needs of enterprise clients.
* Collaborate with other Google Cloud architects and security teams to continuously improve security knowledge assets and best practices, ensuring the most effective security solutions for clients.
* Design and architect solutions to secure Generative AI models and applications against adversarial attacks, prompt injection, and their potential misuse for malicious cyber activities.
What You'll Bring
* Proven experience with Google Cloud securityarchitecture, with hands-on experience in tools like Cloud IAM, VPC Service Controls, Cloud DLP, and Cloud Armor.
* Strong background in defining and implementing Zero Trust and BeyondCorp security models within Google Cloud environments.
* Familiarity or direct experience with Identity and Access Management (IAM), Data Protection, Vulnerability Management, and Cloud Security solutions in Google Cloud.
* Extensive experience with security design patterns specific to Google Cloud, as well as hybrid and multi-cloud securityarchitecture.
* Experience in security and risk advisory consulting, particularly related to cloud security transformations.
* Ability to lead the development and implementation of cloud security roadmaps aligned with business goals and compliance needs.
* Familiarity with Google Cloud's Artificial Intelligence (AI) capabilities (e.g., Vertex AI, Generative AI services, Model Armor) including their applications, associated security risks (e.g., prompt injection, data poisoning, privacy concerns), and proven strategies for implementing security controls, governance, and responsible AI practices.
* Relevant certifications are strongly desired, including (but not limited to):
* GCP Professional Security Engineer
* GCP Professional Cloud Architect
* CISSP
* Security+
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices. For this position the base salary pay ranges are listed below. In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
East Bay, San Francisco, Silicon Valley:
* Consultant: $120,000-$177,000
* Senior Consultant: $140,000-$203,000
San Diego, Los Angeles, Orange County, Seattle, Houston, New Jersey, New York City, Westchester, Boston, Washington DC:
* Consultant: $110,000-$162,000
* Senior Consultant: $130,000-$186,000
All other locations:
* Consultant: $105,000-$148,000
* Senior Consultant: $115,000-$171,000
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
We are accepting applications until 12/31.
$140k-203k yearly 39d ago
Systems Security Engineer
General Dynamics Mission Systems 4.9
Security architect job in Dedham, MA
Basic Qualifications
Requires a Bachelor's degree in Systems Engineering, or a related Science, Engineering, Technology or Mathematics field. Also requires 5+ years of job-related experience, or a Master's degree plus 3 years of job-related experience. Agile experience preferred.
CLEARANCE REQUIREMENTS: Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
We are seeking a Systems Security Engineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
***Please note you will be onsite 100%.
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $112,924.00 - USD $125,275.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
$112.9k-125.3k yearly Auto-Apply 60d+ ago
Director, Information Security
Re-Krut Services
Security architect job in Boston, MA
Extensive knowledge of HIPAA and HITECH. Knowledge of and experience with Information Security frameworks such as HiTRUST, NIST, or ISO 27001. Bachelor's degree in information security, information assurance, information technology, computer science, or a related discipline.
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or related certification.
Five (5) years in an information security operations or management role.
Passion for the mission of Health Leads and strong commitment to Health Leads' core values: belief in collective strength and the power of shared work, constant and courageous learning, celebrating our victories and each other, and stepping up leaders in a common vision.
Experience with information security for cloud environments and/or software-as-a-service (SaaS) platforms.
Knowledge of security-related technologies and processes, including but not limited to: data loss prevention (DLP), identity and access management (IAM), endpoint security, vulnerability and configuration management, security information and event management (SIEM), incident response and digital forensics, disaster recovery/business continuity planning, network security (LAN/WAN).
Ability to communicate complex ideas and information both
verbally
and writing, in a clear, concise, and effective manner to technical and non-technical audiences including customers and colleagues.
Superior capabilities for partnering;
ability to be effective as both a team member and as a leader of teams in defining objectives, staying on task and reaching consensus;
soliciting participation, challenging ideas and summarizing accomplishments and planned actions.
Show integrity and ethical behavior; respect confidentiality, business ethics and organizational standards.
Ability to
formulate
the cost benefit of security initiatives in the context of
overall
business risk mitigation and the organization's operational objectives.
Ability to compare, contrast and
prioritize
among alternative approaches to meet those objectives.
$122k-182k yearly est. 1d ago
Manager, Information Security Compliance & Risk
Analysis Group 4.8
Security architect job in Boston, MA
Analysis Group is one of the largest international economics consulting firms, with more than 1,500 professionals across 15 offices in North America, Europe, and Asia. Since 1981, we have provided expertise in economics, finance, health care analytics, and strategy to top law firms, Fortune Global 500 companies, and government agencies worldwide. Our internal experts, together with our network of affiliated experts from academia, industry, and government, offer our clients exceptional breadth and depth of expertise.
The Manager, Information Security Compliance and Risk is responsible for leading the firm's Governance, Risk, and Compliance (GRC) program, including regulatory compliance, enterprise risk management, and assurance activities that support client requirements and regulatory obligations.
This role also serves as the primary owner of Information Security AI governance, ensuring that the firm's use of AI and machine learning technologies aligns with security, privacy, regulatory, and client expectations.
The role manages a team of three Information Security Analysts and owns SOC 2 and ISO 27001 certification programs, while partnering closely with Legal, Compliance, Privacy, IT, and Security Engineering and Operations to ensure effective control design, evidence collection, risk management, and continuous improvement.
Responsibilities:
Governance and Compliance Leadership
* Own and maintain the firm's information security governance framework, including policies, standards, and procedures.
* Lead annual SOC 2 and ISO 27001 audit cycles, including audit readiness, evidence coordination, and remediation tracking.
* Ensure ongoing compliance with client, regulatory, and contractual information security requirements.
* Manage policy exceptions, risk acceptances, and documentation of compensating controls.
Regulatory Authorization and Assurance
* Lead the renewal and ongoing maintenance of government and client security authorizations, attestations, and approvals required for regulated engagements.
* Coordinate cross-functional evidence collection and control validation to support authorization renewals and periodic reassessments.
* Track authorization requirements, renewal timelines, and control changes to ensure continuous eligibility for regulated work.
AI Security Governance
* Lead the Information Security AI governance program, ensuring secure, responsible, and compliant use of AI technologies across the firm.
* Partner with Legal, Privacy, Compliance, and business stakeholders to define and maintain AI security requirements, risk assessments, and usage standards.
* Establish and maintain security controls for AI-enabled tools, including data handling, access controls, model usage restrictions, and third-party AI risk.
* Support client and regulatory inquiries related to AI security posture and governance practices.
* Track emerging AI-related regulatory and security requirements and assess their impact on firm policies and controls.
Risk Management
* Maintain and mature the enterprise information security risk register.
* Facilitate periodic risk assessments, including risks associated with AI usage, data processing, and third-party technologies.
* Develop and report meaningful risk metrics and dashboards for leadership review.
* Translate technical and operational risks into clear business-impact language.
Third-Party and Emerging Risk Governance
* Oversee third-party security risk management in partnership with Legal.
* Lead structured reviews of vendor security posture, including AI and SaaS providers.
* Track remediation plans and ongoing monitoring of third-party and AI-related risks.
Audit and Assurance Coordination
* Serve as the primary liaison for internal and external audits related to information security.
* Coordinate evidence collection across IT, Security Engineering, Privacy, and business stakeholders.
* Track findings, corrective actions, and continuous improvement initiatives.
Team Leadership
* Directly manage three Information Security Analysts.
* Set priorities, provide mentorship, and support professional development.
* Establish consistent processes, documentation standards, and performance expectations across the GRC function.
Cross-Functional Collaboration
* Partner closely with Security Engineering and Operations to align governance requirements with technical controls.
* Work with Legal, Compliance, Privacy, and Data Science teams on regulatory interpretation and AI governance requirements.
* Support client security inquiries, assessments, and due diligence requests.
Expected Outcomes
* Sustained audit readiness for SOC 2 and ISO 27001 with minimal disruption.
* Clear, measurable visibility into information security and AI-related risk posture.
* Consistent, scalable governance processes supporting firm growth and responsible AI adoption.
* Strong alignment between governance requirements and operational security controls.
Qualifications & Skills
* Bachelor's degree required; degree in information security, risk management, or a related field preferred.
* 7 to 10 years of experience in information security, GRC, audit, or risk management required.
* Prior experience managing SOC 2 and or ISO 27001 programs required.
* Demonstrated people management or team leadership experience.
* Professional certifications such as CISSP, CISM, CRISC, CGRC, or ISO 27001 Lead Implementer or Auditor.
* Experience with GRC platforms and risk management tooling.
* Experience supporting AI governance, data governance, or emerging technology risk programs.
* Experience supporting client-driven security assessments in a professional services environment.
* An inclusive and growth-oriented mindset, strong interpersonal skills, and an ability to work across differences.
* To the extent permitted by applicable law, eligible candidates must be authorized to work in the United States without sponsorship or restriction, now and in the future.
Analysis Group embraces equal opportunity. We are committed to building teams that bring a variety of backgrounds, perspectives, and skills, as we believe that a strong and inclusive workforce directly supports our goal of providing the highest-quality work. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other class protected under applicable federal, state, or local law, and we encourage candidates of all backgrounds to apply.
Analysis Group offers competitive compensation and a comprehensive benefits package. The estimated salary range for this position is $175,000-$200,000. Compensation offered will be based on a number of factors including work experience, education, and skill level. This role is eligible for a discretionary annual bonus that is determined in large part by individual performance. To learn more about our benefit offerings, click here.
#LI-Hybrid
Privacy Notice
For information about Analysis Group's privacy practices, please refer to the applicable Analysis Group privacy policy.
* Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
* Please view the EEOC's "Know Your Rights" poster here.
$175k-200k yearly Auto-Apply 4d ago
Manager, Information Security Compliance & Risk
Job Listingsanalysis Group, Inc.
Security architect job in Boston, MA
Analysis Group is one of the largest international economics consulting firms, with more than 1,500 professionals across 15 offices in North America, Europe, and Asia. Since 1981, we have provided expertise in economics, finance, health care analytics, and strategy to top law firms, Fortune Global 500 companies, and government agencies worldwide. Our internal experts, together with our network of affiliated experts from academia, industry, and government, offer our clients exceptional breadth and depth of expertise.
The Manager, Information Security Compliance and Risk is responsible for leading the firm's Governance, Risk, and Compliance (GRC) program, including regulatory compliance, enterprise risk management, and assurance activities that support client requirements and regulatory obligations.
This role also serves as the primary owner of Information Security AI governance, ensuring that the firm's use of AI and machine learning technologies aligns with security, privacy, regulatory, and client expectations.
The role manages a team of three Information Security Analysts and owns SOC 2 and ISO 27001 certification programs, while partnering closely with Legal, Compliance, Privacy, IT, and Security Engineering and Operations to ensure effective control design, evidence collection, risk management, and continuous improvement.
Responsibilities:
Governance and Compliance Leadership
Own and maintain the firm's information security governance framework, including policies, standards, and procedures.
Lead annual SOC 2 and ISO 27001 audit cycles, including audit readiness, evidence coordination, and remediation tracking.
Ensure ongoing compliance with client, regulatory, and contractual information security requirements.
Manage policy exceptions, risk acceptances, and documentation of compensating controls.
Regulatory Authorization and Assurance
Lead the renewal and ongoing maintenance of government and client security authorizations, attestations, and approvals required for regulated engagements.
Coordinate cross-functional evidence collection and control validation to support authorization renewals and periodic reassessments.
Track authorization requirements, renewal timelines, and control changes to ensure continuous eligibility for regulated work.
AI Security Governance
Lead the Information Security AI governance program, ensuring secure, responsible, and compliant use of AI technologies across the firm.
Partner with Legal, Privacy, Compliance, and business stakeholders to define and maintain AI security requirements, risk assessments, and usage standards.
Establish and maintain security controls for AI-enabled tools, including data handling, access controls, model usage restrictions, and third-party AI risk.
Support client and regulatory inquiries related to AI security posture and governance practices.
Track emerging AI-related regulatory and security requirements and assess their impact on firm policies and controls.
Risk Management
Maintain and mature the enterprise information security risk register.
Facilitate periodic risk assessments, including risks associated with AI usage, data processing, and third-party technologies.
Develop and report meaningful risk metrics and dashboards for leadership review.
Translate technical and operational risks into clear business-impact language.
Third-Party and Emerging Risk Governance
Oversee third-party security risk management in partnership with Legal.
Lead structured reviews of vendor security posture, including AI and SaaS providers.
Track remediation plans and ongoing monitoring of third-party and AI-related risks.
Audit and Assurance Coordination
Serve as the primary liaison for internal and external audits related to information security.
Coordinate evidence collection across IT, Security Engineering, Privacy, and business stakeholders.
Track findings, corrective actions, and continuous improvement initiatives.
Team Leadership
Directly manage three Information Security Analysts.
Set priorities, provide mentorship, and support professional development.
Establish consistent processes, documentation standards, and performance expectations across the GRC function.
Cross-Functional Collaboration
Partner closely with Security Engineering and Operations to align governance requirements with technical controls.
Work with Legal, Compliance, Privacy, and Data Science teams on regulatory interpretation and AI governance requirements.
Support client security inquiries, assessments, and due diligence requests.
Expected Outcomes
Sustained audit readiness for SOC 2 and ISO 27001 with minimal disruption.
Clear, measurable visibility into information security and AI-related risk posture.
Consistent, scalable governance processes supporting firm growth and responsible AI adoption.
Strong alignment between governance requirements and operational security controls.
Qualifications & Skills
Bachelor's degree required; degree in information security, risk management, or a related field preferred.
7 to 10 years of experience in information security, GRC, audit, or risk management required.
Prior experience managing SOC 2 and or ISO 27001 programs required.
Demonstrated people management or team leadership experience.
Professional certifications such as CISSP, CISM, CRISC, CGRC, or ISO 27001 Lead Implementer or Auditor.
Experience with GRC platforms and risk management tooling.
Experience supporting AI governance, data governance, or emerging technology risk programs.
Experience supporting client-driven security assessments in a professional services environment.
An inclusive and growth-oriented mindset, strong interpersonal skills, and an ability to work across differences.
To the extent permitted by applicable law, eligible candidates must be authorized to work in the United States without sponsorship or restriction, now and in the future.
Analysis Group embraces equal opportunity. We are committed to building teams that bring a variety of backgrounds, perspectives, and skills, as we believe that a strong and inclusive workforce directly supports our goal of providing the highest-quality work. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other class protected under applicable federal, state, or local law, and we encourage candidates of all backgrounds to apply.
Analysis Group offers competitive compensation and a comprehensive benefits package. The estimated salary range for this position is $175,000-$200,000. Compensation offered will be based on a number of factors including work experience, education, and skill level. This role is eligible for a discretionary annual bonus that is determined in large part by individual performance. To learn more about our benefit offerings, click here.
#LI-Hybrid
Privacy Notice
For information about Analysis Group's privacy practices, please refer to the applicable Analysis Group privacy policy.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
Please view the EEOC's “Know Your Rights” poster here.
$175k-200k yearly Auto-Apply 2d ago
Director Information Security
Care New England 4.4
Security architect job in Warwick, RI
The Director, Information Security holds primary responsibility for safeguarding the Care New England (CNE) computing environment. This includes securing systems across all CNE operating units, directing enterprise-wide cybersecurity strategy, and ensuring compliance with HIPAA, PCI, and all applicable federal, state, local, and industry regulations.
The Director serves as the Chief Information Security Officer (CISO) for CNE, providing leadership in risk assessment, incident response, regulatory compliance, and cybersecurity governance. The role oversees information security tools, policies, vulnerability assessments, and monitoring systems; responds to security threats; leads mitigation activities; and collaborates closely with IS teams, Audit/Compliance, HR, Finance, and Legal.
This leader develops and manages the Information Security program, directs security staff, sets security standards, leads incident management, evaluates emerging technologies, manages vendor relationships, and ensures organizational readiness through education, training, and participation in business continuity and disaster recovery planning.
Duties and Responsibilities:
Develop and maintain the enterprise Information Security Program.
Establish protection goals, objectives, and metrics aligned with organizational strategy.
Serve as the Chief Information Security Officer (CISO) for CNE.
Coordinate with the Chief Privacy Officer to ensure compliant reporting of security incidents.
Implement, manage, and maintain enterprise security systems and applications.
Lead vulnerability assessments and ensure timely remediation.
Oversee security incident response, forensic investigations, and threat mitigation efforts.
Examine emerging technologies and assess their security implications.
Lead ongoing risk assessment programs addressing information security and privacy.
Ensure compliance with HIPAA, PCI, and applicable state and federal regulations.
Develop and implement security policies, standards, guidelines, and procedures.
Coordinate with IS teams, Audit/Compliance, HR, Finance, and Legal to align security efforts.
Participate in disaster recovery and business continuity planning.
Lead security education and awareness initiatives for staff across CNE.
Manage security vendors responsible for operations, maintenance, and enhancements.
Ensure vendor service delivery aligns with organizational security requirements and policies.
Negotiate and manage contracts and service-level agreements with external partners.
Manage, mentor, and develop information security staff.
Promote professional growth and maintain awareness of industry trends.
Provide input on resource allocation and security budgeting.
Maintain 24-hour on-call availability to support critical operational needs.
Perform other job-related duties as assigned.
Requirements:
Bachelor's Degree Required (computer science, MIS or related field)
Minimum of 7-10 years of progressive experience in information security, Strong technical background in infrastructure, network security, firewalls, and cloud environments, Experience conducting forensic investigations and managing enterprise security products.
Security certifications required: CISSP, GIAC, SANS, or similar. Audit certification preferred: CISA.
Participation in national and regional security organizations preferred.
Deep knowledge of cybersecurity principles, threat landscapes, and protection technologies.
Strong working knowledge of enterprise infrastructure, network security, firewalls, and cloud platforms.
Expertise in vulnerability management, forensic investigation, risk assessment, and incident response.
Ability to develop enterprise-wide policies and governance frameworks.
Strong communication skills for engaging executive leadership and cross-functional stakeholders.
Exceptional organization, analytical, and decision-making abilities.
Ability to manage technical teams and develop staff.
Strong vendor management and contract negotiation skills.
Ability to maintain confidentiality and uphold ethical and regulatory standards
Additional Information:
Care New England Health System (CNE) and its member institutions, Butler Hospital, Women & Infants Hospital, Kent Hospital, VNA of Care New England, Integra, The Providence Center, and Care New England Medical Group, and our Wellness Center, are trusted organizations fueling the latest advances in medical research, attracting top specialty-trained doctors, and honing renowned services and innovative programs to engage in the important discussions people need to have about their health.
EEOC Statement: Care New England is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Ethics Statement: Employee conducts himself/herself consistent with the ethical standards of the organization including, but not limited to hospital policy, mission, vision, and values.
Americans with Disability Act Statement: External and internal applicants, as well as position incumbents who become disabled must be able to perform the essential job-specific functions either unaided or with the assistance of a reasonable accommodation, to be determined by the organization on a case-by-case basis.
$129k-189k yearly est. 56d ago
Director of Information Security
Rxvantage
Security architect job in Providence, RI
We're seeking an experienced Director of Information Security to join our dynamic team and help drive our growth. In this role, your job will be to coordinate people and processes to instill a “security first” mindset for information management, systems development, acceptable use of these systems, staff awareness, and oversight of our vendors and partners.
This security professional will lead the management of risk and compliance of intellectual property, including day-to-day network and cyber tool monitoring, oversight, and ongoing security testing. The individual performing this role will enforce policies and procedures that ensure compliance with state, federal, and industry standards and requirements, ensuring our customers' and company's data are protected.
As the Director of Information Security, you will implement a security-readiness plan and provide guidance on how to quickly and effectively respond to any and all security incidents. In addition, this role will be instrumental in implementing controls and monitoring capabilities that provide visibility into the organization's security posture.
At RxVantage we transform how medical practices engage with life sciences resources and expertise to improve patient care. Our platform intelligently connects healthcare providers with the precise life sciences experts that they need, when they need them. As a result, medical practices stay on the cutting edge of patient care without disrupting workflows. Trusted by more than tens of thousands of healthcare practitioners and all major life sciences companies, RxVantage has powered millions of educational exchanges between healthcare teams and life sciences companies.
What you'll be doing:
Creating and implementing a security roadmap based on current and ongoing assessments
Ensuring policies are developed and maintained from both a business & technical perspective for the application, data, and security needs of the organization
Working with Legal to ensure agreements are congruent with policies
Overseeing the GRC (Governance Risk and Compliance) process
Ensuring compliance with industry laws and regulations for data security and privacy to include CCPR, 21 CFR Part 11, SOC2, NIST SP800-53
Monitoring the Identity and Access Management Framework
Benefits:
Competitive Salary
100% Company-Paid Premiums for Employee's Medical Health (HDHP 4500), Vision, and Dental Plans + $4,400 company sponsored contribution into an HSA
Short-term and Long-term Disability
Life Insurance
401k Matching
Work from Anywhere within the US
Flexible PTO
100% Paid Parental Leave
Post-Parental Leave Program - $5k stipend to assist with expenses, 4 week 100% paid “Ease-Back” return to work transition period
Charitable donation matching
Location:
Our “Work from Anywhere” philosophy is aimed at making sure that we recruit a diverse range of thought leadership to ensure that our technology is better able to serve local health care providers. Our goal is to hire the country's top talent and allow them to create an environment within the U.S. where they can do their best work.
About Our Organization:
At RxVantage, we're a small company with a big mission: to connect healthcare providers with the right life science experts and resources they need, exactly when they need them, to improve patient care. We've built a software platform that's changing the way providers learn about the latest medical advancements and technologies. Every year, our platform powers over 1 million educational exchanges between medical practices and life science companies, making it easier for them to stay informed and provide better care.
We have a proven product, a strong mission, and a passionate team. Now, we're looking for talented people to help us grow even more. If you're driven, eager to make an impact, and ready to be part of something meaningful, we want to hear from you!
---
RxVantage is an equal opportunity employer and dedicated to ensuring that we represent the local communities where our health and wellbeing providers serve as pillars of support to our family, friends, and neighbors. Our representation within these communities allows us to embody a diverse set of backgrounds, experiences, abilities and perspectives; and provide an inclusive environment for our team to feel empowered to be their authentic selves, without fear of harassment or discrimination.
$114k-170k yearly est. Auto-Apply 20d ago
Security Architect-INTL India
Insight Global
Security architect job in Boston, MA
Insight Global is sourcing for a SecurityArchitect to join a global consulting firm supporting the Cybersecurity organization. The ideal candidate will have at least 6-8 years of experience as a SecurityArchitect, with preference to candidates coming from the banking, financial, or consulting industries. In this position, you will be supporting global teams, helping build and architect solutions in alignment with BCG's security regulations. Expectations include, hands on threat modeling experience, knowledge of architectural artifacts and data flow diagram, and experience with OWASP Top 10. This position is a 6-month contract position with opportunity for fulltime hire. Candidates must be local to India, with preference to candidates local to NCR or Gurugram, working roughly 10:00 AM IST to 7:00 PM IST Monday through Friday.
Pay-rate: $18-23/hour USD. Exact pay rate will depend on experience and other factors.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to ********************.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: ****************************************************
Skills and Requirements
-At least 6 years' experience as a SecurityArchitect, preference to candidates with background in the banking, financial, or consulting industries
-Strong threat modeling experience, experience with hands on threat modeling based on STRIDE
-Strong knowledge of OWASP Top 10 for App, API, Cloud, and LLM
-Extensive experience with SecurityArchitecture across domains for SaaS, Cloud, and Enterprise Apps.
-Knowledge of architectural artifacts and data flow diagram
-Excellent communication skills, ability to work cross functionally with global teams and supporting stakeholders directly
-Ability to work independently and deliver efficient solutions based on defined company security regulations and guidelines
$18-23 hourly 24d ago
Information System Security Officer
Woods Hole Oceanographic Institution 4.7
Security architect job in Woods Hole, MA
Woods Hole Oceanographic Institution is searching for a highly skilled and cleared Information System Security Officer (ISSO) / Classified Systems Information Assurance Analyst to join our team, focusing exclusively on the security of classified information systems and networks. This critical role is responsible for ensuring the confidentiality, integrity, and availability of sensitive government information in accordance with stringent U.S. government (USG) security directives.
The ISSO will be instrumental in the authorization and accreditation(A&A) process, continuous monitoring, incident response, and the implementation of robust security controls for classified environments. The ideal candidate will possess a deep understanding of relevant security frameworks, policies, and a proven track record of maintaining secure classified systems. This is a regular, full-time, exempt position, and is eligible for full benefits.
ESSENTIAL FUNCTIONS
Authorization & Accreditation (A&A) / Risk Management Framework (RMF):
Lead or support the development, review, and submission of comprehensive security authorization packages (e.g., System Security Plans (SSPs), Risk Assessment Reports, Contingency Plans, Plan of Action and Milestones (POA&Ms)) for classified systems.
Ensure all classified systems maintain an Authority to Operate (ATO), Interim Authority to Test (IATT), or Authority to Connect (ATC) in accordance with RMF or legacy A&A processes (e.g., DIACAP).
Interpret and apply USG security policies, regulations, and guidelines, including but not limited to: NISPOM, DoD Instruction 8500.01, NIST SP 800-53, DCID 6/3, ICD 503, JSIG, and DISA STIGs.
Security Control Implementation & Enforcement:
Design, implement, and maintain security controls specific to classified systems, including secure configurations, access controls, auditing, media control, and classified spillage prevention/response.
Configure and manage specialized security tools relevant to classified environments (e.g., Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS), Data Loss Prevention (DLP) solutions).
Perform rigorous hardening of operating systems (Windows, Linux), applications, and network devices based on DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
Vulnerability Management & Continuous Monitoring:
Conduct vulnerability scans, analyze results, and work with system administrators to remediate security weaknesses on classified systems.
Oversee and perform continuous monitoring activities, including reviewing audit logs, security events, and system alerts for anomalous behavior.
Track and ensure compliance with Information Assurance Vulnerability Management (IAVM) directives.
Incident Response & Classified Spillage:
Act as a primary point of contact and lead for security incidents and classified spillage events on assigned systems.
Execute incident response procedures, including containment, eradication, recovery, and detailed reporting to relevant government authorities.
Participate in forensic investigations as required for classified incidents.
Compliance & Audit Support:
Maintain meticulous documentation of all security artifacts, configurations, policies, and procedures for classified systems.
Support internal and external security inspections, audits, and assessments by government agencies (e.g., DCSA, DSS, NSA).
Develop and implement standard operating procedures (SOPs) for the secure operation of classified systems.
User Training & Guidance:
Provide guidance and training to users on proper handling, marking, and safeguarding of classified information and operation of classified systems.
Ensure all personnel accessing classified systems meet training requirements (e.g., security awareness, insider threat).
Configuration Management:
Manage and control changes to the hardware, software, and firmware of classified systems to maintain their security posture and accreditation.
MINIMUM QUALIFICATIONS
Security Clearance:
Active U.S. Government Security Clearance required at the SECRET level or above.
Education:
Bachelor's degree in Computer Science, Information Security, Cybersecurity, or equivalent experience.
Experience:
5 years of dedicated experience in Information Assurance/Cybersecurity within classified government or defense environments.
Demonstrable expertise in the Risk Management Framework (RMF) or equivalent A&A processes (e.g., DIACAP).
Hands-on experience with security tools and technologies used in classified environments (e.g., ACAS, HBSS, SIEM, dedicated firewalls).
Proven experience with DISA STIGs and their application to various operating systems and applications.
Technical Skills:
Strong understanding of network protocols, operating systems (Windows, Linux/Unix), and virtualized environments in a classified context.
Experience with encryption technologies and COMSEC devices.
Knowledge of scripting languages (e.g., PowerShell, Python, Bash) for automation and auditing is a plus.
Desired Certifications:
CISSP (Certified Information Systems Security Professional)
DoD 8570.01-M IAT Level II (e.g., CompTIA Security+, CySA+, CCNA Security, SSCP) or higher (IAM Level I, II, or III).
GIAC Certifications relevant to incident handling, forensics, or security auditing (e.g., GCIH, GCFA, GCCC, GSNA)
Additional Job Requirements
Salary Range: $114,000 to $148,000 USD
The salary range provided for this position reflects the expected minimum and maximum base pay for new hires. Actual compensation will be determined based on factors such as relevant skills, experience, and qualifications, as well as internal equity and market conditions. In addition to base salary, eligible employees also receive a comprehensive benefits package.
WHOI accepts applications on a rolling basis - applications will be reviewed as they are received, and we encourage you to submit your application as soon as possible to ensure full consideration. While we will continue to review applications until the position is filled, and early applicants may have an advantage in the selection process.
EEO Statement
Woods Hole Oceanographic Institution (WHOI) provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
$114k-148k yearly Auto-Apply 60d+ ago
Systems Security Engineer II - P2 (On-site)
RTX Corporation
Security architect job in Portsmouth, RI
**Country:** United States of America ** Onsite **U.S. Citizen, U.S. Person, or Immigration Status Requirements:** Active and transferable U.S. government issued security clearance is required prior to start date.
U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
**Security Clearance Type:**
Secret - Current
**Security Clearance Status:**
Active and existing security clearance required on day 1
At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Raytheon is seeking a well-qualified **Systems Security Engineer II (P2)** to join our elite Systems Security Engineering (SSE) team for the Systems Directorate in developing solutions to protect the Warfighter's technology advantage. Systems Security Engineering creates holistic security solutions leveraging Cyber Security, Software Assurance and Supply Chain Risk Management to support Program Protection Implementation on embedded weapons systems. Join our highly visible team and perform technically challenging assignments, which will directly contribute to protecting our nation and our Warfighters. This is an onsite position at Raytheon in Portsmouth, RI.
**What You Will Do**
+ Support the development of cybersecurity requirements, design and architecture artifacts, plans, and policies.
+ Support security development and test efforts implementation of security controls of networking devices, databases, operating systems, and hardware and software component
+ Implement proper cybersecurity controls
+ Integrate cybersecurity development activities
**Qualifications You Must Have**
+ Typically requires a Bachelor's Degree in Science, Technology, Engineering or Mathematics (STEM) and 2 years of prior relevant experience
+ Active and transferable U.S. government issued Secret security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
+ Experience working in the Naval industry
**Qualifications We Prefer**
+ Experience in Cybersecurity Engineering
+ Usage of information security toolsets including anti-virus, Vulnerability Assessment, HIDS/ NIDS. host-based or endpoint security solutions, Multi-Factor Authentication (MFA), and Security Incident and Event Management (SIEM) and centralized auditing tools familiarity with splunk is preferred
+ Linux Bash scripting or Python scripting experience
+ Experience with National Institute of Standards and Technology (NIST) Risk Management Framework (RMF)
+ DoDI 8570.01-M IAT Level-II Compliant Certification (e.g. Security+, CISSP, or equivalent)
+ Security systems engineering involving various computer hardware and software S/W operating system and application solutions in both a stand-alone and in LAN/WAN configurations
+ Experience with IT and/or network and system security administration, including operating system security configuration and account management best practices for UNIX, MS Windows, Red Hat Enterprise Linux, and CISCO systems
**What We Offer**
+ Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation
+ Relocation Eligible - Relocation assistance is available
**_As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote._**
The salary range for this role is 68,900 USD - 131,100 USD. The salary range provided is a good faith estimate representative of all experience levels.
RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.
This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.
RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
_RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act._
**Privacy Policy and Terms:**
Click on this link (******************************************************** to read the Policy and Terms
Raytheon Technologies is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.
$83k-116k yearly est. 9d ago
Information Systems Security Officer (ISSO)
GE Aerospace 4.8
Security architect job in Lynn, MA
GE Aviation Systems - Edison Works in Lynn, MA is seeking an Information System Security Manager (ISSM) in support of US Government (USG), Department of Defense (DoD) activities. In this role, the successful candidate will be supporting and managing information systems security for multiple USG classified systems and networks and for various programs and sponsors. The successful candidate is expected to have a working knowledge of National Institute of Standards and Technology (NIST) information system protection policies and Risk Management Framework (RMF) procedures and tools as prescribed within the Defense Counterintelligence and Security Agency (DCSA), DCSA Assessment and Authorization Manual (DAAPM) and as they apply to various defense industry implementations.
Job Description
Job Title: Information Systems Security Officer (ISSO)
Company Intro/About Us:
GE Aerospace is a world-leading provider of jet engines, components, and integrated systems for commercial and military aircraft. At GE Aerospace, we are committed to pushing the boundaries of technology to deliver innovative solutions that power the future of flight. Working here means being part of a team that values safety, quality, delivery, and cost (SQDC), with safety always being the top priority. Our culture fosters collaboration, respect, and continuous improvement, ensuring every employee has the opportunity to thrive.
Site, Business, OR Functional Area Overview:
At InsertSite/FunctionalArea, you'll be part of a dynamic team dedicated to ensuring the security and compliance of classified systems and networks. We pride ourselves on fostering a culture of respect, innovation, and teamwork, where employees are empowered to make meaningful contributions. With competitive benefits and a focus on professional growth, this is a place where your career can truly take off.
Role Overview: As an Information Systems Security Officer (ISSO), you will play a critical role in implementing and maintaining the cybersecurity compliance of classified systems and networks under the direction of the Information Systems Security Manager (ISSM). This position is on−site and involves working both independently and collaboratively with cross functional teams to execute day‑to‑day cybersecurity program elements. Your work will directly support GE Aerospace's mission of delivering secure and compliant solutions to our customers.
Key Responsibilities
Area ISSO-Focused Responsibilities
Compliance Support certification of IT assets prior to submission to DCSA for accreditation and help ensure compliance with applicable policy documents, under the guidance of the ISSM.
Control implementation Assist in designing, implementing, and maintaining solutions that conform to information system security control requirements after system or network categorization.
Security tools Utilize tools such as STIG, SCAP, SPLUNK, MS Log Parser, and others to help configure, monitor, and review systems and networks.
Audit and monitoring Configure and/or operate audit tools and review security logs to identify anomalies, vulnerabilities, and system errors, escalating issues to the ISSM when needed.
Configuration compliance Help ensure system and network configurations meet USG regulatory compliance requirements and document deviations for remediation.
A&A support Support system certification and accreditation planning and testing activities to enable formal USG Assessment and Authorization (A&A).
DocumentationDevelop, maintain, and update system accreditation documentation, including system security plans, risk assessments, hardware/software lists, and plan of actions and milestones, in coordination with the ISSM.
Continuous monitoring Execute elements of the continuous monitoring plan, document results, and report on findings to validate information protection effectiveness.
Program support Provide support and backup coverage to special access programs as needed, working closely with the ISSM and broader security team.
IT collaboration Collaborate with IT personnel to support secure systems operations, maintenance, and licensing compliance.
User support Assist users with account validation, vulnerability remediation actions, and IT security briefings.
The Ideal Candidate
The ideal candidate is a detail-oriented cybersecurity professional with strong documentation skills and a passion for maintaining secure systems operations. They thrive in a collaborative environment, are comfortable following established processes and standards, and are committed to delivering high-quality results while adhering to federal security requirements and guidance from the ISSM.
Required Qualifications
CategoryRequirement
ClearanceCurrent/Active DoD Secret clearance (adjudicated within the last six years) with the ability to obtain and maintain up to TS.
Education/ExperienceBachelor's degree in computer science, information systems security, or a minimum of 4-6 years of experience in a cybersecurity-related field.
Technical skills Strong knowledge of Microsoft Office and documentation creation/maintenance.
OS experience Experience with recent Windows operating systems.
Regulatory knowledge Familiarity with federal security requirements and mandates (e.g., RMF, NISPOM/DAAPM).
STIG experience Experience implementing DISA Security Technical Implementation Guides (STIG).
CertificationCompTIA Security+ certification or other DoD 8570/8140 IAT II or IAM I-II equivalent qualifications.
Soft skills Strong organizational, time management, and scheduling skills; ability to work independently and collaboratively in a diversified environment.
COMSECWorking knowledge of Communications Security (COMSEC) equipment and administration (or willingness to obtain).
Preferred Qualifications
CategoryPreferred Background
DoD 8570/8140IAT II, IAT III, IAM II, or higher certifications IAW DoD 8570/8140 qualifications.
Networking & crypto Certifications or experience in local area networks, network appliances, and cryptography.
PlatformsCisco, Linux, and VMware experience.
ToolsWorking experience with eMASS.
RMFKnowledge of DoD RMF requirements and implementations per DAAPM and/or JSIG.
Physical security Familiarity with physical security principles and apparatus.
SCAP & STIGExperience using SCAP tools to verify STIG implementation.
Data protection Knowledge of data backup strategies and secure data handling practices.
Additional Information
The base pay range for this position is $127,300.00-$169,700.00. The specific pay offered may be influenced by a variety of factors, including the candidate's experience, education, and skill set. This position is also eligible for an annual discretionary bonus based on a percentage of your base salary/commission based on the plan. This posting is expected to close on February 3rd, 2026.
GE Aerospace offers comprehensive benefits and programs to support your health and, along with programs like HealthAhead, your physical, emotional, financial and social wellbeing. Healthcare benefits include medical, dental, vision, and prescription drug coverage, access to a Health Coach from GE Aerospace, and the Employee Assistance Program, which provides 24/7 confidential assessment, counseling and referral services. Retirement benefits include the GE Aerospace Retirement Savings Plan, a 401(k) savings plan with company matching contributions and company retirement contributions, as well as access to Fidelity resources and planning consultants. Other benefits include tuition assistance, adoption assistance, paid parental leave, disability insurance, life insurance, and paid time off for vacation or illness.
GE Aerospace (General Electric Company or the Company) and its affiliates each sponsor certain employee benefit plans or programs (i.e., is a "Sponsor"). Each Sponsor reserves the right to terminate, amend, suspend, replace or modify its benefit plans and programs at any time and for any reason, in its sole discretion. No individual has a vested right to any benefit under a Sponsor's welfare benefit plan or program. This document does not create a contract of employment with any individual. 2023 GE Aerospace and/or its affiliates. All rights reserved. Attorney-Client Privileged
Closing:
At GE Aerospace, we are committed to fostering a diverse and inclusive workplace. Join us and be part of a team that is shaping the future of flight.
Export Control Language:
GE Aerospace will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a background investigation and drug screen.
This role requires access to U.S. export-controlled information. Therefore, employment will be contingent upon the ability to prove that you meet the status of a U.S. Person as one of the following: U.S. lawful permanent resident, U.S. Citizen, have been granted asylee or refugee status (i.e., a protected individual under the Immigration and Naturalization Act, 8 U.S.C. 1324b(a)(3)).
Additional Information
GE Aerospace offers a great work environment, professional development, challenging careers, and competitive compensation. GE Aerospace is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.
GE Aerospace will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable).
Relocation Assistance Provided: Yes
$127.3k-169.7k yearly Auto-Apply 2d ago
Physical Security Systems Engineer
Security Director In San Diego, California
Security architect job in Wilmington, MA
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, retirement plan, basic life, AD&D, and disability insurance
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law
#LI-26
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID 2026-1512505
$80k-115k yearly Auto-Apply 11d ago
Physical Security Systems Engineer
Allied Universal Technology Services
Security architect job in Wilmington, MA
Overview
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, retirement plan, basic life, AD&D, and disability insurance
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law
#LI-26
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID
2026-1512505
$80k-115k yearly 18d ago
Security Research Architect
Veracode 4.2
Security architect job in Burlington, MA
The Research Architect for Dynamic Application Security Testing (DAST) is responsible for overseeing the security capabilities of Veracode's dynamic scanner offerings.
Responsibilities
· Conduct research and development for automating web application attacks.
· Conduct research for improving techniques for detection of vulnerabilities.
· Develop attack signatures for specific classes of vulnerabilities.
· Define developer focused specifications for new attacks.
· Work with management to set priorities and goals for Veracode's DAST offerings.
· Keep up to date with the latest features in web browsers, web application development techniques, and web application vulnerabilities.
· Develop test cases to demonstrate vulnerabilities and ensure products' ability to identify them in an automated fashion.
· Actively engage with the security research community through speaking at industry conferences, publishing independent research, posting on the Veracode blog, and other means.
The Research Architect for Dynamic Application Security Testing (DAST) is responsible for overseeing the security capabilities of Veracode's dynamic scanner offerings.
Responsibilities
· Conduct research and development for automating web application attacks.
· Conduct research for improving techniques for detection of vulnerabilities.
· Develop attack signatures for specific classes of vulnerabilities.
· Define developer focused specifications for new attacks.
· Work with management to set priorities and goals for Veracode's DAST offerings.
· Keep up to date with the latest features in web browsers, web application development techniques, and web application vulnerabilities.
· Develop test cases to demonstrate vulnerabilities and ensure products' ability to identify them in an automated fashion.
· Actively engage with the security research community through speaking at industry conferences, publishing independent research, posting on the Veracode blog, and other means.
This is a deeply technical role that requires significant knowledge around modern web development technologies and practices. You not only understand common web vulnerabilities, but understand how to find them in an automated fashion. You will need to follow upcoming trends and how they may have implications for security. It's also crucial that you're an effective communicator, as you'll collaborate frequently with engineers to guide them in implementing the specifications you create. You'll also need:
· 5+ years of practical application security work experience, preferably including some or all of the following: source code auditing, penetration testing, product assessments, vulnerability research, reverse engineering, and related pursuits.
· 3+ years of software development experience.
· Deep understanding of web browsers (i.e. security features, DOM, JavaScript, etc.).
· Deep understanding of common client side and server side web application vulnerabilities and how to exploit them (e.g. SQL injection, cross-site scripting, etc.).
· Ability to learn new programming languages and/or technologies quickly and independently
· Ability to balance novelty of attacks with the restrictions automation demands.
· Experience with automated application security testing products (SAST, DAST, etc.) a plus.
· Genuine enthusiasm, not just aptitude, for application security. Up to 20% of your time will be allocated for independent research, and this means you'll need interesting, relevant project ideas.
· Prototyping ability - the skill to hack something together quick and dirty to solve a problem and demonstrate feasibility.
· Excellent attention to detail, quality, and customer satisfaction. Consulting experience a plus.
· Strong analytical, organizational, and technical writing skills.
· B.S. in Computer Science or equivalent industry experience.
Skills & Requirements
This is a deeply technical role that requires significant knowledge around modern web development technologies and practices. You not only understand common web vulnerabilities, but understand how to find them in an automated fashion. You will need to follow upcoming trends and how they may have implications for security. It's also crucial that you're an effective communicator, as you'll collaborate frequently with engineers to guide them in implementing the specifications you create. You'll also need:
· 5+ years of practical application security work experience, preferably including some or all of the following: source code auditing, penetration testing, product assessments, vulnerability research, reverse engineering, and related pursuits.
· 3+ years of software development experience.
· Deep understanding of web browsers (i.e. security features, DOM, JavaScript, etc.).
· Deep understanding of common client side and server side web application vulnerabilities and how to exploit them (e.g. SQL injection, cross-site scripting, etc.).
· Ability to learn new programming languages and/or technologies quickly and independently
· Ability to balance novelty of attacks with the restrictions automation demands.
· Experience with automated application security testing products (SAST, DAST, etc.) a plus.
· Genuine enthusiasm, not just aptitude, for application security. Up to 20% of your time will be allocated for independent research, and this means you'll need interesting, relevant project ideas.
· Prototyping ability - the skill to hack something together quick and dirty to solve a problem and demonstrate feasibility.
· Excellent attention to detail, quality, and customer satisfaction. Consulting experience a plus.
· Strong analytical, organizational, and technical writing skills.
· B.S. in Computer Science or equivalent industry experience.
$108k-142k yearly est. 60d+ ago
Senior Security Engineer - Web & Cloud Defense Champion
Flexcar
Security architect job in Boston, MA
A leading automotive service company in Downtown Boston seeks a dedicated Senior Security Engineer to safeguard its web and mobile applications, manage various security incidents, and ensure compliance with safety standards. This role requires collaboration across teams to implement defense strategies and educate staff on security practices. Self-starters with expertise in threat management and a solid understanding of compliance frameworks will thrive in this vibrant environment. Join the mission to revolutionize car ownership and enjoy competitive pay and exceptional benefits.
#J-18808-Ljbffr
$96k-134k yearly est. 5d ago
Systems Security Engineer
General Dynamics Mission Systems 4.9
Security architect job in Taunton, MA
Basic Qualifications
RRequires a Bachelor's degree in Systems Engineering, or a related Science, Engineering, Technology or Mathematics field. Also requires 5+ years of job-related experience, or a Master's degree plus 3 years of job-related experience. Agile experience preferred.
CLEARANCE REQUIREMENTS:
Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibilityrequirements for access to classified information. Due to the nature of work performed within our facilities, U.S.citizenship is required.
Responsibilities for this Position
We are seeking a Systems Security Engineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
#CJ3
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $124,397.00 - USD $138,003.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
How much does a security architect earn in Brockton, MA?
The average security architect in Brockton, MA earns between $91,000 and $193,000 annually. This compares to the national average security architect range of $92,000 to $179,000.