Lead Security Architect (Director level, individual contributor)
Security architect job in Boston, MA
At Manulife, we are changing the way we unlock value and secure the enterprise through technology and we want you to be part of it! We are growing our cybersecurity program with the vision to deliver quality applications using AI that add value to our customers, faster and securely, at scale. The customer is at the focus of everything we do, and millions of end users rely on our products daily. We are building a state-of-the-art cybersecurity program to better protect the firm's critical assets.
As a Lead Security Architect, you'll be responsible for designing, developing, and implementing robust security strategies and solutions to protect Manulife's digital assets from advanced cyber threats. In this hub-and-spoke model, you will report to the Chief Security Architect and will be the dedicated security architecture lead for a specific business unit, ensuring alignment with the global security framework while addressing the unique needs of the segment. You will play a crucial role in shaping our global security posture and ensuring security is a foundational element of our technology and business initiatives.
Office location: Toronto - Canada (ideal) or Boston - USA.
Work arrangement: Hybrid (3 days in office, 2 days from Home); Remote working option is not available.
Travel Flexibility: Willingness and ability to travel within Canada and USA to support business operations and stakeholder engagement.
Position Responsibilities:
* Architectural Design: Lead the design and development of robust security frameworks, standards, and best practices for global systems, data, and networks. This includes creating reference architectures and implementation patterns for security solutions.
* Strategic Planning: Translate business, technology, and threat drivers into practical security roadmaps. You'll ensure our security strategy is aligned with broader organizational goals.
* Financial Analysis: Conduct financial evaluations of security technologies, including quantifying purchasing and licensing options, estimating labor costs, and calculating the total cost of ownership (TCO), return on investment (ROI), or payback period.
* Project Management: Draft project plans for security service and technology deployments and coordinate with stakeholders across the organization to ensure successful implementation.
* Collaboration & Integration: Work closely with various teams across Manulife's business and IT units-including enterprise architecture, development, and risk management-to seamlessly integrate security throughout the entire project lifecycle.
* Risk Management: Conduct comprehensive risk assessments to identify vulnerabilities and define necessary controls. Partner with global information risk management teams to prioritize and mitigate risks effectively.
* Security Evaluation: Continuously evaluate the security of new and emerging technologies and potential solutions. You will stay ahead of the curve on cybersecurity trends to recommend and implement innovative solutions.
* Mentorship & Communication: Act as a security subject matter expert, coaching and mentoring development teams. You will also communicate complex security standards and strategies to both technical staff and senior management with clarity and influence.
* AI Security: Design and implement security frameworks for Machine Learning (ML), Generative AI (GenAI), and Agentic AI systems. Evaluate AI-powered security tools and integrate artificial intelligence capabilities into security operations and threat detection.
* Domain-Specific Accountabilities:
* Application Security: Assess solution architectures for compliance with security standards, define secure service interfaces, and provide guidance to application security engineers on threat modelling and secure software development methodologies.
* Cloud Security: Provide deep expertise in securing multi-cloud computing environments (SaaS, IaaS, PaaS), with a strong focus on platforms like Microsoft Azure and AWS.
Required Qualifications:
* To succeed in this role, a candidate must have a strong blend of technical expertise, professional experience, and interpersonal skills.
* Education & Certifications:
* Bachelor's or master's degree in computer science, information systems, cybersecurity, or a related field.
* Relevant industry certifications such as CISSP (Certified Information Systems Security Professional) or CCSP (Certified Cloud Security Professional) are required.
* Experience:
* At least 10 years of experience specifically in senior information security architecture roles, with demonstrated progression in responsibility and complexity.
* Proven experience in the financial services industry, with understanding of regulatory requirements, compliance frameworks, and industry-specific security challenges.
* Experience in using architecture methodologies such as SABSA, Zachman, and/or TOGAF.
* Direct, hands-on experience or strong working knowledge of managing security infrastructure-e.g., firewalls, intrusion prevention systems (IPSs), web application firewalls (WAFs), endpoint protection, SIEM, and log management technology.
* Verifiable experience reviewing application code for security vulnerabilities.
* Experience securing CI/CD pipelines.
* Direct, hands-on experience or a strong working knowledge of vulnerability management tools.
* Documented experience and a strong working knowledge of the methodologies to conduct threat-modelling exercises on new applications and services.
* Experience designing the deployment of applications and infrastructure into public cloud services.
* Direct experience designing IAM technologies and services, including Active Directory, Lightweight Directory Access Protocol (LDAP), and Amazon Web Service (AWS) IAM.
* Extensive knowledge of full-stack IT infrastructure, including:
* Applications
* Databases
* Operating systems-Windows, Unix, and Linux
* Hypervisors
* IP networks-WAN and LAN
* Storage networks-Fibre Channel, iSCSI, and NAS
* Backup networks and media
* Containers/Kubernetes
* Soft Skills:
* Communication: Excellent verbal and written communication skills are crucial for articulating complex technical concepts and influencing stakeholders at all levels. You must be able to translate complex security matters into business terms that are easily understood by colleagues and senior management.
* Problem-Solving: Strong analytical, problem-solving, and decision-making abilities.
* Collaboration: The capacity to balance competing priorities and maintain a collaborative and positive attitude.
* Travel Flexibility: Willingness and ability to travel within Canada and USA to support business operations and stakeholder engagement
Preferred Qualifications:
* Experience from large complex environment is highly preferred but not a must.
* Experience from large financial Org's is a definite plus but not a must.
When you join our team:
* We'll empower you to learn and grow the career you want.
* We'll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
* As part of our global team, we'll support you in shaping the future you want to see.
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit *************************************************
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact ************************.
Referenced Salary Location
Toronto, Ontario
Working Arrangement
Hybrid
Salary range is expected to be between
$132,900.00 CAD - $182,900.00 CAD.
If you are applying for this role outside of the primary location, please contact ************************ for the salary range for your location. The actual salary will vary depending on local market conditions, geography and relevant job-related factors such as knowledge, skills, qualifications, experience, and education/training. Employees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance.
Manulife offers eligible employees a wide array of customizable benefits, including health, dental, mental health, vision, short- and long-term disability, life and AD&D insurance coverage, adoption/surrogacy and wellness benefits, and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in Canada includes holidays, vacation, personal, and sick days, and we offer the full range of statutory leaves of absence. If you are applying for this role in the U.S., please contact ************************ for more information about U.S.-specific paid time off provisions.
Auto-ApplyPrincipal Cloud Security Architect
Security architect job in Boston, MA
Role OverviewThe Principal Cloud Security Architect evaluates cloud architectures, identity models, permissions, and security controls across large-scale environments. This role focuses on identifying architectural risks, misconfigurations, and long-term security design gaps.
What You'll Do- Assess cloud architectures (AWS, Azure, GCP) for security gaps - Review IAM configurations, network segmentation, and resource policies - Identify misconfigurations, privilege risks, and insecure patterns - Summarize architectural flaws and provide structured mitigation guidance - Validate alignment with security frameworks and best practices - Support recurring assessments of cloud environments and deployment patterns What You BringMust-Have:- Deep experience in cloud security architecture - Strong understanding of IAM, network design, and cloud service models - Ability to document complex architectures in clear, structured form Nice-to-Have:- Experience with multi-cloud, zero-trust, or high-compliance environments
Auto-ApplyMultiple permanent positions_Certified Security Architect_w2
Security architect job in Cumberland, RI
360 IT Professionals is a Software Development Company based in Fremont, California that offers complete technology services in Mobile development, Web development, Cloud computing and IT staffing. Merging Information Technology skills in all its services and operations, the company caters to its globally positioned clients by providing dynamic feasible IT solutions. 360 IT Professionals work along with its clients to deliver high-performance results, based exclusively on the one of a kind requirement.
Job Description
We are looking to fill multiple full time positions as Information Security Architects in Cumberland RI.
Qualifications
A minimum of 5+ years of relevant security domain experience.
3+ years of hands on technical experience in network and perimeter security
A minimum of 3 years in an architecture role and be able to lead/step up as needed
Demonstrated expertise in integrating/developing security solutions in a 7x24 production environment
Prior experience in defining the technology strategy for a large, global organization, and the ability to influence and persuade peers and colleagues in other reporting structures
Strong Plus Skills:
Industry recognized certifications such as CISA, CISM, CISSP, or SANS GIAC are a plus
Virtualization Security experience is a strong plus (VMware ESX 6.x, Hytrust, Hypervisor, in-hypervisor malware control. Virtual NIC, NSX or equivalent.)
Knowledge of risk assessment methodologies, IT policies and standards
Knowledge of vulnerability identification tools, Qualys, Veracode, Qualys WAS.
Additional Information
In person interview is acceptable.
Google Cloud Security Architect
Security architect job in Boston, MA
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies
As a Consultant or Senior Consultant, you will collaborate with cross-functional teams, including IT, security, and business units, to design and implement Google Cloud-based application innovation solutions. You will work alongside experienced cloud architects, data scientists, and other specialists, ensuring the successful delivery of scalable, cloud-native applications and AI-powered solutions.
What You'll Do
* Stay current with security trends, technologies, and best practices around Google Cloud solutions, leveraging tools like Cloud IAM, Cloud Security Command Center, BeyondCorp, and Cloud Armor.
* Define and guide transformational security strategies for Google Cloud environments, ensuring alignment with Google's Zero Trust and BeyondCorp principles.
* Translate complex regulatory requirements (e.g., GDPR, SOC 2, HIPAA) and technology standards into actionable functional and technical requirements for cloud and hybrid environments, ensuring security and compliance.
* Lead teams through various phases of gap analyses, including security assessments, remediation planning, roadmap development, and implementation of remediation actions using Google Cloud-native tools.
* Deliver on the vision, architecture, execution, and quality assurance of security projects on Google Cloud, driving initiatives that secure enterprise workloads and data.
* Guide stakeholders and senior leaders on aligning security solutions with broader business goals, ensuring the architecture follows Google Cloud's security best practices and roadmap.
* Establish security architecture patterns based on Google Cloud security frameworks and industry standards to meet the unique needs of enterprise clients.
* Collaborate with other Google Cloud architects and security teams to continuously improve security knowledge assets and best practices, ensuring the most effective security solutions for clients.
* Design and architect solutions to secure Generative AI models and applications against adversarial attacks, prompt injection, and their potential misuse for malicious cyber activities.
What You'll Bring
* Proven experience with Google Cloud security architecture, with hands-on experience in tools like Cloud IAM, VPC Service Controls, Cloud DLP, and Cloud Armor.
* Strong background in defining and implementing Zero Trust and BeyondCorp security models within Google Cloud environments.
* Familiarity or direct experience with Identity and Access Management (IAM), Data Protection, Vulnerability Management, and Cloud Security solutions in Google Cloud.
* Extensive experience with security design patterns specific to Google Cloud, as well as hybrid and multi-cloud security architecture.
* Experience in security and risk advisory consulting, particularly related to cloud security transformations.
* Ability to lead the development and implementation of cloud security roadmaps aligned with business goals and compliance needs.
* Familiarity with Google Cloud's Artificial Intelligence (AI) capabilities (e.g., Vertex AI, Generative AI services, Model Armor) including their applications, associated security risks (e.g., prompt injection, data poisoning, privacy concerns), and proven strategies for implementing security controls, governance, and responsible AI practices.
* Relevant certifications are strongly desired, including (but not limited to):
* GCP Professional Security Engineer
* GCP Professional Cloud Architect
* CISSP
* Security+
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices. For this position the base salary pay ranges are listed below. In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
East Bay, San Francisco, Silicon Valley:
* Consultant: $120,000-$177,000
* Senior Consultant: $140,000-$203,000
San Diego, Los Angeles, Orange County, Seattle, Houston, New Jersey, New York City, Westchester, Boston, Washington DC:
* Consultant: $110,000-$162,000
* Senior Consultant: $130,000-$186,000
All other locations:
* Consultant: $105,000-$148,000
* Senior Consultant: $115,000-$171,000
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
We are accepting applications until 12/31.
Chief Information Security Officer
Security architect job in Waltham, MA
Company Profile Trinity Partners, LLC ("Trinity") *********************************** is a leading healthcare consulting firm based in Waltham, MA that specializes in health care strategy for pharmaceutical, biotech and life sciences firms. Our clients include top tier to venture backed companies worldwide. Trinity provides services to these clients in a variety of practice areas including strategic planning, forecasting and market estimation, licensing and acquisitions, launch strategies, data warehousing and sales force effectiveness. The company consists of approximately 900 employees and is headquartered in Waltham, Massachusetts, with offices in New Jersey, New York, San Francisco, Pennsylvania, Germany, London & India. Trinity is an EEO employer. Chief Information Security Officer The Chief Information Security Officer will lead the development and execution of a comprehensive information security strategy for a global pharmaceutical consulting firm. They will act as the strategic leader of Trinity's cyber defense program as an integral part of the Trinity leadership team. This role will ensure the confidentiality, integrity, and availability of enterprise data, systems, and infrastructure across all geographies. The CISO will collaborate with executive leadership, IT, legal, compliance, and operations to embed security into the company's culture and business processes. The CISO will posses the ability to manage the cybersecurity team to identify, assess and prioritize threats and vulnerabilities across all of Trinity's environment, while effectively influencing and communicating across multiple teams to help create a cohesive security ecosystem. The ideal candidate will be able to build strong relationships across the business to help identify gaps in security controls, as well as direct internal audits. They will possess an ability to 'think like an adversary' and promote security throughout the organization. Key Objectives Strategic Leadership Develop and implement a global information security strategy aligned with business goals and regulatory requirements Establish and maintain enterprise-wide security policies, standards, and procedures. Lead the information security governance, risk management, including responsibility for audit readiness and post-assessment remediation plans, especially for ISO 27001 and 42001 gaps Define and report on key security metrics (e.g., incident response times, vulnerability remediation SLAs, phishing simulation results) to executive leadership and the board Lead the development and enforcement of cloud security strategies across Microsoft 365, Azure, AWS, and other SaaS platforms with emphasis on configuration management, monitoring, and incident detection/remediation in cloud environments Foster a security-first culture by engaging business leaders and department heads in regular security briefings and risk discussions. Lead threat detection, prevention, and response capabilities, including Security Operations Center (SOC) oversight. Ensure the timely investigation, response, and remediation of security incidents and breaches. Establish and document a framework-aligned, business-integrated security ecosystem for Trinity and enable mechanisms to showcase it to customers on a need basis. Lead data protection efforts across Trinity SaaS, Product and Internal environments, including cloud-native services and large-scale repositories. Software Development Lifecycle Oversight Integrate security practices into the full software development lifecycle, including secure architecture, code review, automated testing for vulnerabilities, and DevSecOps principles. Collaborate with IT and Product teams to ensure security controls are embedded from project initiation through deployment. Vendor & Third-Party Risk Management Oversee the security review process for third-party vendors, cloud providers, and partners. Ensure supply chain security and resilience. Operational Oversight Oversee the design and implementation of technical safeguards including access control, encryption, patch management, and threat detection systems Manage the cybersecurity team, including security engineers, analysts, and external vendors (e.g., Managed SOC services) Direct incident response planning and execution, including breach investigations and reporting Ensure secure configuration and monitoring of cloud-native services, including identity, access, and data protection controls Oversee data governance and protection strategies for large-scale data repositories, including SharePoint Online, OneDrive, and Teams Orchestrate regular security audits in SaaS ecosystems, to proactively identify vulnerabilities. Collaborate with international teams to maintain consistent security posture and incident response readiness globally Champion regular security audits and continuous improvement cycles, with a focus on cloud ecosystem vulnerabilities such as drift in Microsoft 365, AWS, Azure, among others. Compliance & Risk Management Work directly with General Counsel and Compliance group to ensure compliance with HIPAA, GDPR, NIST CSF, SOC 2, ISO 27001 and ISO 42001and other global data protection regulations relevant to pharmaceutical consulting Conduct regular risk assessments based on NIST RMF and develop mitigation plans Lead external security audits and accreditation surveys Ensure security practices are adapted to regional regulatory requirements and cultural contexts across North America, Europe, and Asia. Training & Awareness Champion a culture of security awareness across the organization specifically with development teams Develop and deliver training programs tailored to different roles and regions Demonstrated ability to communicate complex security concepts to the board, non-technical stakeholders, and external customers in plain, persuasive language. Technology & Innovation Evaluate and implement emerging security technologies (e.g., CASB, PAM, GRC tools) Align security architecture with frameworks such as NIST CSF, CIS 18, and OWASP
Position Requirements:
Education: Bachelor's or Master's degree in Information Security, Computer Science, or related field.
* Work Experience: 10+[PL1] years of progressive experience in information security, including leadership roles and hands-on security engineering and vulnerability remediation.
Other Skills: Knowledge and/or working skills in the following areas:
* Experience in pharmaceutical, healthcare, or consulting industries preferred
* Certifications such as CISSP, CISM, CEH, GSEC, ECSA, Security+ or CISA strongly preferred
* Proven ability to lead cross-functional teams and manage global security operations
* Strategic thinking and business acumen
* Strong communication and stakeholder engagement skills with demonstrated record of translating technical content for business adoption
* Experience with vendor management and contract negotiation
* Familiarity with cloud security, application security, and data loss prevention
* Understanding of modern threats and exploits
* Ability to understand and communicate attack chains to management and key stakeholders
* Develop, execute and track the performance of security measures to protect information and network infrastructure and computer systems
* Identify, define and document system security requirements and recommend solutions to management
* Identify and document security requirements and recommend solutions to management
* Ownership of remediation activities for ISO and other regulatory gaps.
* Experience managing or working with Managed Security Service Providers (MSSPs) and Security Operations Centers (SOCs).
* Familiarity with Zero Trust architecture and identity-centric security models.
About Us
Trinity Life Sciences is a trusted strategic commercialization partner, providing evidence-based solutions for the life sciences. With 25 years of experience, Trinity is committed to revolutionizing the commercial model by providing exceptional levels of service, powerful tools and data-driven insights. Trinity's range of products and solutions includes industry-leading benchmarking solutions, powered by TGaS Advisors. To learn more about how Trinity is elevating life sciences and driving evidence to action, visit trinitylifesciences.com.
Trinity's salary bands account for a wide range of factors that are considered in making compensation decisions including but not limited to skill sets and market demand for skills; level of experience and training; specific qualifications, performance, time in role/company, geographic location, and other business and organizational needs. A reasonable estimate of the current range is $250,000-$300,000 USD.
In addition to your base salary, you will also be eligible for an annual discretionary performance bonus.
Trinity's Commitment to Diversity, Equity & Inclusion
Trinity Life Sciences is an Equal Opportunity Employer that prohibits discrimination and harassment of any kind. Trinity is committed to the principles of diversity, equity, and inclusion and to providing employees with a work environment that is free of discrimination and harassment. All employment decisions at Trinity are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, disability, ethnicity, gender identity or expression, family, parental, or veteran status, and/or any other status based on identity or that is protected by the laws or regulations in the locations where we operate. Trinity will not tolerate any form of discrimination or harassment and encourages applicants of all ages and identities.
For more information about Trinity's commitment to diversity, equity, and inclusion, you can visit our website.
Director, Information Security
Security architect job in Boston, MA
At DraftKings, AI is becoming an integral part of both our present and future, powering how work gets done today, guiding smarter decisions, and sparking bold ideas. It's transforming how we enhance customer experiences, streamline operations, and unlock new possibilities. Our teams are energized by innovation and readily embrace emerging technology. We're not waiting for the future to arrive. We're shaping it, one bold step at a time. To those who see AI as a driver of progress, come build the future together.
The Crown Is Yours
As a Director, Information Security, you'll lead our Security Engineering and Security Operations teams to shape how we defend our platforms at scale. You'll build modern security programs grounded in automation, AI, and pragmatic risk management. You'll drive strategy, deliver key capabilities, and evolve our approach to detection, response, and resilience. This is a hands-on leadership role where you'll empower technical leaders, elevate team performance, and partner closely with Engineering, Legal, IT, and Information Security leadership.
What You'll Do
Lead a high-performing team of managers and senior individual contributors; foster growth through coaching, clarity, and development planning.
Provide strategic direction and mentorship to the broader InfoSec team through skip levels, feedback loops, and leadership modeling.
Define and communicate KPIs to drive the program, looking across operational impact as well as technical indicators of risk and drift toward failure.
Partner with InfoSec leadership on roadmap planning, prioritization, risk management, and capability development across detection, response, engineering, and investigations.
Advance our adoption of AI and automation to drive quantifiable impact across security functions, both in new capabilities and latency.
Collaborate with Legal, Compliance, and Audit to meet regulatory and customer expectations.
What You'll Bring
At least 10 years of progressive experience in security, including 5+ years in leadership roles with a strong emphasis on both proactive security engineering and reactive security operations.
Strong technical foundation in modern enterprise and cloud environments, including what we secure (AWS, GCP, Kubernetes, datacenters, IoT) and what we secure it with (SIEM, EDR, CSPM, SAST/DAST, IAM, forensics).
Familiarity with industry-standard risk and compliance frameworks (NIST CSF, ISO 27001, SOC 2, SLSA) and how to operationalize them in modern, tech-forward environments.
Experience in fast-paced, high-growth companies in enterprise tech, SaaS, gaming, or other technical consumer industries like online video gaming.
Executive-level communication skills, including the ability to deliver clear, timely, and actionable updates to both technical stakeholders and executive leadership.
Join Our Team
We're a publicly traded (NASDAQ: DKNG) technology company headquartered in Boston. As a regulated gaming company, you may be required to obtain a gaming license issued by the appropriate state agency as a condition of employment. Don't worry, we'll guide you through the process if this is relevant to your role.
The US base salary range for this full-time position is 216,000.00 USD - 270,000.00 USD, plus bonus, equity, and benefits as applicable. Our ranges are determined by role, level, and location. The compensation information displayed on each job posting reflects the range for new hire pay rates for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific pay range and how that was determined during the hiring process. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Auto-ApplyDirector, Information Security
Security architect job in Boston, MA
Extensive knowledge of HIPAA and HITECH. Knowledge of and experience with Information Security frameworks such as HiTRUST, NIST, or ISO 27001. Bachelor's degree in information security, information assurance, information technology, computer science, or a related discipline.
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or related certification.
Five (5) years in an information security operations or management role.
Passion for the mission of Health Leads and strong commitment to Health Leads' core values: belief in collective strength and the power of shared work, constant and courageous learning, celebrating our victories and each other, and stepping up leaders in a common vision.
Experience with information security for cloud environments and/or software-as-a-service (SaaS) platforms.
Knowledge of security-related technologies and processes, including but not limited to: data loss prevention (DLP), identity and access management (IAM), endpoint security, vulnerability and configuration management, security information and event management (SIEM), incident response and digital forensics, disaster recovery/business continuity planning, network security (LAN/WAN).
Ability to communicate complex ideas and information both
verbally
and writing, in a clear, concise, and effective manner to technical and non-technical audiences including customers and colleagues.
Superior capabilities for partnering;
ability to be effective as both a team member and as a leader of teams in defining objectives, staying on task and reaching consensus;
soliciting participation, challenging ideas and summarizing accomplishments and planned actions.
Show integrity and ethical behavior; respect confidentiality, business ethics and organizational standards.
Ability to
formulate
the cost benefit of security initiatives in the context of
overall
business risk mitigation and the organization's operational objectives.
Ability to compare, contrast and
prioritize
among alternative approaches to meet those objectives.
Lead Security Engineer, Cloud Infrastructure
Security architect job in Boston, MA
At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you're a close but not exact match with the description, we hope you'll still consider applying. Want to learn more about life at Klaviyo? Visit careers.klaviyo.com to see how we empower creators to own their own destiny.
As a Lead Security Engineer, you'll be a vital part of the Infrastructure Security Team, focusing on strengthening the security posture across Klaviyo's entire technology environment, developing security architectures and repeatable patterns and mentoring colleagues and junior security engineers. Unlike roles with a narrowly defined specialty, this position offers the opportunity to demonstrate your unique expertise-whether that's in cloud security, identity and access management, data protection, secure systems design, or other security domains. Your work will involve evaluating and hardening our infrastructure, collaborating with cross-functional teams, and leveraging AI to build scalable solutions to address emerging threats.
We are looking for someone who is excited to bring their specialized skills to the team, shaping Klaviyo's security practices and helping us continue to raise the bar.
How You Will Make a Difference
Secure Klaviyo's infrastructure by designing, implementing, and maintaining scalable security controls across cloud, on-prem, and hybrid environments
Evaluate and improve security configurations and policies across a range of technologies, using your domain expertise to reduce risk and enable secure-by-default architectures
Collaborate with engineering and IT teams to embed security practices and develop repeatable security patterns across the development and deployment lifecycle
Lead threat modeling, risk assessments, and architecture reviews in areas aligned with your specialty
Develop automated solutions and infrastructure-as-code to drive consistent and reproducible security outcomes
Stay ahead of the latest threats and advocate for innovative security solutions aligned with business needs
Help define security standards and best practices at Klaviyo, championing their adoption across teams
Who You Are
Have 5+ years of experience in infrastructure or security engineering roles, with deep knowledge in one or more security focus areas (e.g., cloud security, IAM, endpoint security, data protection, detection engineering, compliance)
Comfortable navigating ambiguity and defining priorities in a broad-scoped role
Experienced working in modern cloud environments such as AWS, GCP, or Azure
Familiar with infrastructure-as-code tools such as Terraform, CloudFormation, or Pulumi
Proficient in secure systems design, threat modeling, and vulnerability management
AI Agentic development and prompt engineering, MCP (AWS Bedrock, OpenAI, Anthropic)
Able to clearly articulate complex security topics to technical and non-technical stakeholders
Passionate about security, eager to learn from others and share your expertise
Nice to have - certifications (e.g., CISSP, CKS, GCP/AWS Security certs) or equivalent practical experience
We use Covey as part of our hiring and / or promotional process. For jobs or candidates in NYC, certain features may qualify it as an AEDT. As part of the evaluation process we provide Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound on April 3, 2025.
Please see the independent bias audit report covering our use of Covey here
Massachusetts Applicants:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicant's job-related skills, relevant experience, education or training, and work location.
In addition to base salary, our total compensation package may include participation in the company's annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility.
Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.
Base Pay Range For US Locations:$188,000-$282,000 USD
Get to Know Klaviyo
We're Klaviyo (pronounced clay-vee-oh). We empower creators to own their destiny by making first-party data accessible and actionable like never before. We see limitless potential for the technology we're developing to nurture personalized experiences in ecommerce and beyond. To reach our goals, we need our own crew of remarkable creators-ambitious and collaborative teammates who stay focused on our north star: delighting our customers. If you're ready to do the best work of your career, where you'll be welcomed as your whole self from day one and supported with generous benefits, we hope you'll join us.
AI fluency at Klaviyo includes responsible use of AI (including privacy, security, bias awareness, and human-in-the-loop). We provide accommodations as needed.
By participating in Klaviyo's interview process, you acknowledge that you have read, understood, and will adhere to our Guidelines for using AI in the Klaviyo interview Process. For more information about how we process your personal data, see our Job Applicant Privacy Notice.
Klaviyo is committed to a policy of equal opportunity and non-discrimination. We do not discriminate on the basis of race, ethnicity, citizenship, national origin, color, religion or religious creed, age, sex (including pregnancy), gender identity, sexual orientation, physical or mental disability, veteran or active military status, marital status, criminal record, genetics, retaliation, sexual harassment or any other characteristic protected by applicable law.
IMPORTANT NOTICE: Our company takes the security and privacy of job applicants very seriously. We will never ask for payment, bank details, or personal financial information as part of the application process. All our legitimate job postings can be found on our official career site. Please be cautious of job offers that come from non-company email addresses (@klaviyo.com), instant messaging platforms, or unsolicited calls.
By clicking "Submit Application" you consent to Klaviyo processing your Personal Data in accordance with our Job Applicant Privacy Notice. If you do not wish for Klaviyo to process your Personal Data, please do not submit an application.
You can find our Job Applicant Privacy Notice
here
and here (FR).
Auto-ApplySenior Information Security Engineer
Security architect job in Boston, MA
At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives. WHOOP is seeking a Senior Information Security Engineer to serve as a technical leader in our Security team reporting to our Information Security Manager. In this role, you will drive the deployment and continuous enhancement of controls that protect millions of users' biometric and health data, build scalable defenses across our infrastructure and applications, and lead incident response efforts with visibility across the business. This is an opportunity to have direct impact at scale, working alongside engineers, product teams, and executives to drive forward-looking security strategies. RESPONSIBILITIES:
Implement and enhance security controls by leading the deployment, integration, and tuning of solutions such as CNAPP, SIEM, CASB, EDR, DLP, and MDM to maximize effectiveness.
Support security design decisions by providing subject matter expertise on cloud and SaaS security best practices while influencing architecture led by the Security Architect role.
Lead incident response and investigations by guiding containment, remediation, root cause analysis, and post-incident improvements.
Strengthen application security by overseeing secure development practices and managing SAST, SCA, and DAST tooling.
Advance identity and access management by supporting IAM policy enforcement, SSO, MFA, SCIM, RBAC, and user lifecycle governance.
Secure AI systems and integrations by assessing and protecting embedded APIs and organizational AI tool usage to ensure resilience, privacy, and compliance.
Collaborate cross-functionally by working with Engineering, IT, and GRC teams to embed security into systems and workflows.
Mentor and influence by providing technical guidance, reviewing work, and promoting security-first thinking across the organization.
Stay ahead of threats and regulations by tracking emerging risks, technologies, and compliance requirements to inform forward-looking strategies.
Participate in and help improve the on-call rotation by providing guidance, escalation support, and driving improvements in response processes.
QUALIFICATIONS:
Bachelor's degree in Computer Science, Information Security, or a related technical field and/or advanced certifications (CISSP, CISM, AWS Security Specialty, SANS, etc.).
8+ years of hands-on experience in Information Security, IT Security, or a related role, including at least 2 years in a senior or lead capacity.
Proven track record implementing and managing advanced security technologies (e.g., CASB, CNAPP, CSPM, SIEM, SOAR, DLP, SWG).
Experience securing AI/ML systems or APIs, including governance of third-party AI integrations and organizational use of AI tools.
Strong understanding of modern cloud security architecture (AWS, Azure, GCP) and experience performing threat modeling and risk assessments on cloud-based systems.
Hands-on experience with application security tooling (SAST, SCA, DAST) and embedding secure development practices.
Demonstrated leadership in security incident response, investigations, and root cause analysis.
Effective communicator with the ability to influence stakeholders and explain security concepts to technical and non-technical audiences.
Strong project management skills and the ability to drive initiatives to completion in a fast-paced environment.
Experience mentoring engineers and setting operational standards.
Familiarity with compliance and risk frameworks relevant to health and AI (SOC 2, ISO 27001, PCI, GDPR, FTC guidance, HIPAA-adjacent state laws) is a plus.
Interested in the role, but don't meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.
At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.
The U.S. base salary range for this full-time position is $150,000 - $190,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training. In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.
These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.
Learn more about WHOOP.
Auto-ApplyInformation Security Manager
Security architect job in Boston, MA
Are you a Cybersecurity compliance expert ready to take the lead in a dynamic, high-impact role? Join a globally recognized firm where you'll play a key role in shaping and strengthening our cybersecurity strategy. This is your chance to make a difference in a fast-paced, professional environment that values innovation, collaboration, and technical excellence.
Why You'll Love This Role:
Drive Security Initiatives - Lead firmwide cybersecurity programs, ensuring compliance with ISO 27001 and other industry standards.
Be a Decision-Maker - Approve security risks, implement best practices, and enhance policies to safeguard critical systems.
Third-Party & Risk Management - Oversee vendor risk assessments, vulnerability management, and client security audits.
Lead & Mentor - Supervise a Compliance Analyst and provide strategic guidance across teams.
Innovate & Protect - Collaborate with IT leadership to integrate cutting-edge security solutions into firm operations.
What You Bring to the Table:
5+ years of cybersecurity experience in a complex IT environment.
Strong knowledge of security frameworks (ISO 27001, NIST, etc.).
Hands-on experience with security tools, compliance audits, and risk assessments.
Leadership experience with a passion for mentoring and developing security professionals.
Bachelor's degree in Cyber Security, Computer Science, or a related field. Security certifications (CISSP, CRISC, etc.) strongly preferred.
Offer includes:
Competitive salary: $145,000 - $170,000
Hybrid work environment
Excellent benefits package
A culture of excellence, diversity, and professional growth
Ready to step into a leadership role where your expertise will make a real impact? Apply today and be a key player in securing the future of a top international firm.
Apply to this post or email your resume directly to Dan Gilliam, email: ****************************
Tags: Cybersecurity, IT, ISO, Compliance, Security Manager
Easy ApplyCloud Security Architect
Security architect job in Boston, MA
A cloud security architect must be conversant with a breadth of technologies used to protect data, workloads, and systems within cloud platforms. Responsibilities of a cloud security architect include: * Designing and implementing cloud security strategies and policies that meet an organization's specific needs.
* Ensuring the security of cloud-based data and applications against unauthorized access, theft, and other threats.
* Conducting regular security assessments and audits to identify vulnerabilities and develop plans to address them.
* Collaborating with other IT professionals, including network engineers, developers, security team, and operational team to integrate cloud security measures into existing systems and processes.
* Staying up to date on the latest cloud security technologies, trends, and best practices.
* Reviewing and understanding remediation options from application vulnerability monitoring and assessment tooling.
Skills sought in a cloud security architect:
* Strong analytical and problem-solving skills, with an ability to think strategically and tactically about complex cloud security issues.
* Excellent communication skills, including communicating complex technical concepts to non-technical stakeholders.
* The ability to work independently but collaborate closely and effectively with developers and other IT professionals at project start and critical project junctures.
* The ability to manage multiple projects and priorities and meet deadlines in a fast-paced environment.
* Attention to detail and a commitment to quality work.
Requirements for a cloud security architect are:
* A bachelor's or master's degree in computer science, information technology, or a related field.
* More than 7 years of cloud security experience, focusing on designing and implementing secure cloud computing solutions.
* A strong understanding of cloud computing technologies, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).
* Knowledge of security frameworks such as ISO 27001, NIST Cybersecurity Framework, and CIS Controls.
* Familiarity with cloud security platforms like Microsoft Azure, Amazon Web Services, and Google Cloud Platform.
* Certifications such as Certified Cloud Security Professional (CCSP), Certified Information Systems Security Professional (CISSP), or Certified Cloud Architect (CCA) are preferred.
Desirable experience for a cloud security architect include:
* Identity Access Management and Identity Provider technologies and features
* Authentication and authorization strategies; SSO
* DevSecOps practices and testing as part of CICD pipeline workflows
* Key and secrets management services
* Networking and security best practices using VPC/VNet/Subnet deployment
* Kubernetes technology including network policy management
* Experience with private link / endpoint strategies
We are an equal-opportunity employer and do not discriminate because of race, color, religion, sex, national origin, ancestry, marital status, veteran status, age, disability, sexual orientation or gender identity or expression or any other legally protected category. InterSystems is an E-Verify Employer in the United States.
InterSystems is providing a current good faith estimate of the anticipated base salary range for this position depending on a variety of factors including experience, education, skills, and performance.
Other compensation may include a discretionary annual variable target incentive.
The company also provides generous employee benefits including:
* Medical, vision, and dental insurance
* Short-term and long-term disability, and life insurance
* 401(k) Profit Sharing Contribution
* Paid Time Off and Holidays
* Parental Leave
* Tuition reimbursement
The estimated base compensatation range for this role is:
$149,000-$181,000 USD
About InterSystems
InterSystems, a creative data technology provider, delivers a unified foundation for next-generation applications for healthcare, finance, manufacturing, and supply chain customers in more than 80 countries. Our data platforms solve interoperability, speed, and scalability problems for large organizations around the globe to unlock the power of data and allow people to perceive data in imaginative ways. Established in 1978, InterSystems is committed to excellence through its 24×7 support for customers and partners around the world. Privately held and headquartered in Boston, Massachusetts, InterSystems has 38 offices in 28 countries worldwide. For more information, please visit InterSystems.com.
Auto-ApplySenior Manager, Information Security Office Consultant
Security architect job in Concord, NH
Company DescriptionJobs for Humanity is partnering with Capital One to build an inclusive and just employment ecosystem. Therefore, we prioritize individuals coming from the following communities: Refugee, Neurodivergent, Single Parent, Blind or Low Vision, Deaf or Hard of Hearing, Black, Hispanic, Asian, Military Veterans, the Elderly, the LGBTQ, and Justice Impacted individuals. This position is open to candidates who reside in and have the legal right to work in the country where the job is located.
Company Name: Capital One
Job Description201 Third Street (61049), United States of America, San Francisco, CaliforniaSenior Manager, Information Security Office Consultant
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
What You'll Do:
Act as a central Information Security point of contact for the Enterprise Platform team
Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's Information Security capabilities, solutions, policies, procedures and standards
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special Information Security hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
Product security consulting in Authentication/Access Management /Identity application and experienced in Authentication and industry-standard protocol for authorization/authorization
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 8 years of experience working in cybersecurity or information technology
At least 7 years of experience providing guidance and oversight of Security concepts
At least 7 years of experience performing security risk assessments and security architecture reviews
At least 7 years of experience with architecture, software design, networking, and cloud infrastructure
At least 5 years of experience with cloud security engineering
Preferred Qualifications:
Bachelor's Degree
3+ years of experience in securing a public cloud environment (e.g. AWS, GCP, Azure)
4+ years of experience in IAM or related areas
Experience building software utilizing public cloud (e.g. AWS, GCP, Azure)
Familiarity with Cloud patch management practices such as system rehydration and image management
Experience utilizing Agile methodologies
Experience with Software Security Architecture
Experience with Application Security
Experience with Threat Modeling
Experience with Penetration Testing or Vulnerability Management
Experience with integrating SaaS products into an Enterprise Environment
Experience with securing Container services
Splunk-Fu / Enterprise Monitoring experience
Financial services industry experience
Professional certifications such as AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
Experience in Offensive and Defensive Security techniques
Experience in a regulated environment
Strong conceptual thinking, influence and communication skills
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
New York City (Hybrid On-Site): $230,100 - $262,700 for Sr Manager, Cyber TechnicalSan Francisco, California (Hybrid On-Site): $243,800 - $278,200 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at [email protected]. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to [email protected]
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
Senior Analyst, Security (Onsite)
Security architect job in Westford, MA
Country:
United States of America Onsite
U.S. Citizen, U.S. Person, or Immigration Status Requirements:
Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
DoD Clearance: Secret
At RTX, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
The Senior Analyst, Security will help develop, administer and maintain the program's security policies and procedures in a fast-paced, deadline driven environment to ensure compliance with the 32 CFR Part 117 National Industrial Security Program Operating Manual (NISPOM), Department of Defense Manual (DoDM) 5205.07 series, Intelligence Community Directive (ICD) 705.
**
This position is onsite in Westford, MA **
What YOU will do:
Administering the security procedures (NISPOM, DoDM 5205.07 series, and Intelligence Community Directive (ICD) 705), as they relate to operating in a classified environment for: personnel processing, media control, marking and control of documents / materials, security education, visitor control, destruction of classified,
Request, review and submit investigative Standard From (SF) for background investigations.
Submit and track foreign travel through DISS.
Implement local Standard Operating Procedures (SOP), Operations Security (OPSEC) Plans, and proprietary test plans utilizing risk management principles.
Assist in the security oversight and management to subcontractors and subordinate business units via the DD Form 254 or other contractual methods.
Support the establishment, accreditation, and maintenance of a secure facility in accordance with (IAW) ICD 705.
Establish and oversee specialized procedures for the transmission of classified and/or proprietary material/information.
Conduct and/or participate in internal reviews and/or Government inspections.
Investigate security infractions/violations and prepare reports specifying the potential for loss or compromise and the associated risk to the program(s).
Collaborate and assist the FSO on implementation of Security requirements.
This position may require travel.
Qualifications You Must Have:
Typically requires a University Degree and minimum 2 years of prior relevant experience or an Advanced Degree in a related Experience with any of the following: NISPOM, DoDM 5205.07 series, and/or ICD 705.
Active and transferable U.S. government issued TOP SECRET security clearance is required prior to start date.
U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
Qualifications We Prefer
Previous experience as a security professional supporting SAP and/or SCI programs.
Degree major in Business Management, Security and/or Risk Management, Government Policy, Information Management, Criminal Justice, or other related fields of study.
At least 5 years of National Security experience is preferred.
What We Offer:
Some of our competitive benefits packages include:
Medical, dental, and vision insurance.
Three weeks of vacation for newly hired employees.
Generous 401(k) plan that includes employer matching funds and separate. employer retirement contribution, including a Lifetime Income Strategy option.
Tuition reimbursement program.
Student Loan Repayment Program.
Life insurance and disability coverage.
Optional coverages you can buy pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection.
Birth, adoption, parental leave benefits.
Ovia Health, fertility, and family planning.
Adoption Assistance.
Autism Benefit.
Employee Assistance Plan, including up to 10 free counseling sessions.
Healthy You Incentives, wellness rewards program.
Doctor on Demand, virtual doctor visits.
Bright Horizons, child, and elder care services.
Teladoc Medical Experts, second opinion program.
And more!
Learn More & Apply Now!
Do you want to be part of a new, exciting initiative to combine foundational IT with new digital technologies? Our Digital Technology team is driving business efficiencies and a better customer experience by connecting technologies, people, information and processes. From making aircraft more electric, intelligent and integrated to building new software platforms such as Internet of Things, big data, artificial intelligence, and blockchain, there's no better place to be right now than in digital. If you're an agile thinker who enjoys utilizing modern technology to make big improvements, then you're a perfect fit for this team. Join Collins Aerospace to help us revolutionize the aerospace industry today!
WE ARE REDEFINING AEROSPACE.
* Please consider the following role type definitions as you apply for this role.
Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.
Regardless of your role type, collaboration and innovation are critical to our business and all employees will have access to digital tools so they can work with colleagues around the world - and access to Collins sites when their work requires in-person meetings.
At Collins, the paths we pave together lead to limitless possibilities. And the bonds we form - with our customers and with each other -- propel us all higher, again and again.
Apply now and be part of the team that's redefining aerospace, every day.
The salary range for this role is 66,000 USD - 130,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
Auto-ApplySenior Security Analyst
Security architect job in Boston, MA
We are seeking a detail-oriented and highly skilled Security Analyst to join our team in Boston and shape the future of Cybersecurity. As a Security Analyst at 7AI, you will leverage your expertise of the security landscape to review and analyze AI Agent investigations, ensuring accuracy and completeness, ultimately helping to build our multi-agent platform. You will be integral in building and maintaining the reliability of our AI Agents, working in tandem with Engineering and Product to inform our roadmap as we build. If you want to build the next generation of Cybersecurity and put AI in the hands of defenders, please apply below.
Key Responsibilities:
Review and validate alerts and investigations completed by the AI Agents for accuracy and completeness.
Collaborate with the Engineering and Product teams to provide feedback and assist in optimizing the AI platform.
Develop internal playbooks, standard operating procedures and tools that will guide the AI Agents to perform quality investigations.
Stay current with emerging cybersecurity trends, vulnerabilities, and new attack techniques, especially the field of AI-driven attacks.
Investigate flagged security incidents, analyzing potential threats and confirming the findings generated by AI.
Recommend mitigation strategies and remediation steps to train the AI to reduce the threat surface.
Correlate findings from multiple sources, including network logs, endpoint data, and threat intelligence, to validate AI-generated reports.
Assist with ongoing threat monitoring, triage, and prioritization of security incidents.
Required Qualifications:
4+ years of experience in a Security Analyst or similar role within the cybersecurity field.
Hands-on experience with incident response for Cloud and Identity alerts, and at least two of Email, EDR, Threat Intel and Networking alerts.
Strong understanding of security monitoring tools and techniques (SIEM, IDS/IPS, IDP, etc.).
Experience analyzing and investigating security alerts from multiple sources, including intrusion detection systems, network monitoring tools, and endpoint protection platforms.
Familiarity with the latest cybersecurity threats, attack vectors, and vulnerabilities.
Strong analytical and problem-solving skills, with the ability to verify AI-driven analysis and make independent security decisions.
Scripting experience with languages such as Python
Data querying experience with SIEM technologies (SPL, KQL, FQL, SQL, etc).
Auto-ApplySenior Security Compliance Analyst
Security architect job in Boston, MA
Job Description
At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes. Our cloud-based platform, StudyTeam, brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively. StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries. Join us in our mission to advance clinical research and improve patient care.
One mission. One team. That's OneStudyTeam.
We are seeking a Senior Security Compliance Analyst with expertise in Governance, Risk, and Compliance (GRC) to support and enhance our security and compliance programs within the healthcare industry. This role is critical in ensuring adherence to industry regulations, responding to customer audits, and maintaining compliance with ISO 27001, HIPAA, and other security frameworks.
The ideal candidate will be a detail-oriented compliance expert who can navigate complex regulatory environments, assist with internal/external audits, and drive continuous improvement in security governance. The ideal candidate must be able to operate independently while delivering on the following duties.
What You'll Be Working On:
Lead and support customer security audits, responding to security questionnaires and demonstrating compliance with security frameworks.
Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control implementation, and auditor engagement.
Ensure ongoing compliance with HIPAA, NIST CSF, and other regulatory requirements applicable to healthcare data security.
Develop and maintain policies, procedures, and security documentation to meet regulatory and contractual obligations.
Perform gap analyses and risk assessments to identify and remediate compliance risks.
Manage and improve security governance frameworks, ensuring alignment with industry best practices and business objectives.
Conduct third-party vendor risk assessments, ensuring compliance with security policies and contractual obligations.
Monitor security controls, ensuring effectiveness and continuous improvement in alignment with security frameworks.
Support security awareness training initiatives, ensuring employees understand compliance responsibilities.
Stay current on ISO 27001, HIPAA, NIST 800-53, and other relevant standards, translating them into actionable security controls.
Assist in defining security metrics and reporting on compliance status and risk posture to leadership.
Work closely with legal, security, IT, and business teams to align compliance requirements with security operations.
What You'll Bring to OneStudyTeam:
Bachelor's degree in Information Security, Computer Science, Risk Management, or related field (or equivalent experience).
8+ years of progressive experience in GRC, compliance, or security audit roles.
Experience in healthcare or regulated industries strongly preferred.
Certifications strongly preferred: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC.
Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
Strong understanding of NIST CSF, SOC 2, GDPR, and other security frameworks.
Hands-on experience with customer security audits, including responding to security questionnaires and managing security assessments.
Ability to perform risk assessments, policy reviews, and compliance gap analyses.
Strong written and verbal communication skills, with the ability to explain technical concepts to non-technical stakeholders.
Detail-oriented with excellent organizational and project management skills.
Ability to work independently and collaboratively in a remote environment.
Familiarity with GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata) is a plus.
We value diversity and believe the unique contributions each of us brings drives our success. We do not discriminate on the basis of race, sex, religion, color, national origin, gender identity, age, marital status, veteran status, or disability status.
Note: OneStudyTeam is unable to sponsor work visas at this time. If you are a non-U.S. resident applicant, please note that OneStudyTeam works with a Professional Employer Organization.
As a condition of employment, you will abide by all organizational security and privacy policies.
This organization participates in E-Verify (E-Verify's Right to Work guidance can be found here).
Physical Security Systems Engineer
Security architect job in Wilmington, MA
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, basic life, AD&D, and disability insurance
Enrollment in our company's 401 (k) or Supplemental Income Plan, subject to eligibility requirements
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law.
#LI-EL1
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID 2025-1495451
Auto-ApplyPhysical Security Systems Engineer
Security architect job in Wilmington, MA
Overview
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, basic life, AD&D, and disability insurance
Enrollment in our company's 401 (k) or Supplemental Income Plan, subject to eligibility requirements
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law.
#LI-EL1
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID
2025-1495451
Special Access Programs (SAP) - Senior Information System Security Officer (ISSO) - Andover, MA
Security architect job in Andover, MA
Country: United States of America Onsite U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
Secret - Current
At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Our cybersecurity team is seeking an Senior Information System Security Officer (ISSO) to support Special Access Programs (SAPs) 100% onsite at our facility in Andover, Massachusetts. The successful candidate will interface with the Information Systems Security Manager (ISSM) to assist with compliance maintenance and system assessments for all Special Access Program (SAP) operations at site, in accordance with Commercial and Government Entity (CAGE) code as stipulated by various US Government requirements. This includes (but is not limited to): National Industrial Security Operating Manual (NISPOM) and related documents.
What You Will Do
* Complete Special Access Programs, and Raytheon GSS required training within 6 months of appointment (annual requirements thereafter).
* Assessing and monitoring system compliance, auditing, security plan development and delivering information systems security education and awareness
* Investigating information system security violations and help prepare reports specifying corrective and preventative actions
* Reviewing and approving (within authority) configuration management requests
* Conducting technical and administrative assessments
* Integrating new cybersecurity processes, procedures, and tools
* Support the creation, review and update of cybersecurity documentation and other technical writing
Qualifications You Must Have
* Typically requires a University Degree or equivalent experience and minimum 5 years prior relevant experience, or an Advanced Degree in a related field and minimum 3 years' experience.
* Current IAM Level I certification (Security+ or other).
* Relevant Experience Considered in any combination:
* Cybersecurity, systems security or hardening
* Information Technology
* Compliance-based auditing using the Risk Management Framework (RMF), DCSA Assessment and Authorization Process Manual (DAAPM), Joint SAP Implementation Guide (JSIG), National Industrial Security Program Operating Manual (NISPOM), and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA
* Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics)
* Physical security/security, policework/criminal justice, investigations, or Border Patrol
* Project or program management, office management, senior administration, or account management
Qualifications We Prefer
* Experience working in DoD classified operating and/or laboratory environments
* Experience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc.
* Familiarity with implementation of Government directives and policies derived from NIST, CNSSI, DoD, or other Government Regulatory compliance standards within a professional industry
* Experience in the execution of the Assessment & Authorization processes, as defined within the Risk Managed Framework (RMF)
* Experience providing technical security consultation for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT)
* Familiarity with large multi-facility networks including complex components, including Windows and Linux environments
* Experience interpreting, implementing, and assessing DISA STIGs.
* Familiarity with the execution and management of cyber incident response; preservation, containment, and eradication
What We Offer
Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.
Relocation Non-Eligible - Relocation assistance not available
Learn More & Apply Now!
Please consider the following role type definition as you apply for this role:
* Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products
We are RTX
#LI-Onsite
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.
The salary range for this role is 82,000 USD - 164,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.
This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.
RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
Auto-ApplyManager, Information Security
Security architect job in Boston, MA
New England College of Optometry seeks an entry level Information Security Manager to develop, implement, and oversee a robust information security strategy and program. This critical role involves establishing and enforcing policies, procedures, and technologies to protect the confidentiality, integrity, and availability of institutional and student data. The Information Security Manager will be responsible for risk assessment, incident response, security operations, and ensuring compliance with all relevant regulations and standards. This role requires strong leadership, technical expertise, and excellent communication skills to collaborate effectively across the institution.
Responsibilities
* Develop, implement, and oversee a robust information security strategy and program in alignment with institutional goals and industry best practices.
* Establish and maintain institutional information security policies, standards, and guidelines, ensuring they are regularly reviewed, updated, and communicated.
* Manage security operations, including monitoring, detection, prevention, response, and analysis of security threats and vulnerabilities.
* Lead and coordinate the information security incident response team, managing security breaches & ensuring timely and effective resolution and post-incident analysis.
* Conduct regular risk assessments and penetration testing to identify and mitigate potential security vulnerabilities across systems, networks, and applications.
* Ensure compliance with national and international regulatory frameworks (e.g., FERPA, HIPAA, ISO 27001, SOC 2) relevant to the organization.
* Oversee security awareness training programs for all employees to promote a culture of security consciousness.
* Manage the security budget and evaluate, select, and implement appropriate security tools and technologies.
* Report on the status of the security program, vulnerabilities, and incidents to executive leadership.
* Work on "special projects" as assigned by the Chief Information Officer.
* Other duties as assigned.
Requirements
* Experience in designing, implementing, and managing enterprise-level information security programs and strategy.
* Technical knowledge of network security, application security, cloud security (e.g., AWS, Azure, GCP), and endpoint protection technologies.
* Understanding of risk management methodologies and security frameworks (e.g., ISO 27001, NIST, CIS Controls).
* Experience leading security incident response and forensic analysis.
* Strong communication and interpersonal skills, with the ability to explain complex security issues to technical and non-technical audiences.
* Knowledge of networking principles, including wireless networking.
* Excellent written and verbal communication skills, professional appearance, punctuality and a sense of urgency.
* Experience working with Active Directory and Google Cloud Platform.
* Ability and willingness to learn new technologies.
Preferred Background/Skills
* Professional certifications such as CISSP, CISM, or relevant SANS certifications.
* Experience with Governance, Risk, and Compliance (GRC) tools and processes.
* Exceptional organizational skills, with the ability to prioritize projects and tasks.
* Familiarity with scripting languages (e.g., Python, PowerShell) for security automation.
* Ability to write reports and document steps for knowledge sharing.
* Ability to work efficiently and independently with minimal supervision.
* Excellent customer service and communications skills.
Education
* Bachelor's degree in Computer Science, Information Technology, Information Security, or a related technical field.
Experience
* A minimum of 2 years of progressive experience in the field of information security.
NECO is an Equal Opportunity employer and encourages all qualified candidates to apply.
New England College of Optometry offers a robust benefits program including:
* 3 plan options for BCBS medical coverage (employer subsidized at 75% or greater)
* Mental Health and Wellness benefits
* BCBS Dental
* Discounted vision services
* 13 paid holidays and generous paid time off for sick, vacation, and personal days
* Employer-paid life insurance, and short-term and long-term disability
* Voluntary Insurance: life, critical illness, hospital indemnity, accident,
* Voluntary Benefits: employee discounts and pet insurance
* 9% employer contribution to a 403(b) retirement plan after 1 year of service with no vesting schedule or match requirement
* Qualified Public Service Loan Forgiveness Employer
Director, Information Security
Security architect job in Boston, MA
Extensive knowledge of HIPAA and HITECH.
Knowledge of and experience with Information Security frameworks such as HiTRUST, NIST, or ISO 27001.
Bachelor's degree in information security, information assurance, information technology, computer science, or a related discipline.
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or related certification.
Five (5) years in an information security operations or management role.
Passion for the mission of Health Leads and strong commitment to Health Leads' core values: belief in collective strength and the power of shared work, constant and courageous learning, celebrating our victories and each other, and stepping up leaders in a common vision.
Experience with information security for cloud environments and/or software-as-a-service (SaaS) platforms.
Knowledge of security-related technologies and processes, including but not limited to: data loss prevention (DLP), identity and access management (IAM), endpoint security, vulnerability and configuration management, security information and event management (SIEM), incident response and digital forensics, disaster recovery/business continuity planning, network security (LAN/WAN).
Ability to communicate complex ideas and information both verbally and writing, in a clear, concise, and effective manner to technical and non-technical audiences including customers and colleagues.
Superior capabilities for partnering; ability to be effective as both a team member and as a leader of teams in defining objectives, staying on task and reaching consensus; soliciting participation, challenging ideas and summarizing accomplishments and planned actions.
Show integrity and ethical behavior; respect confidentiality, business ethics and organizational standards.
Ability to formulate the cost benefit of security initiatives in the context of overall business risk mitigation and the organization's operational objectives. Ability to compare, contrast and prioritize among alternative approaches to meet those objectives.