Security engineer jobs in North Attleborough, MA - 433 jobs
All
Security Engineer
Hacker
Security System Engineer
Security Architect
Senior Security Engineer
Cyber Security Engineer
Senior Information Systems Engineer
Information Security Engineer
Senior Security Specialist
Information Security Analyst
Senior Information Security Engineer
Principal SaaS Security Engineer Boston, MA, USA Dev-Ops
PTC Inc. 4.8
Security engineer job in Boston, MA
Hybrid## Principal SaaS SecurityEngineerBoston, MA, USAOur world is transforming, and PTC is leading the way.Our software brings the physical and digital worlds together, enabling companies to improve operations, create better products, and empower people in all aspects of their business.Our people make all the difference in our success. Today, we are a global team of nearly 7,000 and our main objective is to create opportunities for our team members to explore, learn, and grow - all while seeing their ideas come to life and celebrating the differences that make us who we are and the work we do possible.**Principal SecurityEngineer-SaaS**JR110938**Key Responsibilities*** **Secure Architecture & Design** + Architect and implement security controls for multi-tenant SaaS environments for both commercial and US federal customers + Harden cloud infrastructure (AWS preferred) and enforce least-privilege IAM policies. + Integrate encryption and key management solutions for data at rest and in transit.* **Threat Detection & Incident Response** + Configure and monitor security tools like Wiz and Crowdstrike. Guide remediation efforts. + Develop and maintain SIEM rules and dashboards for real-time threat monitoring. + Lead incident response efforts, including root cause analysis and remediation.* **Vulnerability Management** + Own vulnerability scanning, prioritization, and remediation across services. + Tune automated scanning in CI/CD pipelines using tools like **Black Duck, or Checkmarx**.* **DevSecOps & Automation** + Build scripts and automation for security posture validation and drift detection.* **Collaboration & Leadership** + Partner with engineering teams to integrate security best practices early in development. + Mentor junior engineers and advocate for secure coding principles.**Required Qualifications*** 8+ years in securityengineering, with at least 3 years in SaaS or cloud-native environments (DevSecOps).* Deep expertise in **AWS security services** (IAM, KMS, Security Hub, GuardDuty).* Strong background in **vulnerability management, SIEM tools (Splunk, Opensearch), and automation scripting** (Terraform, Ansible, Python).* Experience with **container security** and orchestration (Docker, Kubernetes).* Experience securing Linux deployments.**Nice-to-Have*** Working knowledge of **FedRAMP, NIST SP 800-53, or similar compliance processes**.* Relevant certifications: CISSP, CCSP, AWS Security Specialty.* Work on cutting-edge SaaS security challenges.* Influence architecture and security strategy at scale.* Collaborate with a team passionate about building secure, resilient systems.**Work Environment:**The candidate may be required to participate in an on-call rotation to respond to security incidents.The SecOps Engineer position will be a member of the Onshape Technical Operations team. This is a primarily US-based operations, site reliability, compliance, and security team. The team is part of Onshape Engineering and works very closely with other teams in engineering to deliver a reliable, secure service to our customers.PTC carefully considers a wide range of factors when determining compensation. The anticipated annual salary range for this position is between $118,000 - 165,000. The anticipated annual salary range encompasses both the base salary and the on-target incentive compensation that may be attained in this role. The salary range reflects a good-faith estimate of compensation at the time of posting.Actual compensation may vary based on a candidate's skills, qualifications, experience, and location. Eligible employees also have the opportunity to become a PTC shareholder through our employee share purchase program (ESPP) which allows for the purchase of discounted PTC stock. Certain roles may also be eligible for participation in our equity programs. Employees may be eligible for medical, dental and vision insurance, paid time off and sick leave, tuition reimbursement, 401(k) contributions and employer match, flexible spending accounts, life insurance, disability coverage and if you are an office-assigned employee, a generous commuter subsidy. All total rewards and benefits programs are subject to plan eligibility and other terms and conditions.For more information about PTC's comprehensive benefits, please visit our .Applications will be accepted on an on-going basis.At PTC, we believe in the power of diverse ideas and perspectives. As a global company that values and respects all identities, cultures, and perspectives, we strive to create an inclusive PTC for ALL through an environment where everyone feels like they belong and are empowered to bring their true, authentic selves to work. Proud to be an Equal Opportunity Employer, we welcome applicants from all backgrounds and hire without regard to race, national origin, religion, age, color, ethnicity, ancestry, marital status, sex (including pregnancy), sexual orientation, gender identity, gender expression, genetic information, disability, veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.PTC endeavors to make ptc.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact PTC's Talent Acquisition team at *************************. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.Life at PTC is about more than working with today's most cutting-edge technologies to transform the physical world. It's about showing up as you are and working alongside some of today's most talented industry leaders to transform the world around you.We respect the privacy rights of individuals and are committed to handling Personal Information responsibly and in accordance with all applicable privacy and data protection laws. ."**Onshape** is a next-generation, global Software-as-a-Service (SaaS) product development platform that helps businesses of all sizes modernize and accelerate their design and manufacturing processes. The cloud-native platform is the only all-in-one system that combines robust computer-aided design (CAD) with powerful data management and collaboration tools. **Onshape** helps extended design teams work together faster from any location and helps executives make better decisions with real-time business analytics and unprecedented visibility into their company's operations.We are seeking a **Principal SecurityEngineer-SaaS** to lead the design, implementation, and continuous improvement of security for our cloud-native SaaS platform. This role is deeply technical and hands-on, focused on **threat detection, vulnerability management, secure architecture, and SecOps integration**. Compliance knowledge (e.g., FedRAMP, NIST) is a plus but secondary to strong securityengineering expertise.You can learn more about who we are, what we do, and what sets us apart by following us on social media. The #lifeat PTC experience is one that we're proud to share and it just keeps getting better.Top skills Active DirectoryCloud ComputingFirewallsEthical HackingIPsecNetworkingInformation Technology
#J-18808-Ljbffr
$118k-165k yearly 5d ago
Looking for a job?
Let Zippia find it for you.
Cloud-Native Java Engineer for Secure IAM SaaS
RSA Security USA LLC 4.7
Security engineer job in Boston, MA
A leading security technology firm is looking for a Senior Java Engineer to design, develop, and maintain cloud-native SaaS solutions for their RSA ID Plus platform. Candidates should have over 5 years of experience in Java and cloud-native applications. This role emphasizes collaboration within a distributed team to deliver secure Identity and Access Management products. The position offers a competitive salary range of $90k to $195k along with comprehensive benefits including flexible paid time off and a 401(k) retirement plan.
#J-18808-Ljbffr
$90k-195k yearly 5d ago
Security Engineer
Givzey, Inc.
Security engineer job in Boston, MA
Security & IT Engineer
About the Role
We're looking for a hands‑on Security & IT Engineer to own and strengthen Givzey's security posture while managing our internal IT infrastructure. This is a hybrid role combining securityengineering, cloud infrastructure management, and IT operations. You'll be responsible for everything from ensuring SOC 2 / ISO compliance and securing AWS environments to managing employee devices and implementing company‑wide security best practices.
This role is perfect for someone who can think strategically about risk and compliance while still getting into the weeds of configuration, automation, and incident response.
About Givzey:
Givzey is a Boston‑based, rapidly growing digital fundraising solutions company, built by fundraisers for nonprofit organizations.
Join a fast‑growing, mission‑driven team working across two innovative platforms: Givzey, the first donor commitment management platform revolutionizing nonprofit fundraising, and Version2.ai, a cutting‑edge AI platform helping individuals and organizations create their most authentic, effective digital presence. As an engineer at the intersection of philanthropy and artificial intelligence, you'll build scalable, high‑impact solutions that empower nonprofit fundraisers and redefine how people tell their stories online. We're a collaborative, agile team that values curiosity, autonomy, and purpose. Whether you're refining AI‑driven experiences or architecting tools for the future of giving, your work will help shape meaningful technology that makes a difference.
What You'll Do Security & Compliance
Own and evolve our information security program, including policies, controls, and procedures aligned with SOC 2, ISO 27001, and other frameworks.
Conduct regular security risk assessments and audits; maintain continuous compliance readiness.
Manage vulnerability scanning, penetration testing, and incident response processes.
Oversee access control, identity management, and data protection across all systems.
Partner with legal and operations teams to ensure vendor and data processing compliance.
Cloud Infrastructure SecuritySecure and manage AWS infrastructure (IAM, networking, encryption, logging, monitoring, etc.).
Implement security automation for configuration management, secrets management, and incident alerts.
Collaborate with engineering teams to embed security into CI/CD pipelines and software lifecycle.
IT Administration
Manage company devices (Macs) using MDM and endpoint protection tools.
Set up and maintain SSO, MFA, and access control across tools and services.
Handle onboarding/offboarding from a security and IT perspective.
Support internal IT operations and ensure systems run securely and smoothly.
Governance & Culture
Build a strong security culture through training, awareness, and best practices.
Stay current on emerging security threats and compliance standards.
What You'll Bring
5+ years of experience in IT, DevOps, or securityengineering roles.
Hands‑on experience with AWS, IAM, and cloud security tools.
Strong familiarity with SOC 2, ISO 27001, and related compliance frameworks (TX‑RAMP).
Understanding of network security, identity & access management, and incident response.
Comfortable being both strategic and tactical - from writing policies to hardening infrastructure.
Bonus: experience with Pulumi
#J-18808-Ljbffr
A federal services provider located in Boston is seeking a Cyber SecurityEngineer to enhance software security for federal clients. The ideal candidate will possess a Bachelor's degree in a relevant field and experience with DevSecOps tools. Responsibilities include implementing security in software, maintaining security processes, and conducting assessments. This role promises to offer impactful career opportunities within a company that emphasizes employee ownership and diversity.
#J-18808-Ljbffr
$81k-110k yearly est. 2d ago
Senior Cloud Security Specialist
Publicis Sapient 4.7
Security engineer job in Boston, MA
40 Water Street - 40 Water Street Boston, Massachusetts 02109 United States
Leveraging cybersecurity fundamentals, you will possess a strong understanding of cybersecurity principles, threat landscape, risk management and compliance requirements (such as GDPR, HIPPA, PCI DSS)
Security Architecture Design: Proficiency in designing secure cloud architectures, including network security, identity and access management (IAM), data protection, encryption, and secure application development practices.
Network Security: Expertise in designing secure cloud network architectures including VPCs, virtual network segmentation, network security groups (NSGs), Cloud Firewalls, VPN gateways, IDS/IPS, and DDoS protection.
Data Security and Encryption: Knowledge of data protection techniques such as encryption, data masking, tokenization, and data loss prevention (DLP) Identity and Access Management (IAM)
Compliance and Governance: Understanding of regulatory compliance requirements and best practices for ensuring Cloud environments meet industry standards and regulatory mandates. This may include knowledge of Azure Policy, Azure Blueprints, GCP Security Command Center, AWS Compliance Center and other compliance assessment tools.
Experience with multiple cloud service providers (AWS, GCP, Azure) with deep knowledge in at least one major Cloud service provider
Fundamental understanding of security in cloud and how it differs from on-premise
Extensive hands-on experience in Terraform and CI/CD processes and an understanding of DevSecOps pipelines/workflows
Experience in working in a highly regulated environment such as banking, financial services or government (regional/network borders etc.)
Bachelor s degree in computer science, Information Systems or related course of study required or equivalent work experience. Related master s degree a plus
Security certifications in (CISSP, GIAC, Security+)
Additional Information
Benefits of Working Here
An inclusive workplace that promotes diversity and collaboration.
Access to ongoing learning and development opportunities.
Competitive compensation and benefits package.
Flexibility to support work-life balance.
Comprehensive health benefits for you and your family.
Generous paid leave and holidays.
Wellness program and employee assistance.
Pay Range: $160,000 - $215,000
The range shown represents a grouping of relevant ranges currently in use at Publicis Sapient. Actual range for this position may differ, depending on location and specific skillset required for the work itself.
As part of our dedication to an inclusive and diverse workforce, Publicis Sapient is committed to Equal Employment Opportunity without regard for race, color, national origin, ethnicity, gender, protected veteran status, disability, sexual orientation, gender identity, or religion. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at ***************************
Your information will be kept confidential according to EEO guidelines.
Company Description
Publicis Sapient is a digital transformation partner helping established organizations get to their future, digitally-enabled state, both in the way they work and the way they serve their customers. We help unlock value through a start-up mindset and modern methods, fusing strategy, consulting and customer experience with agile engineering and problem-solving creativity. United by our core values and our purpose of helping people thrive in the brave pursuit of next, our 20,000+ people in 53 offices around the world combine experience across technology, data sciences, consulting and customer obsession to accelerate our clients' businesses through designing the products and services their customers truly value.
Looking for the latest openings or want to get rewarded for recommending a peer?
#J-18808-Ljbffr
$160k-215k yearly 5d ago
Information Security Engineer 3
WEX Inc. 4.8
Security engineer job in Boston, MA
Information SecurityEngineer 3 page is loaded## Information SecurityEngineer 3locations: Portland, ME: Boston, MAtime type: Full timeposted on: Posted Todayjob requisition id: R20174****About the Team/Role****We're the Global Information Security Team at WEX, responsible for implementing and operating security technologies and processes throughout WEX. We partner closely with internal teams and customers to assure WEX operates in a secure and compliant manner. Our team holds itself to a high-standard and we collaborate closely with one another to ensure strong, reliable and effective relationships. We own our results and we take pride of ownership in everything we do. **We need help!** Changing the world isn't easy, and we have a lot of work ahead of us. From securing applications, data centers and cloud resources, we've got more work than we can handle and we're looking for great people to come along for the ride. We are looking for an application securityengineer is responsible for ensuring the secure function of software security and familiarity with multiple general security practices and toolsets**How you'll make an impact** **Culturally, you're:*** A highly motivated securityengineer who loves working on small, high performing teams that interface with the entire enterprise* A collaborative, solid communicator who works well with your team and stakeholders to drive projects from inception to completion* Someone who cares deeply for team results but is able to work independently to deliver high quality solutions for projects and operational tasks* Comfortable balancing the need to move fast with the realities of working in a highly regulated organization* Someone who thrives in situations where details and accuracy are vital* A skilled worker that has the motivation, expertise, and work ethic to operate independently across global time zones, and who is able to complete tasks and deliverables with minimal oversight* Work closely with Enterprise IT teams on securing Wex's infrastructure and applications* Able to mentor other engineers both technically and professionally**Technically, you:*** Engineer, implement, and monitor security measures to protect the enterprise* Configure and troubleshoot security infrastructure devices* Regularly review configurations and develop improvement plans* Develop technical solutions and new security tools to help mitigate security findings* Write comprehensive reports including assessment-based findings, outcomes and recommendations for security enhancement.* Have a general background in IT, Security, and supporting processes* Deep experience working with compliance and regulatory frameworks such as PCI-DSS, HIPAA/HITRUST, SOX, GDPR, NIST, etc.**Experience you'll bring*** Have 3-5 years of experience in Enterprise Information SecurityEngineering* Have 3-5 years of broad experience with security technologies such as NextGen AV (EDR), DLP, email security (SPF, DMARC, DKIM), web filtering, HSM, Key and Certificate management, or Identity and Access Management* Have a strong, practical understanding of modern cloud IT infrastructure, networking, and securityengineering concepts* Are able to troubleshoot network and security issues within a complex environment* Have 3-5 years of experience in engineering solutions which meet security, compliance, and business needs* Can commit and deliver on very specific project/delivery timelines with minimal supervision* Are able work in an on-call rotation which may include some night and weekend shifts* Have excellent customer support skills, both written and verbal* Have 3-5 years of experience Linux and Unix operating systems* Have 3-5 years of experience with securing applications and enabling secure communication through HTTPS**It would be nice if you*** Have cloud experience with AWS and Azure* Experience working with AI/LLM Security* Experience working with Splunk* Experience working with CrowdStrike* Experience with automation technologies (SOAR) and writing code for automation* Experience working with Fortanix, Venafi, or similar Pay Range: $102,000.00 - $135,000.00WEX is a global commerce platform that helps businesses solve for operational complexities like employee benefits, managing and mobilizing fleets, and streamlining payments.With over 6,500 employees, we work with large and small companies in more than 200 countries and territories, and can tailor our services to meet the unique needs of their businesses.We hire people who share our passion for continuous innovation and client service that is unparalleled in the industry. Offering comprehensive and market competitive benefits, our offerings are designed to support your personal and professional well-being. If you're looking for a growing career - come be part of WEX today. To learn more about our employee benefits, please .WEX is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex, race, color, age, national origin, religion, sexual orientation, gender identity, protected veteran status, disability or other protected status. WEX promotes a drug-free workplace.Qualified individuals with a disability have the right to request a reasonable accommodation. If you require a reasonable accommodation as a result of your disability at any point in the job application process, please submit your request through our .This form is for accommodation requests only and cannot be used to inquire about the status of applications.
#J-18808-Ljbffr
$102k-135k yearly 5d ago
Principal Cloud Security Architect
Labelbox 4.3
Security engineer job in Boston, MA
The Principal Cloud Security Architect evaluates cloud architectures, identity models, permissions, and security controls across large-scale environments. This role focuses on identifying architectural risks, misconfigurations, and long‑term security design gaps.
What You'll Do
Assess cloud architectures (AWS, Azure, GCP) for security gaps
Review IAM configurations, network segmentation, and resource policies
Identify misconfigurations, privilege risks, and insecure patterns
Summarize architectural flaws and provide structured mitigation guidance
Validate alignment with security frameworks and best practices
Support recurring assessments of cloud environments and deployment patterns
What You Bring
Must-Have:
Deep experience in cloud security architecture
Strong understanding of IAM, network design, and cloud service models
Ability to document complex architectures in clear, structured form
Nice-to-Have:
Experience with multi-cloud, zero‑trust, or high‑compliance environments
$40 - $80 an hour
#J-18808-Ljbffr
$40-80 hourly 5d ago
Senior Cloud Security Engineer - Product Security
IBM 4.7
Security engineer job in Lowell, MA
A leading software solutions company is seeking a Senior Product SecurityEngineer to enhance their product security function. In this role, you will collaborate closely with R&D teams to ensure security is integrated into the cloud offerings, including multi-cloud environments. Responsibilities include monitoring vulnerabilities, executing security assessments, and contributing to secure software architecture. Candidates should have extensive experience in security practices, particularly in cloud environments. This position offers a hybrid work arrangement within the United States.
#J-18808-Ljbffr
$77k-100k yearly est. 5d ago
Senior Remote Cloud Security Engineer (AWS)
Plan A Technologies, Inc.
Security engineer job in Boston, MA
A leading technology firm is seeking an experienced Cybersecurity Engineer to implement and maintain cloud network security systems. The role includes daily monitoring of security alerts, incident response, and collaboration with engineering teams. Candidates must have a minimum of 4 years in cybersecurity engineering, proficiency in AWS, and familiarity with security technologies. This position offers a supportive team environment and flexibility in work location, as well as competitive benefits.
#J-18808-Ljbffr
$96k-134k yearly est. 1d ago
Systems Security Engineer
General Dynamics Mission Systems 4.9
Security engineer job in Dedham, MA
Basic Qualifications
Requires a Bachelor's degree in Systems Engineering, or a related Science, Engineering, Technology or Mathematics field. Also requires 5+ years of job-related experience, or a Master's degree plus 3 years of job-related experience. Agile experience preferred.
CLEARANCE REQUIREMENTS: Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
We are seeking a Systems SecurityEngineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
***Please note you will be onsite 100%.
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $112,924.00 - USD $125,275.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
$112.9k-125.3k yearly Auto-Apply 60d+ ago
Manual Ethical Hacker
Bank of America Corporation 4.7
Security engineer job in Boston, MA
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
Job Description:
Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the vulnerability of the bank's applications to malicious hacking activity.
This intermediate technical role is responsible for performing application security assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include performing research, understanding the bank's security policies, working with the appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business.
Key Responsibilities in order of importance:
* Perform assigned analysis of internal and external threats on information systems and predict future threat behavior
* Incorporate threat actors' tactics, techniques, and procedures into offensive security testing
* Perform assessments of the security, effectiveness, and practicality of multiple technology systems
* Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
* Prepare and present detailed technical information for various media including documents, reports, and notifications
* Provide clear and practical advice regarding managed risks
* Learn and develop advanced technical and leadership skills, Mentor Junior assessors in technical tradecraft and soft skills
Required Skills:
* Minimum of 4 years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
* Detailed technical knowledge in at least 3 of the following areas: securityengineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks; single sign-on technologies; exploit automation platforms; RESTful web services
* SQL injection/XSS attack without the use of tools
* Experience performing manual code reviews for security relevant issues
* Experience working with SAST tools to identify vulnerabilities
* Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
* Experience performing manual web application assessments i.e., must be able to simulate a
* Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
* Experience with vulnerability assessment tools and penetration testing techniques
* Solid programming/debugging skills
* Experience of using a variety of tools, included, but not limited to, IBM AppScan, Burp and SQL Map
* Threat Analysis
* Innovative Thinking
* Technology Systems Assessment
* Technical Documentation
* Advisory
Desired:
* CISSP, CEH, OSCP, OSWE, GPEN, PenTest+ or similar
* Strong programming/scripting skills
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
$90k-129k yearly est. 27d ago
Senior Information Security Engineer
Whoop 4.0
Security engineer job in Boston, MA
Job DescriptionAt WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives. WHOOP is seeking a Senior Information SecurityEngineer to serve as a technical leader in our Security team reporting to our Information Security Manager. In this role, you will drive the deployment and continuous enhancement of controls that protect millions of users' biometric and health data, build scalable defenses across our infrastructure and applications, and lead incident response efforts with visibility across the business. This is an opportunity to have direct impact at scale, working alongside engineers, product teams, and executives to drive forward-looking security strategies. RESPONSIBILITIES:
Implement and enhance security controls by leading the deployment, integration, and tuning of solutions such as CNAPP, SIEM, CASB, EDR, DLP, and MDM to maximize effectiveness.
Support security design decisions by providing subject matter expertise on cloud and SaaS security best practices while influencing architecture led by the Security Architect role.
Lead incident response and investigations by guiding containment, remediation, root cause analysis, and post-incident improvements.
Strengthen application security by overseeing secure development practices and managing SAST, SCA, and DAST tooling.
Advance identity and access management by supporting IAM policy enforcement, SSO, MFA, SCIM, RBAC, and user lifecycle governance.
Secure AI systems and integrations by assessing and protecting embedded APIs and organizational AI tool usage to ensure resilience, privacy, and compliance.
Collaborate cross-functionally by working with Engineering, IT, and GRC teams to embed security into systems and workflows.
Mentor and influence by providing technical guidance, reviewing work, and promoting security-first thinking across the organization.
Stay ahead of threats and regulations by tracking emerging risks, technologies, and compliance requirements to inform forward-looking strategies.
Participate in and help improve the on-call rotation by providing guidance, escalation support, and driving improvements in response processes.
QUALIFICATIONS:
Bachelor's degree in Computer Science, Information Security, or a related technical field and/or advanced certifications (CISSP, CISM, AWS Security Specialty, SANS, etc.).
8+ years of hands-on experience in Information Security, IT Security, or a related role, including at least 2 years in a senior or lead capacity.
Proven track record implementing and managing advanced security technologies (e.g., CASB, CNAPP, CSPM, SIEM, SOAR, DLP, SWG).
Experience securing AI/ML systems or APIs, including governance of third-party AI integrations and organizational use of AI tools.
Strong understanding of modern cloud security architecture (AWS, Azure, GCP) and experience performing threat modeling and risk assessments on cloud-based systems.
Hands-on experience with application security tooling (SAST, SCA, DAST) and embedding secure development practices.
Demonstrated leadership in security incident response, investigations, and root cause analysis.
Effective communicator with the ability to influence stakeholders and explain security concepts to technical and non-technical audiences.
Strong project management skills and the ability to drive initiatives to completion in a fast-paced environment.
Experience mentoring engineers and setting operational standards.
Familiarity with compliance and risk frameworks relevant to health and AI (SOC 2, ISO 27001, PCI, GDPR, FTC guidance, HIPAA-adjacent state laws) is a plus.
Interested in the role, but don't meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.
At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.
The U.S. base salary range for this full-time position is $150,000 - $190,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training. In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.
These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.
Learn more about WHOOP.
$150k-190k yearly 26d ago
Physical Security Systems Engineer
Security Director In San Diego, California
Security engineer job in Wilmington, MA
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, retirement plan, basic life, AD&D, and disability insurance
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law
#LI-EL1
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID 2025-1495451
$80k-115k yearly Auto-Apply 19d ago
Information Security Data Analyst
Stratacuity
Security engineer job in Boston, MA
Information Security Data Analyst Large Banking Client Duration: 6+ month contract; Strong potential for extension / full time hire Our client in the banking industry is seeking a Data Analyst to join the Information Security & Risk team. This role will focus on data protection, compliance, and security analytics, ensuring sensitive information is safeguarded across systems and processes. The position offers an opportunity to contribute to risk mitigation, regulatory adherence, and the development of robust data security controls in a dynamic financial services environment.
Responsibilities
* Monitor, analyze, and report on data security events and potential data loss incidents
* Collect, validate, and analyze data from multiple sources to ensure accuracy and integrity
* Develop and maintain dashboards for security metrics using Power BI and AWS QuickSight
* Execute queries to identify anomalies, trends, and potential vulnerabilities in data flows
* Implement and enforce Data Loss Prevention (DLP) rules and policies across systems
* Conduct testing and validation of DLP rules to ensure accuracy and effectiveness
* Manage website whitelisting processes to support secure business operations
* Support compliance with regulatory standards and internal security frameworks
* Collaborate with security, risk, and IT teams to design and optimize data protection strategies
* Communicate findings and actionable recommendations to leadership and stakeholders
Required Experience
* Minimum 3+ years of experience in data analytics with a focus on security or compliance
* Strong understanding of data protection principles, DLP tools, and regulatory frameworks
* Hands-on experience implementing and testing DLP rules and security controls
* Proficiency in SQL Server for query writing and data validation
* Dashboarding experience with Power BI and AWS QuickSight
* Working knowledge of Python for automation and data analysis
* Familiarity with security monitoring tools and incident response processes
* Prior experience in financial services, preferably banking or fintech
Desired Experience
* Exposure to DLP solutions (e.g., Purview, Netskope)
* Experience with identity and access management concepts
* Understanding of data classification and encryption standards
Soft Skills
* Strong communication skills to engage leadership and cross-functional teams
* Detail-oriented with a proactive approach to risk identification
* Ability to work in a fast-paced, compliance-driven environment
* Apex Benefits Overview
* Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a retirement plan (401k or local country equivalent) program. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Apex team member can provide.
* · EEO Employer
* Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at [email protected] or ************.
Apex Systems is a world-class IT services company that serves thousands of clients across the globe. When you join Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Apex uses a virtual recruiter as part of the application process. Click here for more details.
Apex Benefits Overview: Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Apex team member can provide.
Employee Type:
Contract
Remote:
Yes
Location:
Boston, MA, US
Job Type:
Date Posted:
November 18, 2025
Pay Range:
$45 - $60 per hour
Similar Jobs
* Information Security Analyst
* Information Systems Security Officer
* Senior Information SecurityEngineer
* Information Systems Analyst
* Application Security Analyst
$45-60 hourly 11d ago
Senior Information Systems Security Engineer (ISSE)
Applied Research Solutions 3.4
Security engineer job in Bedford, MA
ARS is seeking a Senior Information Systems SecurityEngineer (ISSE) candidate located at Hanscom, AFB. Applied Research Solutions (ARS) is respected as a world-class provider of technically integrated solutions as we deliver premier talent and technology across our focused markets for unparalleled, continuous mission support. Awarded a Best Places to Work nominee since 2020, ARS recognizes that without our career- driven, loyal professionals, we would not be able to deliver state-of-the-art results for our mission partners. We firmly believe that prioritizing our employees is of the upmost importance. We provide a culture where our employees are challenged to meet their career goals and aspirations, while still obtaining a work/life balance. ARS employees are motivated through our industry competitive benefits package, our awards and recognition program, and personalized attention from ARS Senior Managers.
**Responsibilities include:**
+ Support the system/application authorization and accreditation (A&A) effort for weapon systems and PIT Systems, to include assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing DoD and Air Force policies (i.e., Risk Management Framework (RMF). Understanding of how RMF intersects with the acquisition process and how it's used to generate requirements; how RMF and Cybersecurity should be covered in contracts - requirements, deliverables, PWS/SOW language. Understanding how to work through RMF and controls with a program to establish appropriate levels of risk based on program lifecycle and mission requirements.
+ Recommend policies and procedures to ensure the reliability of and accessibility to information systems and to prevent and defend against unauthorized access to systems, networks, and data.
+ Develop, execute, and track the performance of security measures to protect information and network infrastructure and computer systems.
+ Review and assess architectures and recommend cybersecurity strategies to developmental and legacy system designs.
+ Assess threats to determine impact and recommend corrective actions to program managers to reduce risk.
+ Translate program/system requirements into technical requirements and architectures needed to meet program objectives.
+ Life cycle development Promote awareness of security issues among management and ensuring sound security principles are reflected in program's' visions and goals. Participate in systems design.
+ Understanding of DevSecOps environments to check for security flaws and vulnerabilities during code review.
+ Understanding of operating systems including Linux, Ubuntu, IoT systems, ZTA environments and Cloud development.
+ Identify, define, and document system security requirements and recommend solutions to management.
+ Plan, develop, implement, and update Cyber Security Strategy Information within the Program Protection Plan (PPP) and assess CPI (Critical Program Information) and CC (Critical Components) analysis.
+ Recommend and review Tempest requirements, systems security contingency plans and disaster recovery procedures.
+ Experience with compliance and vulnerability and software scanning tools (STIGs, Nessus, ACAS, SCC/ SCAP, etc.) to include the review and creation of mitigation reports.
+ Review the Vendor submitted Contract Data Requirement List (CDRL) items for Cybersecurity related areas, to ensure technical requirements have been met, and provided substantial comments and recommendations to the Program Management (PM) team as to adequacy of the CDRL.
+ Other duties as assigned.
**Qualifications/Technical Experience Requirements:**
+ Must be a US citizen
+ BA/BS Degree, and 15 years of Cyber-Security experience and 5 years DoD experience or; MA/MS Degree and 12-year experience, 5 years in DoD or; 20 years of directly related experience with proper certifications of which 8 years are in DoD
+ DoD 8570.01 MMGT512 compliant certification.
+ Experience with the Risk Management Framework (RMF).
+ **Active Top Secret Security Clearance**
The expected annual salary range: $178k - $192k. Salary is dependent upon the role and associated responsibilities, candidate's experience, and qualifications to include education/training, and key skills.
All positions at Applied Research Solutions are subject to background investigations. Employment is contingent upon successful completion of a background investigation including criminal history and identity check.
This contractor and subcontractor shall abide by the requirements of 41 CFR 60-741.5(a). This regulation prohibits discrimination against qualified individuals based on disability and requires affirmative action by covered prime contractors and subcontractors to employ and advance in employment qualified individuals with disabilities.
This contractor and subcontractor shall abide by the requirements of 41 CFR 60-300.5(a). This regulation prohibits discrimination against qualified protected veterans and requires affirmative action by covered contractors and subcontractors to employ and advance in employment qualified protected veterans.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights (**************************** notice from the Department of Labor.
$178k-192k yearly 5d ago
Cyber Security Engineer
Highlighttech
Security engineer job in Boston, MA
Highligth is seeking a Cyber SecurityEngineer to join our software team supporting a federal customer in Bedford, MA.
Responsibilities
This individual must have advanced knowledge and hands‑on experience in developing and implementing security into software programs. They will be responsible for maintaining and improving the performance of existing security process for development code, with duties to write and update software code and security processes under direction from the assigned Government Product Manager. Individual must have hands‑on experience in software security assessments, and be capable of documenting and communicating the outcome of these assessments to leadership.
Qualifications
Bachelor Degree in Computer Science, Mathematics or equivalent technical degree, with concentrations/focus on security or equivalent. Or an additional 4 years of software security assessment experience (total of 6 years, added to requirement below)
1+ years experience with DevSecOps tools and processes to include, but not limited to Git, Concourse, SonarQube, Fortify and Sysdig
2 years experience in some software development discipline to include Java, Web services, Database, or web application development.
2 years in software security assessments and/or reviews.
2 years experience of reviewing software documentation, security findings/comments, and source code (if available) for accuracy, completeness, and associated risk
About Highlight
For over ten years, Highlight has provided Development and Modernization, Secure IT, and Mission Solution services to our federal government customers. Our team knows the technology; we understand how our customers and their stakeholders work; and we know how to implement industry best practices to deliver high‑quality, end‑to‑end solutions that minimize risk and maximize results.
Since our inception, Highlight has had an employee‑first mindset. Our mission is to provide employees with rewarding and impactful career opportunities. In 2021, Highlight's founder, Rebecca Andino, implemented an Employee Stock Ownership Plan to embody and expand our culture of transparency, teamwork and rewarding the work of our employees. By becoming an ESOP, our employee‑owners share in the success of the company through their ownership stake. To learn more about ESOPS, check out: *****************
We're an Equal Opportunity Employer (EOE) that empowers our people to fearlessly drive change - regardless of their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other characteristics. Our team is dedicated to foster diversity within our teams to promote creativity, innovation, and teamwork to deliver the best solutions for our customers.
To receive compensation and benefits information for this role, contact us or email us at **************************** Please include the Req ID (this is at the top of the posting under the position title) in the subject line of the email.
Recruitment Fraud Disclaimer
Highlight takes your security seriously. Please be aware that fraudulent actors may attempt to circulate fictitious job opportunities and impersonate our recruiters. The main purpose of these correspondences is to obtain privileged information from individuals.
To protect yourself, keep the following in mind:
All emails will come from an official @highlighttech.com or @talent.icims.com email address.
We will never request payment or personal financial information during the recruitment process.
We will not send job offers via email. All offers are first extended verbally by a member of our recruitment team whenever possible, and then followed up via written communication through official channels.
If you suspect fraudulent activity or have any doubts about the authenticity of an email, letter, or telephone communication supposedly from, for, or on behalf of Highlight, please contact our team directly at ****************************.
#J-18808-Ljbffr
$81k-110k yearly est. 2d ago
SaaS Security Architect & DevSecOps Lead
PTC Inc. 4.8
Security engineer job in Boston, MA
A leading tech company seeks a Principal SaaS SecurityEngineer to enhance security measures for their cloud platform. The role demands over 8 years in securityengineering, with expertise in AWS services and vulnerability management. This position involves leading security architecture, incident response, and mentoring junior engineers in best practices. Ideal candidates should have a strong background in DevSecOps and a passion for building secure systems, contributing to a collaborative environment focused on innovation.
#J-18808-Ljbffr
$108k-140k yearly est. 5d ago
Lead Cloud Security Architect: IAM & Zero-Trust
Labelbox 4.3
Security engineer job in Boston, MA
A leading cloud technology firm in Boston seeks a Principal Cloud Security Architect to evaluate cloud architectures for security gaps. This role involves reviewing IAM configurations and network designs while identifying risks and misconfigurations in AWS, Azure, and GCP environments. Candidates should have extensive experience in cloud security architecture and document complex systems effectively. The position offers competitive compensation at $40 - $80 an hour, providing an opportunity to influence robust security practices.
#J-18808-Ljbffr
$40-80 hourly 5d ago
Manual Ethical Hacker
Bank of America 4.7
Security engineer job in Boston, MA
Denver, Colorado;Seattle, Washington; Jersey City, New Jersey; Boston, Massachusetts; Washington, District of Columbia; Charlotte, North Carolina; Jacksonville, Florida; Chicago, Illinois **To proceed with your application, you must be at least 18 years of age.**
Acknowledge
Refer a friend
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge (******************************************************************************************
**:**
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
**Job Description:**
Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the vulnerability of the bank's applications to malicious hacking activity.
This intermediate technical role is responsible for performing application security assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include performing research, understanding the bank's security policies, working with the appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business.
Key Responsibilities in order of importance:
+ Perform assigned analysis of internal and external threats on information systems and predict future threat behavior
+ Incorporate threat actors' tactics, techniques, and procedures into offensive security testing
+ Perform assessments of the security, effectiveness, and practicality of multiple technology systems
+ Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
+ Prepare and present detailed technical information for various media including documents, reports, and notifications
+ Provide clear and practical advice regarding managed risks
+ Learn and develop advanced technical and leadership skills, Mentor Junior assessors in technical tradecraft and soft skills
Required Skills:
+ Minimum of 4 years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
+ Detailed technical knowledge in at least 3 of the following areas: securityengineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks; single sign-on technologies; exploit automation platforms; RESTful web services
+ SQL injection/XSS attack without the use of tools
+ Experience performing manual code reviews for security relevant issues
+ Experience working with SAST tools to identify vulnerabilities
+ Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
+ Experience performing manual web application assessments i.e., must be able to simulate a
+ Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
+ Experience with vulnerability assessment tools and penetration testing techniques
+ Solid programming/debugging skills
+ Experience of using a variety of tools, included, but not limited to, IBM AppScan, Burp and SQL Map
+ Threat Analysis
+ Innovative Thinking
+ Technology Systems Assessment
+ Technical Documentation
+ Advisory
Desired:
+ CISSP, CEH, OSCP, OSWE, GPEN, PenTest+ or similar
+ Strong programming/scripting skills
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
**Shift:**
1st shift (United States of America)
**Hours Per Week:**
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your **"Know your Rights (************************************************************************************** "** poster.
**View the LA County Fair Chance Ordinance (************************************************************************************************** .**
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy ("Policy") establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank's required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
$90k-129k yearly est. 60d+ ago
Systems Security Engineer
General Dynamics Mission Systems 4.9
Security engineer job in Taunton, MA
Basic Qualifications
RRequires a Bachelor's degree in Systems Engineering, or a related Science, Engineering, Technology or Mathematics field. Also requires 5+ years of job-related experience, or a Master's degree plus 3 years of job-related experience. Agile experience preferred.
CLEARANCE REQUIREMENTS:
Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibilityrequirements for access to classified information. Due to the nature of work performed within our facilities, U.S.citizenship is required.
Responsibilities for this Position
We are seeking a Systems SecurityEngineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
#CJ3
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $124,397.00 - USD $138,003.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
How much does a security engineer earn in North Attleborough, MA?
The average security engineer in North Attleborough, MA earns between $72,000 and $132,000 annually. This compares to the national average security engineer range of $77,000 to $141,000.
Average security engineer salary in North Attleborough, MA