Senior Security Engineer
Security engineer job in Boston, MA
Senior Security Engineer (US)
New York & Boston candidates: Office-based
Other listed states: Remote employees considered
Contract: Full-time, Hybrid / Flexible | 35-hour week
Salary: $175,000 base + 15% bonus
Overview
We are seeking a hands-on, senior security engineer to proactively strengthen our security posture across cloud-native and hybrid environments. This highly technical, strategic role will lead security platform integration, governance, threat detection, and mentoring, while influencing security-first practices across the organisation.
Key Responsibilities
Security Architecture & Engineering
Lead integration and optimisation of Zscaler, Wiz (EDR/CSPM/CNAPP), and endpoint protection (EDR/XDR) to maximise prevention, detection, and response.
Develop detection rules and manage analytics in Microsoft Sentinel and Wiz.
Conduct proactive threat hunting, posture management, and remediation validation.
Administer Zscaler Internet Access (ZIA), including policy tuning, SSL inspection, forwarding profiles, and authentication flows.
Troubleshoot traffic flows and collaborate with DevOps, IT, and R&D to integrate security into CI/CD pipelines and infrastructure-as-code.
Compliance, Audit & Governance
Ensure compliance with NIST SP 800-53, NIST SP 800-171, SOC 2, ISO/IEC 27001:2022, and client-specific requirements.
Lead audits, penetration testing, and maintain continuous audit readiness.
Security Operations & Incident Response
Develop, tune, and manage detection rules and playbooks across Wiz, Zscaler, and other platforms aligned with MITRE ATT&CK.
Hunt threats, triage alerts, and lead incident investigations.
Manage advanced email security with Microsoft Defender for Office 365.
Drive automation and orchestration initiatives to improve operational efficiency.
Stakeholder Engagement & Leadership
Act as a technical advisor on Zero Trust, cloud security, and operations.
Mentor junior staff and foster a security-first culture.
Communicate complex security concepts clearly to technical and non-technical stakeholders, including senior leadership.
Mandatory Platform Expertise
GitGuardian
CyberHaven
Wiz Advanced & Defend
Zscaler
Email Security (various platforms)
Education & Preferred Certifications
Master's degree in Information Security, Computer Science, or related field.
GIAC certifications: GCIA, GCED, GCIH, GDAT, GDSA, GMON
Microsoft Cloud Security certifications: AZ-500, AZ-305, SC-300
Information Security Analyst and Engineer
Security engineer job in Boston, MA
ABOUT OUR CLIENT
Our Client is a leader in energy management and power trading, leveraging cutting-edge platforms to deliver secure and resilient operations. With a strong focus on protecting systems, data, and intellectual property, they are committed to building a world-class information security program that supports business growth while staying ahead of emerging cyber threats.
ABOUT THE ROLE
The Information Security Analyst and Engineer will play a key role in safeguarding mission-critical systems, ensuring compliance, and advancing the organization's security maturity. This hybrid role blends hands-on security engineering with proactive monitoring, incident response, and program improvement. The position will collaborate with consultants, managed service providers (MSPs), and internal stakeholders to realize a highly effective security strategy. Reporting directly to the Director of Information Security, the role also provides occasional support to the Infrastructure team with basic system administration and help desk duties.
RESPONSIBILITIES
Develop and implement processes and technologies to enhance the security program and protect business platforms
Monitor security systems and analyze alerts, logs, and reports
Analyze vulnerability reports and track remediation across teams and systems
Provide metrics to evaluate security program effectiveness
Support security training and awareness programs, including phishing campaigns and in-person sessions
Research emerging IT security trends, attack techniques, and defensive measures
Assist in designing secure architectures across applications and infrastructure
Support internal and external risk assessments, vendor reviews, and security audits
Analyze penetration test results and drive remediation
Contribute to security roadmaps and maturity assessments
Safeguard IT assets and intellectual property by recommending best practices and solutions
Participate in incident response planning, investigations, and compliance reviews
Enhance data loss prevention technologies and processes
Respond rapidly to incidents, conduct root cause analysis, and recommend mitigations
Support business continuity and disaster recovery planning and testing
Validate MSP-delivered security solutions to ensure alignment with standards
Use automation to improve efficiency and effectiveness of security processes
Maintain and improve information security policies and ensure compliance
QUALIFICATIONS
Bachelor's degree in Computer Science, Information Security, or a related technical field
3-5 years of IT security experience, with hands-on implementation and analysis
Proficiency with EDR or SIEM solutions for configuration and investigations
Competency with firewalls, email gateways, internet filters, and VPNs
Strong background in network security, protocols, and best practices
Understanding of operating system, network, and application security concepts
Familiarity with the NIST Cybersecurity Framework
Working knowledge of network and data center operations
Experience with hybrid, public cloud (Azure preferred), and SaaS environments
Strong analytical, troubleshooting, and problem-solving skills
Excellent communication skills and attention to detail
Adaptability and eagerness to learn new technologies in a collaborative environment
PREFERRED QUALIFICATIONS
Experience in the energy or financial services industries
Familiarity with regulatory compliance frameworks such as NERC CIP or SOX
Relevant certifications such as CISSP, CompTIA, or GIAC
Experience in Agile and DevSecOps environments
Scripting knowledge in PowerShell and/or Python
System Cybersecurity Engineer II
Security engineer job in Bedford, MA
Veteran-Owned Firm Seeking a System Cybersecurity Engineer II for an Onsite Assignment at Hanscom Air Force Base (AFB)
My name is Stephen Hrutka. I lead a Veteran-Owned management consulting firm in Washington, DC. We specialize in Technical and Cleared Recruiting for the Department of Defense (DoD), the Intelligence Community (IC), and other advanced defense agencies.
At HRUCKUS, we support fellow Veteran-Owned businesses by helping them recruit for positions across organizations such as the VA, SBA, HHS, DARPA, and other leading-edge R&D-focused defense agencies.
We seek to fill a System Cybersecurity Engineer II role at Hanscom Air Force Base (AFB) in Bedford, MA.
The ideal candidate must have an active Secret Security Clearance, a DoD 8570.01-M MGT512-compliant certification, and experience with LogRhythm. Required qualifications include either a BA/BS with 10 years of cybersecurity experience (5 in DoD), an MA/MS with 5 years (3 in DoD), or 15 years of related experience with proper certifications, including 5 years in DoD.
If you're interested, I'll gladly provide more details about the role and discuss your qualifications further.
Thanks,
Stephen M Hrutka
Principal Consultant
HRUCKUS LLC
Executive Summary: HRUCKUS is seeking a System Cybersecurity Engineer II with Secret Clearance for a role at Hanscom Air Force Base (AFB) in Bedford, MA.
Position Overview: The System Cybersecurity Engineer II will be able to perform work that involves ensuring the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information systems security programs, policies, procedures, and tools.
Position Responsibilities:
Supporting the system/application authorization and accreditation (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing DoD and Air Force policies (i.e., Risk Management Framework (RMF).
Recommending policies and procedures to ensure the reliability of and accessibility to information systems and to prevent and defend against unauthorized access to systems, networks, and data.
Conducting risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs.
Promoting awareness of security issues among management and ensuring sound security principles are reflected in organizations' visions and goals.
Conducting systems security evaluations, audits, and reviews.
Recommending systems security contingency plans and disaster recovery procedures.
Recommending and implementing programs to ensure that systems, networks, and data users are aware of, understand, and adhere to systems security policies and procedures.
Participating in network and systems design to ensure implementation of appropriate systems security policies.
Facilitating the gathering, analysis, and preservation of evidence used in the prosecution of computer crimes.
Assessing security events to determine impact and implementing corrective actions.
Ensuring the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services.
Perform the Information System Security Engineer (ISSE) duties in an Information Assurance Workforce System Architecture and Engineering (IASAE) position as outlined in AFI 33-200, AFI 33-210 and AFMAN 33-285 for assigned systems.
Perform the Information System Security Manager (ISSM) duties as outlined in DoDI 8510.01 for assigned systems/applications.
Perform the Information System Security Officer (ISSO) duties as outlined in DoDI 8510.01 for assigned systems/applications.
Other duties as assigned.
Required Qualifications:
Clearance: Active Secret Security Clearance
BA/BS degree with a minimum of 10 years of cybersecurity experience, including 5 years supporting the Department of Defense (DoD); or an MA/MS degree with at least 5 years of experience, including 3 years in a DoD environment; or 15 years of directly related experience with the appropriate certifications, of which a minimum of 5 years must be within the DoD.
DoD 8570.01 MMGT512 compliant certification.
Experience with LogRhythm.
Lab/SCIT management experience preferred.
Experience with the Risk Management Framework (RMF).
Details:
Job Title: System Cybersecurity Engineer II
Location: Hanscom Air Force Base, MA
Clearance Requirement: Active Secret Clearance
Assignment Type: Full-time, Onsite
Salary Range: $130,000 - $140,000 per year
AI & Systems Engineer
Security engineer job in Boston, MA
Job Title: Artificial Intelligence Engineer Location: Boston/Hybrid Type: Full-time
The Role We're looking for a hands-on AI Systems Engineer to own the deployment, integration, and support of AI-powered tools (LLMs, Copilot, Claude, etc.) while keeping enterprise infrastructure running smoothly in a professional services environment.
What You'll Do
Build, deploy, and maintain AI applications that supercharge legal and knowledge workflows
Manage and optimize cloud (Azure/M365) and on-prem environments (Windows/Linux, VMware/Nutanix, AD, SQL)
Write production-grade Python/PowerShell, automate everything, consume REST APIs and SDKs
Craft high-impact prompts and fine-tune LLM usage
Partner with architecture and ops leadership on strategy, resilience, and continual improvement
Research emerging tech and drive efficiency gains
Rotate in 24×7 on-call (escalation/triage)
You Bring
7+ years supporting mission-critical IT in professional services or similar
Real experience with modern LLMs and AI tools
Strong Python or PowerShell + familiarity with ML libraries
Deep experience with Azure, M365, Active Directory, virtualization, networking, backups
Proven ability to solve complex problems independently and communicate clearly
Bachelor's in CS or related field
Network Engineer
Security engineer job in Waltham, MA
Length: 6 months + (temp to perm potential)
24x7 support team with on-call rotation
Skills
The infrastructure services engineer will provide reliable and flexible support to all components of client's infrastructure, including systems, networking, data center operations, cloud infrastructure, telecom, and others. This role will be dedicated to maintenance and management of these systems, as well as responding to all alerts to ensure maximum reliability.
Skills
3+ years' experience with a variety of infrastructure tools (VMWare, Cisco, Windows Server OS, etc.)
Experience with public cloud providers (AWS, Azure) and associated infrastructure management a plus
Knowledge of networking protocols and technologies (DNS, DHCP, SNMP, TCP/IP)
Solid knowledge of and previous experience using scripting technologies (PowerShell or Python)
Thorough understanding of managing servers in large corporate settings, covering security protocols, compliance with policies, and handling exceptions or changes
Excellent communication and documentation skills
Ability to work well as part of a large team
Proven ability to troubleshoot and resolve production issues while making sensible decisions in times of stress
Systems Engineer
Security engineer job in Bedford, MA
Our client is seeking a highly skilled Systems Engineer to provide advanced technical and systems engineering expertise across complex defense programs. This role involves applying engineering principles and innovative problem-solving to develop, evaluate, and enhance systems and technologies that support mission objectives. The ideal candidate will have a strong foundation in systems engineering, digital engineering, and Model-Based Systems Engineering (MBSE), with the ability to influence strategy and guide program decisions through analytical insight and technical leadership.
Essential Duties and Responsibilities (but not limited to):
Apply and adapt engineering principles, standards, and methods to address unique and complex technical challenges.
Research, design, and develop solutions that extend existing engineering concepts and technologies.
Provide expert technical consultation and guidance to senior management and program stakeholders.
Integrate digital engineering and MBSE practices throughout all phases of the system lifecycle.
Evaluate new technologies, engineering methodologies, and emerging industry trends for potential application.
Conduct systems-level analysis, trade studies, and performance evaluations to support mission and design objectives.
Lead or contribute to the development of new engineering standards, methods, or models.
Assess risks, recommend mitigations, and support system and program risk management activities.
Analyze system performance and ensure alignment with cost, schedule, and security requirements.
Incorporate resiliency and system security principles into engineering designs and architectures.
Conduct feasibility assessments, concept development, and decision analyses for proposed solutions.
Perform validation and verification of system designs, develop testing criteria, and evaluate results.
Provide systems integration oversight to ensure interoperability among subsystems and external interfaces.
Prepare technical documentation, reports, and presentations summarizing findings, recommendations, and performance metrics.
Support communication system integration and open architecture frameworks (e.g., Open Mission Systems) for NC3 modernization efforts.
Qualifications:
Bachelor's degree in Engineering or a related technical discipline (advanced degree preferred).
Minimum of 10 years of experience in systems engineering or a related engineering field.
Proven expertise applying engineering theories and principles to solve complex technical and operational problems.
Experience supporting system design, development, testing, and sustainment activities.
Strong understanding of digital engineering and MBSE concepts and tools.
Ability to assess and evaluate the impact of emerging technologies, methodologies, and strategies.
Skilled in developing technical recommendations, performing trade analyses, and influencing engineering decisions.
Excellent communication, analytical, and technical writing skills.
Adaptable and proactive, with the ability to learn and lead in a dynamic environment.
Must be a United States Citizen with an active Top Secret clearance and SCI eligibility.
POST-OFFER BACKGROUND CHECK IS REQUIRED. Digital Prospectors is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other characteristic protected by law. Digital Prospectors affirms the right of all individuals to equal opportunity and prohibits any form of discrimination or harassment.
Come see why DPC has achieved:
4.9/5 Star Glassdoor rating and the only staffing company (< 1000 employees) to be voted in the national Top 10 ‘Employee's Choice - Best Places to Work' by Glassdoor.
Voted ‘Best Staffing Firm to Temp/Contract For' seven times by Staffing Industry Analysts as well as a ‘Best Company to Work For' by Forbes, Fortune and Inc. magazine.
As you are applying, please join us in fostering diversity, equity, and inclusion by completing the Invitation to Self-Identify form today!
*******************
Job #18001
Resident Network Engineer
Security engineer job in Worcester, MA
Job Description/Purpose:
This is an Onsite role and the Resident Engineer's work location would be 474 Main St, Worcester, MA 01608.
Reporting to the Manager of Advanced Services, this is a highly technical role, providing post-sales support of Junipers Network Products. The Resident Engineer will reside at customer location and is expected to have expertise on Juniper products deployed or to be deployed within the customer's service provider network and provide technical and operational support on network issues, on-going certification and testing efforts.
Typical Activities:
Day to day support and troubleshooting for network issues
Applying industry best practices to the design, planning, and implementation of the network and the tools driving it
Applying extensive industry experience to optimize network performance and proactively analyze potential enhancements
Understand concepts of modeling design optimization
Key Responsibilities:
This may require long work hours or occasional on call weekend support. Technical support to the customer may require the Resident Engineer to:
Understand the customer's organizational structure and become familiar with the customer's network implementation and support processes and procedures to help in designing a network that is available and sustainable.
To hold network information gathering workshops with the Customer to understand the Customer's existing network design and technical requirements of new network designs.
Carry out testing of new tools, features, and functionality as required by the customer in a laboratory environment and to help develop plans to implement and verify that they are operating correctly in the live network
Test patches and fixes to operating software and to ensure that they are implemented and functioning correctly in the pre-production test network and then live network as implementation plans dictate.
Hold technology workshops with the customer to discuss equipment and network problems, and to provide case status updates, including the reasons for any problems encountered and the workarounds and/or solutions that are being tried
Support design and planning of Juniper MX, QFX, EX series and associated solutions within customer's commercial network
Support ongoing efforts in defining best practice policies for Juniper product applications used by customer
To peer with other employees performing similar Resident Engineering roles where lessons learned may help minimize risk associated with major network upgrades or changes in the network.
The RE will be expected to develop secondary skills in other products in the Juniper product portfolio.
Skills and Experience:
Preferred candidates for this position should have a Bachelor's Degree in Engineering or Computer Science with JNCIE certification. Candidates for this role MUST have a minimum 5 years experience providing implementation and technical support of networking products in LAN, WAN, or Internet services environments with either a technology vendor or a service provider environment.
Candidates should be able to demonstrate the following competencies:
Strong interpersonal skills.
Demonstrated ability to break-down work activity to achieve project goals
Demonstrated ability to communicate project status and identify risk
The ability to work independently and to function in a team environment.
Strong customer interface and presentation skills
Demonstrated ability to manage multiple projects and work calmly under pressure.
Programming and scripting experience preferred (Python, Ruby, shell, awk, slax, etc…)
Familiar with operation of management tools and network analyzers.
Trend analysis to help deliver more efficient solutions to customer network
An understanding of the protocols surrounding IP service provider networks. These skills include but are not limited to:
IP/Routing experience (OSPF, ISIS, BGP, MPLS-TE, RSVP, LDP, IPv6, Routing Policy)
Understanding of Multicast strongly preferred
Routing protocol operation, migration, and scaling mechanisms
Routing policies at BGP peering points
VPNs and the associated tunneling technologies (MPLS,EVPN, L3VPN, VPLS)
Ethernet switching and 802.1Q, QOS
Software Define Networking (SDN)
Focal Technologies:
The ideal candidate for this role should be able to demonstrate the following competencies:
Service Provider architecture experience
JUNOS CLI experience across MX, QFX, EX series
Must understand BGP and route reflector topologies
Must be able to communicate effectively and technically with internal JTAC, Escalation and Engineering teams.
Must be able to communicate effectively with the customer.
Scripting skills (Slax, Python, Ansible)
Test equipment (such as Spirent, Agilent N2X, and Ixia) a plus
Network management tools such as SNMP, Syslog, etc.
JNCIE- SP Preferred.
Desired Experience 7-10 yrs
ATM Network Engineer
Security engineer job in Boston, MA
ATM (Application Traffic Management) Network Engineer
Merrimack, NH / Westlake, TX / Boston, MA / Durham, NC
W2 Only
**In-person interview required**
We are currently sourcing for an ATM Network Engineer to work in our client's Enterprise Infrastructure Group in Merrimack NH, Westlake TX, Boston MA or Durham NC!
The ATM (Application Traffic Management) Network Engineer will be responsible for the overall F5 & AVI Load Balancing design and providing secure connectivity solutions to the client enterprise allowing Business teams and customers to be more competitive, more productive, and more profitable in a global business environment. These responsibilities include designing new enterprise solutions, enabling new customer connectivity, securing the environment through tactical change management, as well as working in a cross-organizational fashion to consult and enable these services. This position will require a disciplined approach towards ITSM methodologies ensuring the delivery of information technology services to meet the needs of the business community.
Manage, support, and design F5 and load balancing solutions for critical applications running on-prem, at multiple CSPs, and hybrid environments.
Consult with business partners on best practices and options with the various technology platforms.
Troubleshoot complex issues related to the Application Traffic Management environment (F5 and AVI)
Shift -oriented operations support, in collaboration with network operations and network engineering teams.
Work closely with business partners and other Global Network Services team to ensure 24x7 availability.
Member of 3rd level engineering escalation on-call rotation.
Escalate issues as needed.
A minimum of 4-6 years' engineering experience installing, configuring, and supporting load balancing technologies, preferably F5, HA Proxy, and/or VMWare/AVI.
Deep knowledge of Traffic Management platforms
Automation experience, E.g.. Ansible, Python (a plus, not required)
Extensive knowledge of TCP/IP, including application knowledge.
Network Engineering and Troubleshooting skills
Application Traffic Analysis
Routed/Routing Protocols: BGP, OSPF, MPLS, VRF, VPNs - a plus
Enterprise Security Policy knowledge and best practices
Agile methodologies and framework
Network certifications a plus but not required.
Works well independently and as part of a team; ability to lead a project.
Enjoys working directly with customers and solving their technical problems.
Thanks & Regards...
Raj Mohan
Technical Recruiter
VMC Soft Technologies inc.
EMail: ************************
Ph No: : ************ Ext: 241
System Engineer
Security engineer job in Boston, MA
Systems Engineer
Contract-to-Hire
Boston-based
1x per week onsite
We're looking for a hands-on Systems Engineer with broad experience across Windows Server, Active Directory, virtualization, and endpoint management. You will be responsible for maintaining, supporting, and improving a large and active IT environment.
Role
Administer and maintain Windows servers, Active Directory, and group policies
Support virtualization platforms such as VMware or Hyper-V
Manage endpoint systems including SCCM, Intune, and patching cycles
Handle backup, monitoring, and basic networking tasks
Build and maintain automation scripts for routine tasks and deployments
Troubleshoot system issues and implement long-term solutions
Participate in projects to modernize and optimize the IT estate
Responsibilities
Strong hands-on experience with Windows Server and Active Directory
Solid knowledge of endpoint management (SCCM, Intune, or similar)
Experience with virtualization platforms (VMware or Hyper-V)
Familiarity with patch management, backup, and monitoring tools
Comfortable with scripting (PowerShell, Python, or similar)
Able to work independently and take ownership of issues
Exposure to cloud environments (Azure, AWS) is a plus
If you're a proactive engineer who enjoys a varied role across servers, endpoints, and virtualization, this is a great opportunity to make an impact. Apply today.
Network Engineer
Security engineer job in Boston, MA
Qualifications/Skills:
Minimum CCNA/JNCIA certification; CCNP (Routing and Switching) preferred.
Familiarity with PoP infrastructure concepts including MMR, cross connect, peering, cage, patch panel, and ODF.
Proficient in fiber-optic technology, cable and connector types, patch panels, and optical transport technologies.
Experience in ordering cross connects and local patches from vendors like Equinix, Interxion, Telehouse, etc. across the region.
Hands-on experience in Edge capacity provisioning and decommissioning.
Skilled in network optimization, including re-stripes, migrations, and capacity upgrades.
Strong understanding and practical experience with networking protocols such as BGP, LACP, IS-IS, and MPLS.
Excellent attention to detail, time management, and organizational skills.
Proven ability to maintain comprehensive documentation.
Expert troubleshooting skills with the capacity to analyze complex situations under pressure.
Effective communicator with the ability to collaborate with external peers, vendors, and internal teams.
Programming and scripting capabilities are highly desirable.
Ability to thrive in a fast-paced, dynamic global team environment with minimal supervision.
Proactive, self-motivated, with a can-do attitude.
Responsibilities:
Deploy, configure, and maintain large-scale production and corporate network and server infrastructure across data centers, Points of Presence (POPs), edge, backbone, and content delivery network (CDN) infrastructure.
Provide onsite network support and expertise within local data center campuses and offer remote support for POP sites, collaborating with vendor support teams.
Schedule and execute network maintenance, repairs, or upgrades, with minimum impact on production networks.
Turn up new circuits and collaborate with vendors to troubleshoot out-of-service or faulty circuits.
Maintain accurate documentation and database updates to reflect changes in the network.
VIE - Growth Hacker (H/F)
Security engineer job in Boston, MA
Job Description
Withings revolutionized connected health by launching the world's first Wi-Fi scale in 2009. Our award-winning ecosystem includes beautifully designed, easy to use connected devices for monitoring blood pressure, weight, activity, sleep, temperature, and more.
Now our devices are used for preventive health and weight-loss programs, telehealth and remote patient monitoring, and clinical studies. They are the key enabling technologies which support our partners' strategies by accurately and reliably providing the data & metrics they need in order for their programs to be successful.
Under the joint supervision of the Head of E-commerce (US) and in close collaboration with the Head of Revenue Performance (France), the VIE Growth Hacker's primary mission will be to define, execute, and take full ownership of the commercial strategy for the U-Scan Calci cartridge.
The core purpose of this role is to decipher the target consumer niches (particularly individuals concerned by kidney stones), extract actionable insights, and implement all necessary tactics to boost sales and product adoption in the United States. He/she will act as a true entrepreneur within the team, with a clear mandate for identifying growth levers to scale-up sales of U-Scan Calci. He/she will then pave the way for the same business development approach for the other U-scan cartridges.
The main missions will include:
I. Niche Market & Business Modeling:
Strategy Definition: Establish the detailed acquisition strategy for U-Scan Calci on the US market.
Target Expertise: Develop a deep understanding of the product (technology and health implications) and the expectations, barriers, and purchasing journey of the target audience (patients, urologists, etc.).
Prioritization: Identify and prioritize high-potential acquisition channels and growth experiments (SEO, Content, Paid Social, Niche Partnerships, Cold mailing, Trade shows…).
II. Growth Hacking & Execution:
Launch & Execution: Lead end-to-end growth experiments (A/B testing on landing pages, automated emailing campaigns, conversion funnel optimization).
On-the-Ground Acquisition: Conduct direct prospecting or partnership actions to "get their hands dirty" and discover initial growth levers.
Content/Messaging: Adapt the copywriting and marketing message to specifically resonate with the target's health challenges (kidney stones).
III. Performance Tracking & Insights:
Performance Monitoring: Define and track key performance indicators (KPIs) for the sales funnel growth (Surveys, CAC, conversion rate specific to the Calci niches).
Analysis & Recommendations: Conduct post-mortem analyses on commercial operations and experiments to generate clear recommendations for product development and future strategies.
Competitive Intelligence: Maintain active competitive intelligence on connected health and urological products, including webscraping customer reviews to refine target profiling.
Requirements
Master's degree (business, engineering, data, marketing, entrepreneurship).
Strong analytical skills and interest in health/tech topics.
Ability to quickly understand scientific or technical concepts.
Knowledge of digital marketing and/or growth (SEO, content, A/B testing, automation).
Excellent communication skills, especially in English.
Comfortable with digital tools (Sheets/Excel, CRM, automation tools).
Entrepreneurial mindset, autonomy, curiosity, and a hands-on approach.
Strong prioritization and performance-tracking abilities (KPIs, analysis).
Benefits
Becoming part of one of the pioneers and global leaders in connected health, multiple-time award winner at the Consumer Electronics Show.
Contributing to innovative and ambitious projects shaping the future of health, within an agile and fast-evolving environment.
Joining an international company, member of the FrenchTech 120, with teams based in Issy-les-Moulineaux, Boston, Hong Kong, and Shenzhen.
Actively participating in the continuous improvement of our products and services by beta-testing them before release - including during our many sports sessions with colleagues.
Collaborating with passionate teammates and celebrating our collective successes!
All applications are reviewed independently of ethnic origin, beliefs, religion, gender, sexual orientation, or health status. Withings is committed to offering and ensuring equal opportunities for all candidates. Only authorized personnel (HR and Management) will have access to information related to your application.
Cyber Security Solutions Engineer - GES
Security engineer job in Boston, MA
States: MA, NH, RI, ME, CT, VT, NJ, NY is home office based. Meet the Team You will provide guidance and assist Security Sellers and Account teams within the territory in a pre-sales technical role, showcasing Cisco security product solutions, setting up demonstrations, explaining features and benefits to customers, and designing and configuring products to address specific customer security needs. You will form relationships with our customer's key decision-makers, positioning Cisco security solutions aligned accurately to their requirements.
You will be a part of an outstanding technical pre-sales team in our Global Security Sales Organization (GSSO), responsible for driving the success of Cisco's Security Portfolio and focusing on protecting Customer Application Environments no matter where they live (on-prem / any cloud).
Our mission is simple: democratize security by making it easy and effective for everyone. We're transforming security from the ground up by solving the world's most pressing geopolitical challenge - safe, secure information access. We engineer our business to enable our customers to easily address their ever-evolving security challenges.
We believe that impactful work is rewarding work and that our team is at its best when everyone feels empowered to bring their whole self to work. We learn together by hiring for cultural contribution, not cultural fit, and recognize that diversity in background and thought are essential to building high-impact teams.
We invest in growth and learning opportunities and encourage our people to never stop learning. We foster collaboration and believe in being recognized (and rewarded!) for hard work. We champion a healthy work-life balance. We're kinder than necessary.
Together we build for the future by designing simple solutions for complex problems. And that's why we're the most loved and trusted name in security.
Your Impact
As an advisor to the customer, you'll be working with technology experts to craft architectures and configure products to meet customer-specific needs, are prepared to lead all technical aspects of pre-sales activities, and position security solutions effectively against competing offerings. You are an aggressive starter, self-starter with the ability to build executive relationships, develop and execute sales strategies and tactics that improve Cisco's opportunity with a customer environment, position and promote the partner and customer value proposition for Cisco security architecture, articulate Cisco's product and business strategies, and create the demand that makes deals happen! You will:
* Serve as the subject matter expert in Cisco security solutions
* Provide guidance and assist account teams within the territory in building solutions to address specific customer security needs
* Understand business requirements for a customer base and be able to translate them into technical requirements
* Understand and articulate Cisco's architecture and services within security technologies
* Create, present, and document technical solutions
* Perform in-depth and high-level technical presentations for customers partners and prospects
* Drive identified major account opportunities (i.e. technical consulting, upper-level management presentations, and Cisco technology solutions) while allowing local account teams to maintain long-term ownership
Who You Are
You are passionate about the customer experience and excited about new technology. You are a true teammate and love to learn. Being a self-starter, our SEs act as an industry domain authority, and strive to help Cisco make customers for life.
Minimum Qualifications
* Minimum of 4 years of pre-sales experience
* Hands on experience with one or more of these Cisco Security Products (or their competitive equivalent):
********************************************************************
* Experience with whiteboard discussions that transform customer requirements into security solutions
Preferred Qualifications
* History of successful quota achievement.
* Ability to demo / POV any of these Cisco Security products (the more the better): ********************************************************************
* Knowledge of public clouds AWS, Azure, GCP, and OCI.
* Experience with incident response a plus
* Experience with administering security for a company (e.g. purchased and deployed Cisco security products as a customer) is a plus.
* Solid presentation and interpersonal skills.
* Highly motivated self-starter who does not need day-to-day management
* Experience with APIs and scripting languages
Why Cisco?
At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
Message to applicants applying to work in the U.S. and/or Canada:
The starting salary range posted for this position is $217,200.00 to $274,100.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.
Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.
U.S. employees are offered benefits, subject to Cisco's plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.
U.S. employees are eligible for paid time away as described below, subject to Cisco's policies:
* 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
* 1 paid day off for employee's birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco
* Non-exempt employees receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees
* Exempt employees participate in Cisco's flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)
* 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next
* Additional paid time away may be requested to deal with critical or emergency issues for family members
* Optional 10 paid days per full calendar year to volunteer
For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco's policies.
Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:
* .75% of incentive target for each 1% of revenue attainment up to 50% of quota;
* 1.5% of incentive target for each 1% of attainment between 50% and 75%;
* 1% of incentive target for each 1% of attainment between 75% and 100%; and
* Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.
For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.
The applicable full salary ranges for this position, by specific state, are listed below:
New York City Metro Area:
$223,000.00 - $330,300.00
Non-Metro New York state & Washington state:
$217,200.00 - $315,300.00
* For quota-based sales roles on Cisco's sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.
Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.
Systems Security Engineer
Security engineer job in Dedham, MA
Basic Qualifications
CLEARANCE REQUIREMENTS: Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
We are seeking a Systems Security Engineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $107,529.00 - USD $114,000.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Auto-ApplySenior Manual Ethical Hacker
Security engineer job in Boston, MA
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
Job Description:
Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the security resilience of the bank's applications to malicious hacking activity.
This senior technical role is responsible performing and leading ethical hacking assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research, understanding the bank's security policies, working with appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business. These individuals are expected to perform application security-oriented dynamic and static assessments across a multitude of technologies including web UI, web APIs, mobile and cloud, including associated source code.
Key Responsibilities in order of importance:
* Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.
* Incorporate threat actors' tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.
* Developing Proof-of-concepts for exploitation.
* Perform assessments of the security, effectiveness, and practicality of multiple technology systems.
* Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
* Prepare and present detailed technical information for various media including documents, reports, and notifications.
* Provide clear and practical advice regarding managing risks.
* Learn and develop advanced technical and leadership skills, mentor Junior and Intermediate assessors in technical tradecraft and soft skills.
* Respond to security incidents and provide technical assistance to leadership across the Information Security organization.
Required Skills:
* Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
* Detailed technical knowledge in at least 5 of the following areas:
* security engineering
* application architecture
* authentication and security protocols
* application session management
* applied cryptography
* common communication protocols
* mobile frameworks
* single sign-on technologies
* exploit automation platforms
* Web APIs
* Cloud environments
* LLM security
* Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
* Experience performing manual web application assessments i.e., must be able to simulate a OWASP Top 10 vulnerabilities without the use of tools
* Experience performing manual code reviews for security relevant issues
* Experience working with DAST and SAST tools to identify vulnerabilities
* Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
* Experience with vulnerability assessment tools and penetration testing techniques.
* Solid programming/debugging skills, development frameworks, CVE and CWE research/reproduction
* Threat Analysis, threat modelling and SBOM analysis
* Innovative thinking, threat actor simulation
* Technology Systems Assessment
* Technical Documentation
* Advisory
Desired:
* CEH, OSCP/OSCE/OSWE/GXPN/GPEN/GWAPT/GMOB/All Practitioner Certs [Port Swigger BSP Academy]/Cloud Cert(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy]
* Strong programming/scripting skills
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Senior Information Security Engineer
Security engineer job in Boston, MA
At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives. WHOOP is seeking a Senior Information Security Engineer to serve as a technical leader in our Security team reporting to our Information Security Manager. In this role, you will drive the deployment and continuous enhancement of controls that protect millions of users' biometric and health data, build scalable defenses across our infrastructure and applications, and lead incident response efforts with visibility across the business. This is an opportunity to have direct impact at scale, working alongside engineers, product teams, and executives to drive forward-looking security strategies.
RESPONSIBILITIES:
* Implement and enhance security controls by leading the deployment, integration, and tuning of solutions such as CNAPP, SIEM, CASB, EDR, DLP, and MDM to maximize effectiveness.
* Support security design decisions by providing subject matter expertise on cloud and SaaS security best practices while influencing architecture led by the Security Architect role.
* Lead incident response and investigations by guiding containment, remediation, root cause analysis, and post-incident improvements.
* Strengthen application security by overseeing secure development practices and managing SAST, SCA, and DAST tooling.
* Advance identity and access management by supporting IAM policy enforcement, SSO, MFA, SCIM, RBAC, and user lifecycle governance.
* Secure AI systems and integrations by assessing and protecting embedded APIs and organizational AI tool usage to ensure resilience, privacy, and compliance.
* Collaborate cross-functionally by working with Engineering, IT, and GRC teams to embed security into systems and workflows.
* Mentor and influence by providing technical guidance, reviewing work, and promoting security-first thinking across the organization.
* Stay ahead of threats and regulations by tracking emerging risks, technologies, and compliance requirements to inform forward-looking strategies.
* Participate in and help improve the on-call rotation by providing guidance, escalation support, and driving improvements in response processes.
QUALIFICATIONS:
* Bachelor's degree in Computer Science, Information Security, or a related technical field and/or advanced certifications (CISSP, CISM, AWS Security Specialty, SANS, etc.).
* 8+ years of hands-on experience in Information Security, IT Security, or a related role, including at least 2 years in a senior or lead capacity.
* Proven track record implementing and managing advanced security technologies (e.g., CASB, CNAPP, CSPM, SIEM, SOAR, DLP, SWG).
* Experience securing AI/ML systems or APIs, including governance of third-party AI integrations and organizational use of AI tools.
* Strong understanding of modern cloud security architecture (AWS, Azure, GCP) and experience performing threat modeling and risk assessments on cloud-based systems.
* Hands-on experience with application security tooling (SAST, SCA, DAST) and embedding secure development practices.
* Demonstrated leadership in security incident response, investigations, and root cause analysis.
* Effective communicator with the ability to influence stakeholders and explain security concepts to technical and non-technical audiences.
* Strong project management skills and the ability to drive initiatives to completion in a fast-paced environment.
* Experience mentoring engineers and setting operational standards.
* Familiarity with compliance and risk frameworks relevant to health and AI (SOC 2, ISO 27001, PCI, GDPR, FTC guidance, HIPAA-adjacent state laws) is a plus.
Interested in the role, but don't meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.
At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.
The U.S. base salary range for this full-time position is $150,000 - $190,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.
In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.
These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.
Learn more about WHOOP.
SECURITY RESEARCH
Security engineer job in Brookline, MA
Security Researcher Do You Enjoy… * And strive to be a practiced subject matter expert? * Researching, learning, and evaluating technologies? * Educating business leaders on their technology investments? * Work that is Impactful and rewarding? ...
The Security Researchers' primary responsibility is the evaluation of security technologies. The core of this process is the quantitative scoring of requirements, including both business and technical. Researcher will validate security products through a variety of means and confidently
Systems Security Analyst/Cyber Defense Analyst
Security engineer job in Newport, RI
DecisiveInstincts, LLC has an immediate opportunity for a Systems Security Analyst / Cyber Defense Analyst in Newport, RI. This position requires a Top Secret/SCI clearance.
Immediate Opportunity: Systems Security Analyst / Cyber Defense Analyst
Location: Newport, RI
Clearance Required: Top Secret/SCI
Key Responsibilities
Analyze, document, and develop integration, testing, operations, and maintenance for system security.
Utilize cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to monitor and mitigate threats.
Apply defensive measures to identify, analyze, and report security events.
Coordinate threat and mitigation strategies across the enterprise.
Required Experience
Network & Security Operations:
Install, configure, and maintain security devices on EDU, SIPRNET, DMZ, and commercial ISP networks.
Ensure compliance with DoD security and information assurance policies.
Support unclassified and classified information security services.
Security Tools & Technologies:
Operate ACAS, McAfee HBSS, Corelight, and Cortex for threat detection and management.
Implement SOAR orchestration and SIEM event correlation & analysis.
Manage cloud security systems for DLP, email security, and threat prevention.
Perform vulnerability scanning, penetration testing, and firewall administration.
Cybersecurity Expertise:
Analyze network alerts and identify causes of security incidents.
Conduct security reviews, gap analysis, and risk mitigation.
Apply knowledge of cyber threats, attack vectors, and mitigation strategies.
Understand TCP/IP, DHCP, DNS, and OSI Model.
Perform packet-level analysis and collect data from cyber defense resources.
Education & Certifications
Degree Requirement:
Bachelor's in Information Technology, Cybersecurity, Data Science, Information Systems, or Computer Science (ABET-accredited or CAE-designated institution).
Certifications may be considered in lieu of a degree.
************Direct Applicants Only - No Agencies or Third-Party Recruiters***********
Auto-ApplyVIE - Growth Hacker (H/F)
Security engineer job in Boston, MA
Withings revolutionized connected health by launching the world's first Wi-Fi scale in 2009. Our award-winning ecosystem includes beautifully designed, easy to use connected devices for monitoring blood pressure, weight, activity, sleep, temperature, and more.
Now our devices are used for preventive health and weight-loss programs, telehealth and remote patient monitoring, and clinical studies. They are the key enabling technologies which support our partners' strategies by accurately and reliably providing the data & metrics they need in order for their programs to be successful.
Under the joint supervision of the Head of E-commerce (US) and in close collaboration with the Head of Revenue Performance (France), the VIE Growth Hacker's primary mission will be to define, execute, and take full ownership of the commercial strategy for the U-Scan Calci cartridge.
The core purpose of this role is to decipher the target consumer niches (particularly individuals concerned by kidney stones), extract actionable insights, and implement all necessary tactics to boost sales and product adoption in the United States. He/she will act as a true entrepreneur within the team, with a clear mandate for identifying growth levers to scale-up sales of U-Scan Calci. He/she will then pave the way for the same business development approach for the other U-scan cartridges.
The main missions will include:
I. Niche Market & Business Modeling:
Strategy Definition: Establish the detailed acquisition strategy for U-Scan Calci on the US market.
Target Expertise: Develop a deep understanding of the product (technology and health implications) and the expectations, barriers, and purchasing journey of the target audience (patients, urologists, etc.).
Prioritization: Identify and prioritize high-potential acquisition channels and growth experiments (SEO, Content, Paid Social, Niche Partnerships, Cold mailing, Trade shows…).
II. Growth Hacking & Execution:
Launch & Execution: Lead end-to-end growth experiments (A/B testing on landing pages, automated emailing campaigns, conversion funnel optimization).
On-the-Ground Acquisition: Conduct direct prospecting or partnership actions to "get their hands dirty" and discover initial growth levers.
Content/Messaging: Adapt the copywriting and marketing message to specifically resonate with the target's health challenges (kidney stones).
III. Performance Tracking & Insights:
Performance Monitoring: Define and track key performance indicators (KPIs) for the sales funnel growth (Surveys, CAC, conversion rate specific to the Calci niches).
Analysis & Recommendations: Conduct post-mortem analyses on commercial operations and experiments to generate clear recommendations for product development and future strategies.
Competitive Intelligence: Maintain active competitive intelligence on connected health and urological products, including webscraping customer reviews to refine target profiling.
Requirements
Master's degree (business, engineering, data, marketing, entrepreneurship).
Strong analytical skills and interest in health/tech topics.
Ability to quickly understand scientific or technical concepts.
Knowledge of digital marketing and/or growth (SEO, content, A/B testing, automation).
Excellent communication skills, especially in English.
Comfortable with digital tools (Sheets/Excel, CRM, automation tools).
Entrepreneurial mindset, autonomy, curiosity, and a hands-on approach.
Strong prioritization and performance-tracking abilities (KPIs, analysis).
Benefits
Becoming part of one of the pioneers and global leaders in connected health, multiple-time award winner at the Consumer Electronics Show.
Contributing to innovative and ambitious projects shaping the future of health, within an agile and fast-evolving environment.
Joining an international company, member of the FrenchTech 120, with teams based in Issy-les-Moulineaux, Boston, Hong Kong, and Shenzhen.
Actively participating in the continuous improvement of our products and services by beta-testing them before release - including during our many sports sessions with colleagues.
Collaborating with passionate teammates and celebrating our collective successes!
All applications are reviewed independently of ethnic origin, beliefs, religion, gender, sexual orientation, or health status. Withings is committed to offering and ensuring equal opportunities for all candidates. Only authorized personnel (HR and Management) will have access to information related to your application.
Auto-ApplyManual Ethical Hacker
Security engineer job in Boston, MA
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
Job Description:
Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the vulnerability of the bank's applications to malicious hacking activity.
This intermediate technical role is responsible for performing application security assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include performing research, understanding the bank's security policies, working with the appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business.
Key Responsibilities in order of importance:
* Perform assigned analysis of internal and external threats on information systems and predict future threat behavior
* Incorporate threat actors' tactics, techniques, and procedures into offensive security testing
* Perform assessments of the security, effectiveness, and practicality of multiple technology systems
* Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
* Prepare and present detailed technical information for various media including documents, reports, and notifications
* Provide clear and practical advice regarding managed risks
* Learn and develop advanced technical and leadership skills, Mentor Junior assessors in technical tradecraft and soft skills
Required Skills:
* Minimum of 4 years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
* Detailed technical knowledge in at least 3 of the following areas: security engineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks; single sign-on technologies; exploit automation platforms; RESTful web services
* SQL injection/XSS attack without the use of tools
* Experience performing manual code reviews for security relevant issues
* Experience working with SAST tools to identify vulnerabilities
* Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
* Experience performing manual web application assessments i.e., must be able to simulate a
* Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
* Experience with vulnerability assessment tools and penetration testing techniques
* Solid programming/debugging skills
* Experience of using a variety of tools, included, but not limited to, IBM AppScan, Burp and SQL Map
* Threat Analysis
* Innovative Thinking
* Technology Systems Assessment
* Technical Documentation
* Advisory
Desired:
* CISSP, CEH, OSCP, OSWE, GPEN, PenTest+ or similar
* Strong programming/scripting skills
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Systems Security Engineer
Security engineer job in Taunton, MA
Basic Qualifications
RRequires a Bachelor's degree in Systems Engineering, or a related Science, Engineering, Technology or Mathematics field. Also requires 5+ years of job-related experience, or a Master's degree plus 3 years of job-related experience. Agile experience preferred.
CLEARANCE REQUIREMENTS:
Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibilityrequirements for access to classified information. Due to the nature of work performed within our facilities, U.S.citizenship is required.
Responsibilities for this Position
We are seeking a Systems Security Engineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
#CJ3
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $127,432.00 - USD $140,000.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Auto-Apply