Information Security Engineer

Randstad
Somerville, MA, United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$45,000.0 - $65,000.0
Working hours
Shift work
Job source

Tech stack

Systems Engineering Cloud Computing Cyber Security Identity and Access Management Role-Based Access Control Zero Trust Network Access Software Engineering Software Vulnerability Management Enterprise Software Applications Information Technology

Job description

We are seeking an Information Security Engineer III to join an enterprise Information Security Architecture team. This is a senior-level role focused on evaluating a broad range of technologies, business initiatives, operational processes, and strategic projects to identify security risks and provide practical, risk-based guidance., Evaluate technologies, business initiatives, operational processes, and proposed solutions to identify security risks.

Perform security assessments, architecture reviews, risk analyses, and technology evaluations.

Quickly assess unfamiliar technologies and understand their security implications.

Develop practical, risk-based recommendations and appropriate security controls.

Partner with technical teams, business stakeholders, vendors, project leaders, and security professionals.

Research emerging technologies, evolving threats, regulatory requirements, and industry practices.

Develop security assessments, recommendations, standards, reports, and other written deliverables.

Communicate technical risks, tradeoffs, and recommendations to engineers, project teams, business leaders, and senior leadership.

Present findings, facilitate discussions, answer questions, and help build stakeholder consensus.

Serve as a trusted cybersecurity advisor to business and technology teams.

Contribute to security standards, methodologies, assessment processes, and best practices.

Mentor junior and mid-level security professionals.

Lead or contribute to cross-functional technical initiatives., Occasional additional onsite presence may be required based on business needs.

Monday-Friday, either 8:00 AM-4:00 PM or 9:00 AM-5:00 PM, with flexibility.

Full-time, permanent position.

Why This Role?

This is an opportunity for a senior security professional who enjoys solving complex problems, evaluating unfamiliar technologies, and serving as a trusted advisor to both technical and business leadership.

The strongest candidates will not simply identify security risks - they will be able to quickly understand the environment, determine what matters, develop a practical recommendation, and explain it clearly to the people responsible for making the decision., * Evaluate technologies, business initiatives, operational processes, and proposed solutions to identify security risks.

  • Perform security assessments, architecture reviews, risk analyses, and technology evaluations.
  • Quickly assess unfamiliar technologies and understand their security implications.
  • Develop practical, risk-based recommendations and appropriate security controls.
  • Partner with technical teams, business stakeholders, vendors, project leaders, and security professionals.
  • Research emerging technologies, evolving threats, regulatory requirements, and industry practices.
  • Develop security assessments, recommendations, standards, reports, and other written deliverables.
  • Communicate technical risks, tradeoffs, and recommendations to engineers, project teams, business leaders, and senior leadership.
  • Present findings, facilitate discussions, answer questions, and help build stakeholder consensus.
  • Serve as a trusted cybersecurity advisor to business and technology teams.
  • Contribute to security standards, methodologies, assessment processes, and best practices.
  • Mentor junior and mid-level security professionals.
  • Lead or contribute to cross-functional technical initiatives

Requirements

The ideal candidate is someone who can quickly understand complex and unfamiliar technology environments, analyze security implications, and clearly communicate recommendations to senior leadership and business stakeholders.

Top 3 Qualifications

  1. Strong analytical ability across a broad technology landscape

Ability to evaluate a wide range of technologies, systems, business initiatives, and operational processes and identify meaningful cybersecurity risks.

  1. Exceptional communication skills

Ability to clearly communicate complex technical concepts, security risks, recommendations, and tradeoffs both verbally and in writing to senior leadership and business owners who may not have the same level of technical expertise.

  1. Ability to do both quickly and effectively

Strong judgment and the ability to rapidly understand unfamiliar technologies and business challenges, assess risk, and develop practical recommendations., Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field; equivalent experience may be considered.

5-7 years of experience in systems engineering, security engineering, security architecture, cybersecurity consulting, or a related field.

Strong understanding of cybersecurity principles, risk management, and security frameworks.

Experience performing security assessments, architecture reviews, risk analyses, technology evaluations, or similar analytical work.

Ability to identify complex security issues and develop practical recommendations.

Strong understanding of enterprise technology environments, including familiarity with:

Cloud platforms

Identity and access management, Knowledge of Zero Trust, least privilege, defense-in-depth, data protection, secure software development, threat modeling, and vulnerability management.

Strong written and verbal communication skills.

Strong analytical, critical-thinking, and problem-solving abilities.

Ability to work effectively in complex and ambiguous environments.

Experience mentoring junior professionals and/or leading cross-functional initiatives., Knowledge of Zero Trust, least privilege, defense-in-depth, data protection, secure software development, threat modeling, and vulnerability management.

Strong written and verbal communication skills.

Strong analytical, critical-thinking, and problem-solving abilities.

Ability to work effectively in complex and ambiguous environments.

Experience mentoring junior professionals and/or leading cross-functional initiatives.

skills:

Cloud,Information Security,Cybersecurity,security architecture,Security operations,enterprise technology,Identity and access management,Computer Science,Information Technology,least privilege,secure software development,vulnerability management,systems engineering,Zero Trust,analytical,communicate,Exceptional communication skills,Strong written and verbal communication,critical-thinking,work effectively,leadership,problem-solving abilities,solving complex problems,Architecture,architecture reviews,business initiatives,consulting,data protection,cybersecurity risks,cybersecurity principles,security frameworks,industry practices,Infrastructure,Mentor,mentoring,regulatory requirements,risks,risk,assess risk,risk analyses,risk management,security,security assessments,security controls,security engineering,technology evaluations,threat modeling

Benefits & conditions

Salary: $93,953.60-$136,739.20 annually, with flexibility toward the higher end for candidates with approximately 6-8 years of experience. Candidates with additional relevant experience may be considered at a higher level.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

4:08 min

Introduction to speakers and model-based systems engineering goals

Daniel Siegl +1 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all