> Markdown version of [/jobs/ext/2280458-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/2280458-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Schneider Llp - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $117,600.0 - $176,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Disaster Recovery, Domain Name System (DNS), Identity and Access Management, Secure Coding, Web Application Security, Web Applications, Datadog, Software Security, Infrastructure as Code (IaC), Software Coding, Legacy Systems - **Published:** August 28, 2026 - **Apply:** https://www.jofdav.com/jobs/59438982-senior-security-engineer ## About the Role + 7+ years of demonstrated experience in writing and deploying secure code, including proficiency in Infrastructure as Code (IaC). + Strong problem-solving skills with the ability to integrate security into legacy systems and ensure high-quality, reviewable pull requests. * Monitoring and Alerting Skills: + Experience in configuring and managing monitoring and alerting systems for web applications, with a knack for balancing proactive and reactive tasks. + Ability to consolidate information from various sources and manage security alerts efficiently, including responding to active threats. * Effective Trainer and Communicator: + Track record of delivering impactful training sessions to technical teams, with a clear ability to communicate complex security concepts to both technical and non-technical audiences. + Skill in adapting training approaches for different audiences and addressing any misunderstandings effectively. * Strategic Security Reviewer: + Experience in reviewing and critiquing architecture proposals with a focus on security. + Proven ability to challenge and improve security proposals while balancing technical authority with approachability. * Technical Proficiencies: + In-depth knowledge of web security principles (e.g., cookies, security headers, DNS) and AWS (e.g., networking, IAM roles, Infrastructure as Code). + Familiarity with CDK, Cognito, and Datadog is advantageous. * Relevant Experience: + Hands-on experience in security engineering and incident management, ideally within a fast-paced B2C environment. + Background in briefing executives and delivering security training sessions to technical teams is preferred. ## Description As a Senior Security Engineer at EnergySage, you will play a pivotal role in fortifying our application security through both hands-on technical work and strategic initiatives., + Implement and refine security measures for our infrastructure, including writing code and developing Infrastructure as Code (IaC) solutions. + Create and maintain security reference implementations and templates to streamline best practices across the team. * Monitoring and Incident Management: + Set up, configure, and manage security alerting systems to ensure proactive threat detection. + Regularly review and triage security findings, assess their urgency, and take appropriate action to address and escalate critical issues. * Training and Development: + Lead and deliver training sessions to elevate the security expertise of our team, covering topics from AppSec basics to advanced concepts. + Design and conduct exercises to prepare the team for potential security incidents and disaster recovery scenarios. * Collaborative Security Leadership: + Work closely with IT and Platform teams to manage permissions and configurations securely. + Engage with the SE security team and vendors on security audits, scans, and assessments, fostering strong relationships with key stakeholders. + Contribute to architecture and security review processes, offering valuable insights to enhance overall security posture., + Implement and refine security measures for our infrastructure, including writing code and developing Infrastructure as Code (IaC) solutions. + Create and maintain security reference implementations and templates to streamline best practices across the team. * Monitoring and Incident Management: + Set up, configure, and manage security alerting systems to ensure proactive threat detection. + Regularly review and triage security findings, assess their urgency, and take appropriate action to address and escalate critical issues. * Training and Development: + Lead and deliver training sessions to elevate the security expertise of our team, covering topics from AppSec basics to advanced concepts. + Design and conduct exercises to prepare the team for potential security incidents and disaster recovery scenarios. * Collaborative Security Leadership: + Work closely with IT and Platform teams to manage permissions and configurations securely. + Engage with the SE security team and vendors on security audits, scans, and assessments, fostering strong relationships with key stakeholders. + Contribute to architecture and security review processes, offering valuable insights to enhance overall security posture. General Business about 1 hour ago PEPI Senior Associate - Merger Integration & Carve-Outs Alvarez & Marsal Private Equity Performance Improvement Group, LLC Boston, Massachusetts General Business 30+ days ago PEPI Senior Associate - Merger Integration & Carve-Outs Alvarez & Marsal Private Equity Performance Improvement Group, LLC Boston, Massachusetts ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [How to TDD in legacy code](https://www.wearedevelopers.com/videos/309-how-to-tdd-in-legacy-code) - [Accelerating Authentication Architecture: Taking Passwordless to the Next Level](https://www.wearedevelopers.com/videos/733-accelerating-authentication-architecture-taking-passwordless-to-the-next-level) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)