> Markdown version of [/jobs/ext/2502395-security-engineer-boston-hq](https://www.wearedevelopers.com/jobs/ext/2502395-security-engineer-boston-hq). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer (Boston HQ) - **Company:** WinnCompanies LLC - **Location:** Boston, MA, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Security Information and Event Management, User Provisioning Software, Scripting, CIS Benchmarks - **Published:** August 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9d83b46066c4559c ## About the Role * 2-5 years of hands-on experience in security engineering, security operations, IT security, or a closely related role. * Practical experience with identity and access management concepts and tooling (e.g., directory services, SSO, MFA, user provisioning/deprovisioning). * Experience working with security incident detection and response tools, including working with SIEM, EDR, or MDR- services. * Understanding of third-party / vendor risk assessment principles. * Proven ability to collaborate effectively with internal IT teams and external service providers (MSSP, MDR). * Strong written and verbal communication skills, with the ability to clearly document findings and articulate risks to non-technical stakeholders. * Self-directed and capable of working independently, demonstrating a strong problem-solving mindset in a lean and rapidly growing security program Preferred * Experience supporting a large or distributed workforce, ideally across multiple physical sites. * Hands-on experience implementing controls for the protection of sensitive data (PII), * Familiarity with common security and privacy frameworks (e.g., NIST CSF, CIS Controls) and associated regulatory considerations. * Relevant certifications such as Security+, SSCP, GSEC, or progress toward CISSP. * Experience using scripting or automation tools (e.g., PowerShell, Python) to streamline IAM and security operational tasks ## Description Reporting to the Director of Information Security & Risk Management, you will be a core member of a lean security team. This is a high impact role with broad exposure: where you will work across core domains including identity and access management (IAM), third-party risk, and incident detection and response while working closely with the Director of Information Security to strengthen overall security architecture and program strategy. You will work closely with our internal IT team and our managed security service provider (MSSP) to deploy, configure, and tune security tools, improve monitoring and alerting, and support incident response activities., Identity & Access Management * Administer and manage identity and access management (IAM) processes and tools across a large, distributed workforce. * Manage the high-volume onboarding and offboarding process common in property management environments. * Implement and tune access controls, role-based access, multi-factor authentication, and least-privilege practices. * Support access reviews, partnering with IT and business owners to validate findings. Vendor & Third-Party Risk * Conduct vendor and third-party risk assessments using the firm's third-party assessment tool. * Evaluate vendor security postures, document findings, track remediation, and advise stakeholders on acceptable risk. * Help refine the third-party risk process and reporting as the program matures. Incident Detection & Response * Serve as a key point of contact for security incident detection and response, working alongside our managed detection and response (MDR) provider. * Triage, investigate, and coordinate response to alerts * 24/7 on call for incidents escalated by the MDR service. * Contribute to and help mature incident response playbooks, runbooks, and post-incident reviews. Program Development & Implementation * Work directly with the Director of Information Security & Risk Management to shape the strategy, roadmap, and priorities of the security program. * Work with internal IT and the IT MSSP to implement, configure, and operate security tools and controls. * Contribute to policy development, security awareness training, and compliance-supporting activities as needed. * Take on related security responsibilities as the program evolves., A job that challenges you: Our employees are responsible for our growth and success, and we challenge our team members to always be their best in our fast-paced, dynamic and rewarding workplace. A job you can learn from: We offer multi-faceted leadership and learning opportunities to support our team members' career growth and professional development. A team that cares: We value teamwork, innovation, diversity and mutual respect. Through our recognition and rewards programs, we're committed to celebrating and uplifting our team members. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)