> Markdown version of [/jobs/ext/564560-it-security-compliance-engineer](https://www.wearedevelopers.com/jobs/ext/564560-it-security-compliance-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security & Compliance Engineer - **Company:** OPTION ONE TECHNOLOGIES LLC - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $80,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Cyber Security, Information Security Management, Python (Programming Language), Performance Tuning, Windows PowerShell, Phishing, Zero Trust Network Access, Web Application Security, Security Information and Event Management, Software Vulnerability Management, Scripting, Bug Reporting, Cybercrime, SentinelOne Expertise, Vulnerability Analysis - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=158714f37cb76e80 ## About the Role Do you have experience in Zero Trust security?, The ideal candidate is equally comfortable triaging a SIEM alert, walking a non-technical user through a phishing simulation result, scoping a penetration test, and mapping a control to a NIST subcategory. Strong communication is not a "nice to have" here - it is central to the job., * 4+ years in security engineering, security operations, or a closely related role (mid-to-senior range; depth matters more than exact years). * Hands-on SOC / SIEM experience - alert triage, investigation, tuning, and detection logic. * Working knowledge of and demonstrable experience with SentinelOne, Zscaler, Umbrella and KnowBe4 (or directly comparable EDR, ZTNA/SWG, and security-awareness platforms). * Practical penetration testing ability and experience running/interpreting vulnerability scans and driving remediation. * Solid understanding of SOC 2 and NIST (e.g., 800-53 / CSF) controls, evidence, and audit support. * Familiarity with compliance considerations for Registered Investment Advisors or another regulated financial environment. * Excellent written and verbal communication - you can teach, de-escalate, and explain risk to non-technical audiences, and you genuinely enjoy working with users every day. Preferred / Nice to Have * Relevant certifications such as OSCP, CISSP, GPEN, GCIH, Security+, or equivalent. * Experience with cloud security (AWS / Azure / GCP) and SaaS security posture. * Scripting / automation (Python, PowerShell, or similar) for tooling and detection. * Prior experience in financial services, fintech, or another highly regulated industry., * Writing Security Policies: 2 years (Required) * Security User Training: 2 years (Required) * DUO: 2 years (Preferred) * KnowBe4: 2 years (Preferred) ## Description We are seeking a mid-to-senior Security Engineer to own and advance the security posture of a regulated financial services environment. This is a hands-on role that blends day-to-day operational defense with compliance, user enablement, and offensive testing. You will be the connective tissue between our security tooling, our compliance obligations, and the people who rely on you to keep them safe., * Security operations & monitoring - Operate and tune our SOC/SIEM stack, investigate alerts, triage incidents, and drive detection and response improvements. Reduce noise, increase signal, and document what you find. * Endpoint & network defense - Administer and optimize SentinelOne (EDR) and Zscaler (ZTNA / secure web gateway), including policy tuning, exclusions, threat hunting, and incident containment. * Vulnerability management - Run and interpret recurring vulnerability scans, prioritize findings by real-world risk, coordinate remediation with IT and engineering, and track issues to closure. * Penetration testing - Plan and perform internal and external penetration tests, document findings with clear severity and reproduction steps, and partner with stakeholders on remediation. Coordinate scope and results from third-party pen tests where applicable. * Compliance & governance - Maintain and evidence controls for SOC 2 and NIST frameworks, and support compliance obligations specific to Registered Investment Advisors (RIAs) (e.g., SEC/regulatory safeguarding and recordkeeping expectations). Prepare for and support audits. * Security awareness & training - Own the KnowBe4 program: build phishing simulations, manage training campaigns, analyze results, and follow up with users. Work with employees daily to coach them on secure behavior in plain, approachable language. * User-facing support - Serve as a trusted, patient point of contact for security questions across the business. Translate technical risk into terms any user can act on. * Documentation & continuous improvement - Keep runbooks, policies, and procedures current. Recommend and implement improvements to tooling, process, and posture. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)