Security Engineer

QuEra Computing Inc.
Boston, MA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Access Network Amazon Web Services Software System Penetration Testing JIRA Microsoft Azure Bash Shell Cyber Security DevOps Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language) Windows PowerShell
+11 more
Security Information and Event Management Software Vulnerability Management Scripting Cloud Platform System Multi-Cloud Firewalls (Computer Science) Microsoft Sentinel Oracle Cloud Infrastructure Splunk Qualys Vulnerability Analysis

Job description

As a Security Engineer, you will be part of our growing IT, Security & Compliance team, designing, administrating and configuring security baselines/best practices for on-premises and cloud environments, assisting teams with vulnerability management, gathering evidence for audits, and more. This is an opportunity to be part of a small team with increasing importance and responsibility. Primary Responsibilities

  • Deploy/Administer secure configuration baselines for network access, firewalls/WAFs, VPN, AWS/Azure Cloud resources.
  • Review and triage findings from vulnerability scans, penetration tests, and configuration assessments to identify potential security risks.
  • Work with engineers, DevOps and system owners to remediate vulnerabilities across multi-cloud and on-prem assets.
  • Monitor cloud environments for misconfigurations and suspicious activity.
  • Review/Configure IAM/access policies for internal and cloud systems.
  • Integrate security tools and data into dashboards or workflow systems (e.g., Jira, SIEM, or ticketing).
  • Provide technical evidence and control implementation support for SOC 2, ISO 27001, or customer security assessments.
  • Partner with business leads to map technical controls to framework requirements.
  • Assist with incident triage, response, and root cause analysis.
  • Support endpoint protection, log monitoring, and threat intelligence initiatives.

Requirements

  • Bachelor’s degree in a related field or equivalent related experience
  • Minimum of four years of experience in information security, systems administration, or DevOps.
  • Strong understanding of operating systems, networking, and cloud fundamentals.
  • Knowledge of security/compliance frameworks such as SOC 2, ISO 27001, or NIST
  • Familiarity with vulnerability management tools (e.g., Tenable, CrowdStrike, Qualys, Rapid7, AWS Inspector, or Microsoft Purview).
  • Working knowledge of AWS, Azure, and/or Oracle Cloud security controls and services.
  • Comfortable working cross-functionally with engineering, IT, and other teams as needed.

Knowledge, Skills, and Abilities

  • Ability to travel up to 15% to assist in team building and planning exercises.
  • Strong, professional communication skills, both verbal and written, including the skill in articulating and translating technical language to non-technical customers.
  • Ability to plan for contingencies and anticipate problems.
  • Ability to ask critical questions to assess needs and requirements, * Security certifications (Security+, GSEC, AWS Security Specialty, or similar).
  • Proficient in at least one scripting language (Python, PowerShell, or Bash).
  • Endpoint Security/Patching/Inventory experience
  • Experience with SIEM or SOAR platforms (e.g., Splunk, Microsoft Sentinel).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all