> Markdown version of [/jobs/ext/731752-senior-it-security-engineer](https://www.wearedevelopers.com/jobs/ext/731752-senior-it-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IT Security Engineer - **Company:** Sequel Med Tech - **Location:** Marlborough, MA, United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cloud Computing, Cyber Security, Information Lifecycle Management, IT Management, Information Technology Operations, Microsoft Security Essentials, Azure Active Directory, Phishing, Security Information and Event Management, User Provisioning Software, Software Vulnerability Management, EndPointSecurity, Mttr, Information Technology, Patch Management - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c914934e059f4513 ## About the Role Do you have experience in Vuls?, 7+ years in security engineering, security operations, or a closely related discipline, with at least 4 years of hands-on ownership of security operations or incident response programs., * Demonstrated experience contributing to or owning a security roadmap or program maturity initiative - helping define what the program should accomplish next and building the case for it. * Hands-on experience with vulnerability management and incident response * Experience with SIEM tools and Microsoft security ecosystem (Defender, Entra, Purview) * Exposure to security and compliance frameworks (SOC 2, HITRUST, or similar) * Experience supporting audits, including evidence collection and remediation * Ability to work independently and manage multiple priorities * Strong communication skills with both technical and non-technical stakeholders * Candidate must reside in the contiguous United States and work East Coast hours ## Description Sequel, headquartered in Manchester, New Hampshire, is a company developing the next generation of transformative drug-delivery advancements starting with diabetes. Sequel's approach is to look at diabetes management holistically to advance systems that make living with diabetes simpler and easier for all. Sequel's flagship product, the twiist Automated Insulin Delivery (AID) System, launched in July 2025 for people with type 1 diabetes providing them with personalized diabetes management., The Sr. IT Security Engineer is a hands-on technical leader responsible for executing and continuously improving Sequel's security operations program. This role plays a key part in protecting the organization's systems, data, and users by managing day-to-day security operations, responding to risks, and strengthening core security capabilities. The Manager partners closely with the Senior Manager, Security & Compliance and IT leadership to implement security priorities, support compliance efforts, and drive measurable risk reduction. This role balances deep technical execution with practical input into process improvements and program maturity. This position does not own helpdesk or end-user provisioning activities and works in close collaboration with IT operations to continuously raise the organization's security posture and deliver measurable, auditable risk reduction., Security Strategy, Roadmap & Program Leadership * Execute and support ongoing security operations aligned with Sequel's security priorities and roadmap * Translate security findings, alerts, and audit requirements into actionable remediation plans * Proactively monitor the evolving threat landscape and regulatory environment; assess their impact on Sequel's security posture and bring forward-looking recommendations before they become reactive obligations. * Contribute to investment and business-case discussions by articulating risk-reduction value, projected outcomes, and cost framing in terms leadership can act on. * Partner with IT and Security & Compliance to implement security initiatives and enhancements Vulnerability & Patch Management * Manage the vulnerability lifecycle, including scanning, triage, prioritization, and remediation tracking * Drive recurring patch cycles in coordination with IT operations; champion timely remediation of high-severity findings and validate that fixes close the underlying vulnerability, not just the ticket. * Track and report on vulnerability metrics, trends, and SLA adherence * Support improvements to tooling, processes, and reporting over time SIEM Operations, Incident Response & Platform Maturity * Monitor, triage, and investigate alerts across SIEM and Microsoft Defender tools (Defender for Endpoint, Defender for Cloud Apps, Defender for Identity). * Lead end-to-end incident response, including containment, investigation, root cause analysis. Communicate status and findings to security leadership. * Own SIEM platform maturity: build and tune detection rules, develop response automation and playbooks, expand log and data-source coverage, and continuously reduce alert noise and analyst fatigue. * Define, track, and present response metrics - MTTD, MTTR, alert volume, false-positive rates - and use trend data to prioritize tuning and platform investment decisions. Risky User & Risky Device Remediation * Identify, investigate and remediate risky users and devices across Microsoft Entra and Defender tools. * Support Conditional Access and device compliance policies * Partner with IT to address identity risks and improve overall security posture Security Policy & Data Protection Administration (Microsoft Purview & DLP) * Administer Microsoft 365 security and data protection solutions, including Purview DLP, sensitivity labeling, retention policies, data lifecycle management, and defensible deletion. * Maintain and update security configurations and documentation in response to evolving business and compliance feedback. * Assess current data-protection coverage and recommend policy enhancements aligned to the compliance roadmap. Security Awareness & Training Program * Support the execution of the security awareness program, including phishing simulations and training campaigns (KnowBe4). * Analyze simulation results, assess the threat landscape, and provide recommendations on training content and simulation difficulty to keep improve training program outcomes. Audit & Compliance Execution * Support audit readiness activities, including evidence collection and control execution (e.g., SOC 2, HITRUST) in the GRC platform (Vanta). * Maintain documentation and drive remediation of audit findings; partner with the Senior Manager, Security & Compliance to ensure audit readiness is maintained. * Partner with Security & Compliance to ensure controls are operating effectively Documentation, Metrics & Reporting * Maintain runbooks, standard operating procedures, and security workflow documentation sufficient for audit evidence and operational continuity. * Track and report security and compliance metrics and related platforms; deliver leadership-ready reporting on a regular cadence. * Contribute to board- and executive-level security reporting by providing clear, data-backed summaries of program status, risk posture, and progress against roadmap milestones. Cross-Functional Collaboration * Partner with IT, Legal, and People & Culture to align security practices with business and regulatory needs * Provide security guidance on IT projects, configurations, and change requests ## Related Videos - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)