Back to search
CRICO Linkedin · Posted 9d ago

Security Engineer

Boston, Massachusetts, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Security Engineer

Role Summary:

Reporting to the Chief Information Security Officer, the Cybersecurity Engineer is responsible for implementing and maintaining security technologies, processes, and controls that protect the organization's information assets. This role supports cybersecurity operations, identity and access management, governance, risk, and compliance (GRC) activities, and emerging AI security initiatives. The engineer will assess security risks, implement technical safeguards, support regulatory and compliance requirements, monitor security events, and help establish governance frameworks for the secure adoption and use of artificial intelligence technologies.

Responsibilities:

Security Engineering & Operations


  • Evaluate, deploy, and administer security tools, technologies, and controls to strengthen the organization's security posture.
  • Apply security policies, standards, and industry best practices to support enterprise security objectives.
  • Respond to alerts and events from security monitoring systems by performing triage, investigation, analysis, and escalation.
  • Tune detection systems to reduce false positives and develop new threat detection and response capabilities.
  • Contribute to the organization's threat hunting program through hypothesis development, investigation, and reporting.
  • Collaborate with internal teams and external partners during security incidents and response activities.
  • Support vulnerability management activities, including identification, assessment, prioritization, remediation tracking, and reporting.
  • Submit and track changes through the organization's change management process to maintain system integrity and security.
  • Application & Cloud Security


  • Support secure software development practices by identifying, communicating, and addressing application security risks.
  • Collaborate with development teams to validate remediation efforts through testing and review.
  • Participate in security architecture reviews for cloud, SaaS, and enterprise applications.
  • Support onboarding of new applications into the organization's identity and access management ecosystem.
  • Identity & Access Management


  • Assist with implementation and administration of identity governance, privileged access management, and authentication technologies.
  • Support periodic access certification and segregation-of-duty reviews.
  • Governance, Risk, and Compliance (GRC)


  • Conduct cybersecurity risk assessments and document identified risks, mitigation strategies, and residual risk.
  • Support the development, maintenance, and review of security policies, standards, procedures, and control frameworks.
  • Assist with regulatory, audit, and compliance activities, including evidence collection, control validation, and remediation tracking.
  • Maintain risk registers, exception processes, and security metrics for reporting to leadership.
  • Participate in third-party and vendor risk assessments.
  • Support compliance initiatives aligned with frameworks such as NIST Cybersecurity Framework (CSF), CIS Controls, ISO 27001, HIPAA, and SOC 2.
  • AI Security & Governance


  • Support the secure adoption and governance of artificial intelligence and machine learning technologies across the organization.
  • Assist in developing AI security policies, standards, and risk management practices aligned with the NIST AI Risk Management Framework.
  • Evaluate AI-enabled applications and services for security, privacy, compliance, and operational risks.
  • Assess and monitor risks associated with generative AI, large language models (LLMs), third-party AI platforms, and AI-integrated business processes.
  • Collaborate with stakeholders to implement controls that mitigate AI-specific threats, including prompt injection, data leakage, model misuse, and unauthorized access.
  • Participate in AI security reviews, risk assessments, and governance activities to ensure responsible and secure use of AI technologies.
  • Security Awareness & Training


  • Assist with the delivery of cybersecurity and AI security awareness training for employees and targeted user groups.
  • Evaluate user-reported communications to identify phishing, social engineering, and other malicious threats and respond appropriately.
  • Maintain security documentation, including playbooks, standards, procedures, and knowledge base articles.
  • Assist in gathering, analyzing, and reporting cybersecurity and AI governance metrics for leadership.
  • Qualifications:

    Education & Experience:

    • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field preferred; equivalent experience will be considered.
    • 2-3+ years of experience in cybersecurity, information security, security engineering, security operations, risk or related disciplines.
    • In-depth knowledge of enterprise infrastructure, including operating systems, directory services, system configuration, application hosting, and virtualization technologies.
    • Familiarity with AI, machine learning, generative AI, or emerging AI governance and security practices preferred.
    • Experience implementing and managing endpoint protection strategies such as data protection and malware defense.
    • Experience supporting security governance, risk management, compliance, audit, or control assessment activities.
    • Experience securing cloud platforms and service-based architectures (SaaS, PaaS, IaaS).
    • Proficient in analyzing network traffic and identifying abnormal or malicious activity through packet analysis and monitoring tools.
    • Experience with centralized event monitoring and log analysis platforms for security incident detection and response.
    • Ability to assess, prioritize, and mitigate security vulnerabilities and clearly communicate risk mitigation strategies to technical and non-technical audiences.

    Skills:

    • Strong understanding of IT operations and security best practices, with the ability to identify improvement opportunities and implement process enhancements.
    • Familiarity with vulnerability assessment, penetration testing methodologies, and secure system configuration practices.
    • Skilled in leveraging data analysis tools and techniques to obtain, clean, and organize data to generate recommendations and insights

    Specialized Certifications for Consideration:

    • CompTIA Security+
    • CompTIA CySA+
    • Certified in Risk and Information Systems Control (CRISC)
    • Certified Information Security Manager (CISM)
    • Certified Cloud Security Professional (CCSP)
    • ISC2 Certified in Cybersecurity (CC)
    Free. 20 seconds. No password. See every match in this search.

    Create a free Caio profile to unlock more results and save your role and location preferences.

    Unlock free search
    Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
    View Managed Job Search