Search jobs > Boston, MA > Permanent > Security engineer

Security Engineer

CPS Insurance Services
Boston, Massachusetts, US
Full-time

We are hiring a Security Engineer with a specialization in APIs to join our DevSecOps team. The ideal candidate will play a crucial role in enhancing our API-centric development approach, managing API security tools, and ensuring the security of our systems within an Azure environment.

Our DevSecOps team is focused on high performance, tracking work in a management system to demonstrate progress towards our goals.

We value meaningful security work over security theater, emphasizing evidence-backed security measures.

Increase your chances of an interview by reading the following overview of this role before making an application.

What you'll be doing

  • Own the API security program, including strategic planning, tool selection, and demonstrating program value through metrics.
  • Implement and manage API security tools, focusing on identifying full-featured API security solutions.
  • Work closely with development teams to integrate security principles in API development and ensure compliance with security standards.
  • Support the DevSecOps team in areas such as container security, application security testing tools, and infrastructure as code scanning.
  • Strategically manage, identify, and track new technologies to ensure a comprehensive security tool stack configuration to address threats and gaps, particularly related to API security.
  • Build and present business cases on new technologies to address new and emerging risks, as well as gaps identified by external and internal assessors.
  • Lead work in security controls and requirements identification for large and small technology and business initiatives.
  • Build strong relationships with other technical personnel to create trust in guidance and insight on security topics.
  • Maintain and improve policy and standards documentation relating to API security.

What you will need to be successful

  • Bachelor's degree in Information Systems, Cybersecurity or a related field and minimum 2 years relevant experience; or equivalent combination of education and experience.
  • Demonstrated experience as a professional security engineer and / or software engineer, particularly regarding APIs and modern software architecture.
  • Experience with Azure cloud environments and familiarity with API management tools like Azure APIM and Kong.
  • Experience executing and performing security risk assessments for on-premise and cloud-based services.
  • Advanced security certification (e.g., CISSP, CSSLP, CEH) or demonstrable level of competency preferred.
  • Agile / Scrum and Microsoft Azure experience are beneficial with expert-level working knowledge of API Security and the concepts and tooling that can help protect them.
  • Expert knowledge of leading information security frameworks and best practices (OWASP API Top 10, NIST Cybersecurity Framework, ISO27001 / 2, and CIS Top 20 Controls), and extensive experience applying frameworks to identify appropriate security measures and applying multiple risk treatments.
  • An API attacker mindset that is only satisfied when defense-in-depth controls are in place but will still question assumptions about our existing security posture.
  • Ability to perform high-quality and effectual threat modeling.
  • Ability to present complex security recommendations and influence both senior leaders and technology SMEs.
  • Ability to research, identify and iterate on new security metrics to provide greater visibility on program status and improvement opportunities to senior leadership.
  • Ability to clearly and logically document all procedures related to this role and a passion for keeping documentation up to date.
  • Excellent interpersonal skills including the ability to interact effectively and professionally with individuals at all levels; both internal and external.
  • Team player capable of developing strong collaborative working relationships with internal partners and able to effectively engage and build consensus among cross-functional teams.
  • Experience in financial services or healthcare industries, dealing with sensitive data protection is a plus.
  • Familiarity with container security, application security testing tools, and infrastructure as code scanning is a plus.

No phone calls or third parties. Candidates must be United States citizens or legal permanent residents. Proof of legal residence and work authorization in the United States is required.

J-18808-Ljbffr

1 day ago
Related jobs
Promoted
MITRE
Bedford, Massachusetts

Requires a minimum of 8 years of related experience with a Bachelor’s degree; or 6 years and a Master’s degree; or a PhD with 3 years’ experience; in human factors engineering (HFE), human computer interaction, engineering, business, or a related field. Technical depth and stature in applying collab...

Promoted
Greylock
Boston, Massachusetts

Greylock has a history of investing in enterprise-category-defining security companies (Palo Alto Networks, Rubrik, Okta, Sumo Logic, Imperva, Skyhigh, Demisto, Sqreen, Abnormal Security, Cato Networks, Censys, Cribl, Obsidian, and Opal). We've recently invested in a new startup set to revolutionize...

Promoted
MITRE
Bedford, Massachusetts

Typically requires a minimum of 8 years of related experience with a bachelor’s degree in electrical engineering,physics, computer engineering, mathematics,or similar field; or 6 years and a master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work e...

Promoted
Thornton Tomasetti
Boston, Massachusetts

Project Engineer - Protective Design & Security page is loaded Project Engineer - Protective Design & Security Apply locations Boston, MA, USA time type Full time posted on Posted 3 Days Ago job requisition id R4299. Similar Jobs (5) Engineer - Protective Design and Security locations Boston...

Promoted
BERKSHIRE HATHAWAY SPEC INS
Boston, Massachusetts

Works closely with our external managed security solution provider and SOC analysts to enhance security solutions to reduce malicious and suspicious activity based on security data analysis, review of the current threat landscape, and assessment/triage of security tickets. Berkshire Hathaway Special...

Promoted
Smartsheet
Boston, Massachusetts

Commercial Security Solutions Engineer. Represent Smartsheet's security and compliance capabilities to prospects; proactively support prospects in performing evaluations; ensure that prospects keep to their security evaluation scope and timelines. Be a recognized Smartsheet security expert and devel...

Promoted
Sonos, Inc.
Boston, Massachusetts

The Product Security team identifies security problems, risks, and threats in current and future products and proactively addresses them by designing in and implementing security from the hardware level to the application level. As a Security Software Engineer you will help ensure that the security ...

Blackbaud
Remote, Massachusetts, US
Remote

You are either a security-minded software engineer who has been building modern services using a microservice architecture in an agile development environment or a development-interested security practitioner who understands security best practices, but wants to get closer to development and enginee...

MITRE
Bedford, Massachusetts

The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. MITRE’s National Security Accelerator Program (. ...

Cloud Security Services
Bedford, Massachusetts

Contract Duration : 6-7 months Position Location : Hybrid – 60% Office, 40% Remote (Onsite Locations: Bedford, MA / Atlanta, GA / San Diego, CA / Waukasha, WI) Position Overview: We are seeking an experienced Active Directory (AD) Engineer to supplement an existing team and provide Identity an...