Security Engineer

CPS Insurance Services
Boston, Massachusetts, US
Full-time

We are hiring a Security Engineer with a specialization in APIs to join our DevSecOps team. The ideal candidate will play a crucial role in enhancing our API-centric development approach, managing API security tools, and ensuring the security of our systems within an Azure environment.

Our DevSecOps team is focused on high performance, tracking work in a management system to demonstrate progress towards our goals.

We value meaningful security work over security theater, emphasizing evidence-backed security measures.

Increase your chances of an interview by reading the following overview of this role before making an application.

What you'll be doing

  • Own the API security program, including strategic planning, tool selection, and demonstrating program value through metrics.
  • Implement and manage API security tools, focusing on identifying full-featured API security solutions.
  • Work closely with development teams to integrate security principles in API development and ensure compliance with security standards.
  • Support the DevSecOps team in areas such as container security, application security testing tools, and infrastructure as code scanning.
  • Strategically manage, identify, and track new technologies to ensure a comprehensive security tool stack configuration to address threats and gaps, particularly related to API security.
  • Build and present business cases on new technologies to address new and emerging risks, as well as gaps identified by external and internal assessors.
  • Lead work in security controls and requirements identification for large and small technology and business initiatives.
  • Build strong relationships with other technical personnel to create trust in guidance and insight on security topics.
  • Maintain and improve policy and standards documentation relating to API security.

What you will need to be successful

  • Bachelor's degree in Information Systems, Cybersecurity or a related field and minimum 2 years relevant experience; or equivalent combination of education and experience.
  • Demonstrated experience as a professional security engineer and / or software engineer, particularly regarding APIs and modern software architecture.
  • Experience with Azure cloud environments and familiarity with API management tools like Azure APIM and Kong.
  • Experience executing and performing security risk assessments for on-premise and cloud-based services.
  • Advanced security certification (e.g., CISSP, CSSLP, CEH) or demonstrable level of competency preferred.
  • Agile / Scrum and Microsoft Azure experience are beneficial with expert-level working knowledge of API Security and the concepts and tooling that can help protect them.
  • Expert knowledge of leading information security frameworks and best practices (OWASP API Top 10, NIST Cybersecurity Framework, ISO27001 / 2, and CIS Top 20 Controls), and extensive experience applying frameworks to identify appropriate security measures and applying multiple risk treatments.
  • An API attacker mindset that is only satisfied when defense-in-depth controls are in place but will still question assumptions about our existing security posture.
  • Ability to perform high-quality and effectual threat modeling.
  • Ability to present complex security recommendations and influence both senior leaders and technology SMEs.
  • Ability to research, identify and iterate on new security metrics to provide greater visibility on program status and improvement opportunities to senior leadership.
  • Ability to clearly and logically document all procedures related to this role and a passion for keeping documentation up to date.
  • Excellent interpersonal skills including the ability to interact effectively and professionally with individuals at all levels; both internal and external.
  • Team player capable of developing strong collaborative working relationships with internal partners and able to effectively engage and build consensus among cross-functional teams.
  • Experience in financial services or healthcare industries, dealing with sensitive data protection is a plus.
  • Familiarity with container security, application security testing tools, and infrastructure as code scanning is a plus.

No phone calls or third parties. Candidates must be United States citizens or legal permanent residents. Proof of legal residence and work authorization in the United States is required.

J-18808-Ljbffr

1 day ago
Related jobs
Promoted
Abacus Technology Corporation
Hanscom Air Force Base, Massachusetts

Network Engineer to provide infrastructure support for the Technical Advisory and Assistance Services (TAAS) program at Hanscom AFB. Analyze network system trade space, identify, and propose optimal solutions to meet cost, schedule, performance, security, and resiliency requirements. Advise staff En...

Promoted
GeoLogics Corporation
Dedham, Massachusetts

Proficient understanding of cyber security specifications such as Risk Management Framework (RMF), DIACAP, STIGs and other government security specifications and guidelines. Sr Advanced Information Assurance Engineer with ACTIVE Secret Clearance (US Citizenship REQUIRED). ACTIVE Secret security clea...

Promoted
MITRE
Bedford, Massachusetts

Master of Science (or equivalent experience) in Cybersecurity, Software Engineering, Computer Science, Computer Engineering, or related engineering disciplines. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, a...

Promoted
Fifth Third Bank
Boston, Massachusetts

As the Information Security Software Data Engineer II, you will join our team to support the development and maintenance of data-driven cybersecurity solutions. Information Security Software Data Engineer II. Your role will involve building tools and solutions for data management, security, and valu...

Promoted
MITRE
Bedford, Massachusetts

TheDistinguished Chief Engineeris the technology leader for the Division and works directly for the Managing Director to set the strategy, vision, and direction for the Cyber Division, working closely with the Center Distinguished Chief Engineer. Partner with other MITRE Air and Space Force Center d...

Promoted
Smartsheet
Boston, Massachusetts

Commercial Security Solutions Engineer. Represent Smartsheet's security and compliance capabilities to prospects; proactively support prospects in performing evaluations; ensure that prospects keep to their security evaluation scope and timelines. Be a recognized Smartsheet security expert and devel...

Promoted
MITRE
Bedford, Massachusetts

MS in electrical engineering, computer engineering, applied mathematics, physics, systems engineering, or related discipline. Applicants selected for this position will be subject to a government security investigation and must meet eligibility requirements for access to classified information or ap...

Promoted
Canonical - Jobs
Boston, Massachusetts

We have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. The Security Operations (SecOps) team is responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies. They de...

Promoted
Recooty
Boston, Massachusetts

Support staff adherence and education to QuEra Cloud Security best practices and lead the SaaSIO Engineering Security best-practices training. This position is responsible for the QuEra cybersecurity posture from an engineering, analysis and auditing perspective. Responding to security incidents and...

GovServicesHub
Boston, Massachusetts

Position Overview: We are seeking a skilled and experienced CyberArk Security Engineer to collaborate with our chosen solution integrator on the implementation of CyberArk solutions, including Privilege Access Management (PAM), Endpoint Privilege Management (EPM), and Secure Cloud Access (SCA)....