
Security Engineer
Suffolk Construction2 years ago
Boston, MA, USASenior
Responsibilities
- Diagnose and resolve Level 2 security configuration and platform issues escalated by Level 1 support.
- Support data classification, administration, lifecycle management, and data-handling requirements across systems and business processes.
- Assess risks, review access controls, support secure configurations, and coordinate remediation for corporate applications.
- Participate in security audits, vulnerability scans, and penetration tests across Suffolk infrastructure.
- Support identity and access management, access reviews, role-based and privileged access controls, secure authentication, provisioning, and access governance.
- Implement and manage secure identity solutions through third-party providers.
- Monitor vulnerability findings, validate ownership, prioritize remediation, track corrective actions, and report progress.
- Investigate and resolve security issues across development and operations while documenting root causes and coordinating remediation.
- Maintain security dashboards and metrics, perform risk analysis, and support enterprise security systems and review processes.
- Mentor Help Desk Analysts and promote Suffolk information security standards.
- Apply security controls across Azure, AWS, or similar cloud environments, including identity configuration, logging, monitoring, secure access, vulnerability remediation, and cloud workload protection.
Requirements
- Bachelor’s degree in computer science, information systems management, or a related technical discipline, or an equivalent combination of education, technical training, or work/military experience.
- At least five years of relevant IT and/or information security experience, including hands-on enterprise systems, security tools, or security operations experience.
- At least three years of experience with enterprise information security and enterprise cloud-based solutions.
- At least three years of experience with large, distributed systems.
- Experience designing, installing, and configuring enterprise security solutions while meeting architecture, security, and privacy requirements.
- Technical foundation in systems security and network security.
- Familiarity with Microsoft security tools, vulnerability management platforms, cloud security platforms, security monitoring solutions, information security frameworks, and security configuration guides.
- Understanding of PCI, MA 201 CMR 17.00, CCPA, HIPAA, and similar regulatory and contractual security requirements.
- Working knowledge of Windows, MacOS, Linux, and related security risks, controls, and vulnerabilities.
- Ability to collaborate with development, engineering, and DevOps teams to integrate security requirements, controls, and automation into software delivery pipelines.
- Experience with penetration testing, security scanning, threat modeling, incident management, project management, and audits is desirable.
- At least one industry certification, such as CISSP or CISA, is desirable.
- Strong collaboration, communication, negotiation, mediation, peer influence, and technical documentation skills.
Benefits
- Competitive salaries and a comprehensive total rewards program.
- Medical, dental, vision, virtual care, and emotional and mental health benefits.
- Generous paid time off, company-paid and voluntary life insurance, short- and long-term disability, and tax-deferred savings accounts.
- 401(k) plan with employer match and access to financial resources.
- Commuter benefits and 10 backup daycare days per year.
- Auto allowances and gas cards are available for certain roles.
- The role is performed primarily in an office environment and includes job site walking.