Mass General Brigham logo
Mass General BrighamPosted 2 weeks ago

Information Security Engineer III

$93,954–$136,739 year

On-siteSomerville, Massachusetts, United States

Full TimeSenior LevelEnterpriseHealthcare Tech

Job Summary

Analyze technologies, business initiatives, operational processes, and proposed solutions to identify security risks and provide practical, risk-based guidance for informed decision-making. Quickly assess unfamiliar technologies and business challenges, develop an understanding of their security implications, and translate that understanding into actionable recommendations. Apply cybersecurity principles and industry frameworks to evaluate complex situations, recommending appropriate security controls, safeguards, or courses of action. Collaborate with technical teams, business stakeholders, vendors, and security professionals to ensure security considerations are incorporated into decision-making processes. Research emerging technologies, evolving threats, regulatory requirements, and industry practices to determine their relevance and potential impact on the organization. Perform security reviews, architectural evaluations, and other analytical activities to identify weaknesses, opportunities for improvement, and areas requiring additional safeguards or oversight. Develop clear, concise, and well-reasoned security guidance, recommendations, assessments, standards, reports, and other written deliverables that enable stakeholders to make informed business and technology decisions. Communicate complex technical concepts, risks, tradeoffs, and recommendations effectively to audiences ranging from engineers and project teams to business leaders and executive stakeholders. Serve as a trusted advisor by helping stakeholders understand cybersecurity risks, evaluate available options, and make balanced decisions that align with organizational objectives and risk tolerance. Exercise independent judgment in situations that may involve incomplete information, competing priorities, evolving technologies, or ambiguous requirements. Contribute to the development and continuous improvement of security standards, methodologies, assessment approaches, and best practices that strengthen the organization's overall security posture. Mentor junior and mid-level team members by sharing technical knowledge, analytical approaches, communication skills, and professional expertise.

Required Qualifications

  • Bachelor's degree in Computer Science or a related field
  • 5-7 years of experience as a systems engineer, security engineer, security architect, cybersecurity consultant, or in a related role
  • Strong understanding of cybersecurity principles, risk management concepts, and industry-standard security frameworks
  • Demonstrated ability to rapidly understand new technologies, business processes, and operational environments and evaluate their security implications
  • Experience performing security assessments, architecture reviews, risk analyses, technology evaluations, or similar analytical activities
  • Ability to identify complex security issues, evaluate potential solutions, and develop practical, risk-based recommendations
  • Strong knowledge of enterprise technologies, including familiarity with cloud platforms, identity and access management, networking, applications, infrastructure, security operations, and emerging technologies
  • Understanding of security concepts such as Zero Trust, least privilege, defense-in-depth, data protection, secure software development, threat modeling, and vulnerability management
  • Strong verbal communication and presentation skills, including the ability to explain complex technical concepts, influence stakeholders, and facilitate productive discussions
  • Strong analytical, critical-thinking, and problem-solving skills, with the ability to work effectively in complex and ambiguous environments
  • Ability to mentor junior engineers and lead cross-functional technical initiatives
  • Hybrid role with onsite work required
  • Candidates must be flexible based on weekly or monthly business needs
  • Monday-Friday schedule during Eastern business hours
  • On remote workdays, employees must work from a stable, secure, and compliant workstation in a quiet environment
  • Teams video is required and must be accessed using Mass General Brigham-provided equipment

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce