Security Engineer (Boston HQ)

WinnCompanies

$80K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2-5 years of hands-on experience in security engineering, operations, or IT security.
  • Practical knowledge of identity and access management (IAM) concepts and tools.
  • Experience with security incident detection and response tools.
  • Understanding of third-party/vendor risk assessment principles.
  • Strong communication skills for interacting with technical and non-technical stakeholders.
  • Ability to work independently in a lean environment and solve problems effectively.

Responsibilities

  • Administer and manage IAM processes and tools for a distributed workforce.
  • Conduct vendor and third-party risk assessments and document findings.
  • Serve as a main contact for security incident detection and response.
  • Triage and investigate security alerts alongside the MDR provider.
  • Collaborate with the Director of Information Security on program strategy and priorities.
  • Configure and operate security tools in partnership with IT and MSSP.
  • Contribute to policy development and compliance-related activities.

Benefits

  • Generous time off policies including paid holidays and sick time.
  • 401(k) with company match and various health plan options.
  • Long-term disability and life insurance coverage, including optional supplemental insurance.
  • Tuition reimbursement and continuous professional development opportunities.
  • Wellbeing program with health incentives and employee assistance resources.
Full Job Description
Security Engineer to join our team in Boston, MA to help drive our progress forward.

Our organization manages affordable housing communities and supports approximately 3,000 corporate and property-based employees. We are building out a maturing security program and are looking for a hands-on Security Engineer to help drive it forward.

Reporting to the Director of Information Security & Risk Management, you will be a core member of a lean security team. This is a high impact role with broad exposure: where you will work across core domains including identity and access management (IAM), third-party risk, and incident detection and response while working closely with the Director of Information Security to strengthen overall security architecture and program strategy. You will work closely with our internal IT team and our managed security service provider (MSSP) to deploy, configure, and tune security tools, improve monitoring and alerting, and support incident response activities.

The salary range for this role is $80,000 to $110,000 per year, dependent on experience.

Responsibilities:

Identity & Access Management
  • Administer and manage identity and access management (IAM) processes and tools across a large, distributed workforce.
  • Manage the high-volume onboarding and offboarding process common in property management environments.
  • Implement and tune access controls, role-based access, multi-factor authentication, and least-privilege practices.
  • Support access reviews, partnering with IT and business owners to validate findings.

Vendor & Third-Party Risk
  • Conduct vendor and third-party risk assessments using the firm's third-party assessment tool.
  • Evaluate vendor security postures, document findings, track remediation, and advise stakeholders on acceptable risk.
  • Help refine the third-party risk process and reporting as the program matures.

Incident Detection & Response
  • Serve as a key point of contact for security incident detection and response, working alongside our managed detection and response (MDR) provider.
  • Triage, investigate, and coordinate response to alerts
  • 24/7 on call for incidents escalated by the MDR service.
  • Contribute to and help mature incident response playbooks, runbooks, and post-incident reviews.

Program Development & Implementation
  • Work directly with the Director of Information Security & Risk Management to shape the strategy, roadmap, and priorities of the security program.
  • Work with internal IT and the IT MSSP to implement, configure, and operate security tools and controls.
  • Contribute to policy development, security awareness training, and compliance-supporting activities as needed.
  • Take on related security responsibilities as the program evolves.

Requirements
  • 2-5 years of hands-on experience in security engineering, security operations, IT security, or a closely related role.
  • Practical experience with identity and access management concepts and tooling (e.g., directory services, SSO, MFA, user provisioning/deprovisioning).
  • Experience working with security incident detection and response tools, including working with SIEM, EDR, or MDR- services.
  • Understanding of third-party / vendor risk assessment principles.
  • Proven ability to collaborate effectively with internal IT teams and external service providers (MSSP, MDR).
  • Strong written and verbal communication skills, with the ability to clearly document findings and articulate risks to non-technical stakeholders.
  • Self-directed and capable of working independently, demonstrating a strong problem-solving mindset in a lean and rapidly growing security program

Preferred
  • Experience supporting a large or distributed workforce, ideally across multiple physical sites.
  • Hands-on experience implementing controls for the protection of sensitive data (PII),
  • Familiarity with common security and privacy frameworks (e.g., NIST CSF, CIS Controls) and associated regulatory considerations.
  • Relevant certifications such as Security+, SSCP, GSEC, or progress toward CISSP.
  • Experience using scripting or automation tools (e.g., PowerShell, Python) to streamline IAM and security operational tasks


Our Benefits:

Regular full-time US employees are eligible to participate in the following benefits:
  • Generous time off policies (including 11 paid holidays (12 for MA employees); Generous Accrued Time Off increasing with years of service; Generous paid sick time; Annual day of service; Floating Holiday)
  • 401(k) plan options with a company match
  • Various Comprehensive Medical, Dental, & Vision plan options
  • Flexible Spending Account, Dependent Care Flexible Spending Account, Health Savings Account options with HSA annual employer contribution
  • Long Term Disability and voluntary Short Term Disability; Basic Term Life Insurance and AD&D; optional supplemental life insurance
  • Health Expense Reimbursement program (including gym memberships, equipment, and subscriptions)
  • Tuition Reimbursement program and continuous training and development opportunities
  • Wellbeing program (group challenges, seminars, opportunities to earn points to reduce medical premiums), Employee Assistance Program, & Commuter and Parking Reimbursement options
  • Employee Corporate Discount Programs
  • Flexible and/or Hybrid schedules are available for certain roles
  • Employee Relief Program supporting employees with unexpected hardships that place undue financial stress on them and their families
  • To learn more, visit winnbenefits.com


Salary will vary based on job responsibilities and scope, geographic location, candidate's relevant experience, and other factors.

Internal candidates, please apply here: Internal Careers Hub

Similar Jobs

More Jobs at WinnCompanies

More Information Technology Jobs

Find similar Security Engineer (Boston HQ) jobs: