Lead Security Compliance Engineer

| Greater Boston Area
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.

What if security was an opportunity and not an obstacle? What if it wasn't a clunky afterthought, or a cumbersome requirement preventing you from doing the things you really want to do? What if you could securely advance your business with clarity and confidence? We like the sound of that, too! At Rapid7, we believe in simplifying the complex through shared visibility, analytics, and automation that unite teams around challenges and successes of cybersecurity. Our products and services empower over 9,100 customers across over 120 countries to seamlessly build security into the heart of their organizations.

Partnering with our customers to build lasting trust is essential to our joint success. That's why we're looking for a Lead Security Compliance Engineer to join our Trust & Security Governance team, focusing on our policy and compliance related programs. This role will partner closely with our Platform Delivery (DevOps), Software Engineering, and IT teams to deliver on the program goals.

Responsibilities

  • Educate partner teams on compliance programs, workflows, and processes including upcoming changes

  • Perform risk assessment and control gap analysis against policies and standards such as ISO, SOC 2, PCI, FedRAMP, and NIST 

  • Create, organize, and articulate summarized risk findings that are clear and actionable by partner teams

  • Work closely with partner teams to deliver policy and compliance requirements in ways that are cost effective, align with business objectives and comply with security standards

  • Design, develop, and implement automation for continuous control monitoring, administrative tasks, and metric reporting for all security compliance programs

  • Monitor environments to verify the effectiveness of security controls and identify areas for improvement

  • Maintain knowledge of Rapid7’s products, environment, systems, and architecture

  • Maintain knowledge of industry trends and security landscape to drive roadmap and continuous program evolution

  • Create and maintain solutions to automate the discovery and remediation of noncompliant resources

  • Support internal and external auditors or advisors as needed

Qualifications

  • Experience implementing compliance-as-code approaches and tools, such as Chef InSpec, Terraform Sentinel, CFN Guard, or Open Policy Agent (OPA)

  • Experience creating post-deployment security checks with tools such as AWS Config and the Config Rule Development Kit (RDK), DivvyCloud, Azure Policy, or GCP Cloud Asset Inventory

  • You are passionate about security chaos engineering

  • Experience with DevOps tools such as Salt, Puppet, Chef, or Ansible

  • Demonstrated experience with security audit, security control assessments, risk assessment and compliance

  • Experience with serverless technologies such as Lambda, Docker, and Kuberneetes

  • Demonstrated experience with security standards/frameworks such as ISO, SOC 2, PCI, FedRAMP, NIST, etc.

  • Experience managing the implementation or enhancement of security controls across diverse business units

  • Effective negotiating, critical thinking and problem-solving skills, including the ability to develop innovative risk mitigation solutions that address core issues with limited supervision

  • Hands-on experience with scripting and coding to automate systems and security administration tasks in Python, Go, Javascript, or Rust

 

Additional Qualifications

  • One or more of the following: AWS Certified Solutions Architect Professional, AWS Certified DevOps Professional, GCP Professional Cloud Security Engineer, GCP Cloud DevOps Engineer Professional, Azure Security Engineer, Azure Solutions Architect, Azure DevOps Engineer, Hashicorp Security Automation Certified

Read Full Job Description
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
    • GolangLanguages
    • JavaLanguages
    • JavascriptLanguages
    • PythonLanguages
    • RLanguages
    • RubyLanguages
    • ScalaLanguages
    • SqlLanguages
    • jQueryLibraries
    • ReactLibraries
    • ReduxLibraries
    • AngularJSFrameworks
    • DjangoFrameworks
    • ExpressFrameworks
    • FlaskFrameworks
    • HadoopFrameworks
    • Node.jsFrameworks
    • Ruby on RailsFrameworks
    • SparkFrameworks
    • SpringFrameworks
    • TensorFlowFrameworks
    • CassandraDatabases
    • MongoDBDatabases
    • MySQLDatabases
    • PostgreSQLDatabases
    • RedisDatabases
    • Google AnalyticsAnalytics
    • OptimizelyAnalytics
    • IllustratorDesign
    • InVisionDesign
    • PhotoshopDesign
    • SketchDesign
    • AsanaManagement
    • ConfluenceManagement
    • JIRAManagement
    • WordpressCMS
    • SalesforceCRM

Location

Rapid7 is conveniently located between the North End and West End of Boston, with plenty of restaurants, bars and public transport close by.

An Insider's view of Rapid7

What does your typical day look like?

For the majority of the day it’s a mix of weekly check-ins with various teams, project updates, and the occasional brainstorm.

When I’m not in meetings I’ve got headphones in while planning, writing, or designing — at my desk or perched somewhere around the office.

Grace

Senior Brand Storyteller

What are some things you learned at the company?

When we talk about being a moose and impact together, what we are saying is that we support each other on our journey forward. We actively look for ways to collaborate, strengthen our ideas and learn from each other, no matter what department you may be in at Rapid7.

David

Global Director of Sales Engineering

What are Rapid7 Perks + Benefits

Culture
Volunteer in local community
Once a year, Rapid7 offices across the globe close for the day so employees can volunteer.
Partners with Nonprofits
Friends outside of work
Eat lunch together
Intracompany committees
Open door policy
Team owned deliverables
Team based strategic planning
Group brainstorming sessions
Open office floor plan
Diversity
Dedicated Diversity/Inclusion Staff
Highly diverse management team
Rapid7 is led by a diverse management team that represent the security community we serve. We believe that we all have a responsibility to continuously improve our DE&I efforts.
Unconscious bias training
We believe in continuous learning, our in-house trainers conduct consistent diversity trainings. We advocate for diverse thinking and strive to cultivate a workforce that mirrors the best minds.
Someone's primary function is managing the company’s diversity and inclusion initiatives
Diversity Employee Resource Groups
We have so many amazing and organically created employee resource groups! These internal Rapid7 communities allow for an authentic experience where diverse employees and allies can come together.
Hiring Practices that Promote Diversity
We've taken the Parity Pledge, we reinforce strategic recruitment, we are committed to diversity partnerships, and we understand the importance in training around unconscious bias.
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Dental Benefits
Vision Benefits
Health Insurance Benefits
Life Insurance
Wellness Programs
Onsite Gym
Mental Health Benefits
Retirement & Stock Options Benefits
401(K)
401(K) Matching
Employee Stock Purchase Plan
Performance Bonus
Child Care & Parental Leave Benefits
Generous Parental Leave
Flexible Work Schedule
Remote Work Program
Our remote work program includes full-time remote for specific positions, Work remotely on occasion as needed.
Family Medical Leave
Vacation & Time Off Benefits
Unlimited Vacation Policy
Paid Volunteer Time
Our employees receive unlimited hours per year of paid volunteer time.
Paid Holidays
Paid Sick Days
Employees receive unlimited hours per year of paid sick leave.
Perks & Discounts
Casual Dress
Commuter Benefits
Company Outings
Game Room
Stocked Kitchen
Rapid7 has a fully stocked kitchen including unlimited snacks, coffee, tea and all of the flavored sparkling water you can handle.
Some Meals Provided
Employees get free lunch during quarterly in-office Town Halls and some team meetings.
Happy Hours
Fitness Subsidies
Home Office Stipend for Remote Employees
Professional Development Benefits
Job Training & Conferences
Diversity Program
Lunch and learns
Cross functional training encouraged
Promote from within
Continuing Education stipend
Variable.
Time allotted for learning
Online course subscriptions available
Paid industry certifications
More Jobs at Rapid7112 open jobs
All Jobs
Finance
Data + Analytics
Dev + Engineer
HR + Recruiting
Marketing
Operations
Product
Project Mgmt
Sales
Content
Data + Analytics
new
Boston
HR + Recruiting
new
Boston
Operations
new
Boston
Data + Analytics
new
Boston
Finance
new
Boston
HR + Recruiting
new
Boston
Sales
new
Boston
Operations
new
Boston
Data + Analytics
new
Boston
Project Mgmt
new
Boston
Operations
new
Boston
Operations
new
Boston
Data + Analytics
new
Boston
Sales
new
Boston
Operations
new
Boston
Developer
new
Boston
Marketing
new
Boston
Data + Analytics
new
Boston
Data + Analytics
new
Boston
Project Mgmt
new
Boston
HR + Recruiting
new
Boston
Developer
new
Boston
Developer
new
Boston
Operations
new
Boston
Developer
new
Boston
Developer
new
Boston
Data + Analytics
new
Boston
Operations
new
Boston
Developer
new
Boston
Marketing
new
Boston
Operations
new
Boston
Marketing
new
Boston
Project Mgmt
new
Boston
Operations
new
Remote
Operations
new
Boston
HR + Recruiting
new
Boston
Data + Analytics
new
Boston
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.
Save jobView Rapid7's full profileSee more Rapid7 jobs