Suffolk Construction Logo

Suffolk Construction

Security Engineer

Posted 2 Days Ago
Be an Early Applicant
In-Office
Boston, MA, USA
Senior level
In-Office
Boston, MA, USA
Senior level
Supports enterprise cybersecurity through security configuration, identity and access management, vulnerability management, cloud security, audits, penetration testing, risk analysis, security monitoring, and remediation coordination. The role diagnoses escalated security issues, maintains dashboards and metrics, supports compliance initiatives, collaborates with technical and business teams, and mentors Help Desk Analysts. Responsibilities span Azure, AWS, on-premises infrastructure, applications, and enterprise security systems.
The summary above was generated by AI
Overview

About Suffolk  


Suffolk is a national enterprise that builds, innovates, and invests. We provide value across the entire project lifecycle through our core construction management services and complementary business lines in real estate investment, design, self-perform construction, and technology start-up investment (Suffolk Technologies). By integrating data, artificial intelligence, and advanced technology through our Seamless Platform, we connect design, construction, and operations to deliver smarter, more predictable results and redefine how America builds. 


Suffolk – America’s Contractor – is a national company with more than $9 billion in annual revenue, 3,000 employees, and 17 offices, including Boston (headquarters), New York City, Miami, West Palm Beach, Tampa, Estero, Dallas, Los Angeles, San Francisco, San Diego, Las Vegas, Herndon, U.S. Virgin Islands, and other key markets. Suffolk manages some of the most complex and transformative projects in the country, serving clients across healthcare, life sciences, education, gaming, aviation, transportation, government, mission critical, and commercial sectors. Suffolk is privately held and is led by founder, chairman and CEO John Fish. Suffolk is ranked #8 on ENR’s list of “Top CM-at-Risk Contractors.” For more information, visit www.suffolk.com and follow Suffolk on Facebook, Twitter, LinkedIn, YouTube, and Instagram. 


At Suffolk, we believe that our total rewards program should offer you and your family the support you need when it matters most. That’s why we have created a program that provides employees with access to a wide variety of options that can be personalized to support you and your loved ones physically, emotionally, and financially. 


Benefits include, competitive salaries, auto allowances and gas cards for certain roles, access to market leading medical and emotional and mental health benefits, dental, and vision insurance plans, virtual care options for physical therapy and primary care, generous paid time off, 401k plan with employer match and access to expert financial resources, company paid and voluntary life insurance, tax deferred savings accounts, 10 backup daycare days each year, short- and long-term disability, commuter benefits and more.  For more information, click here. 

Responsibilities

Roles and Responsibilities

  • Diagnose and solve Level 2 issues related to security configurations and platforms as escalated by Level 1 support
  • Support standards for the classification, administration, and lifecycle management of Suffolk data, including helping apply established data handling requirements across systems and business processes.
  • Serve as a key security resource for Suffolk corporate applications by helping assess risks, support secure configurations, review access controls, and coordinate remediation with application owners and technical teams.
  • Participate in independent security audits, vulnerability scans, and penetration tests on Suffolk infrastructure to ensure confidentiality, integrity, and availability of Suffolk data.
  • Help enforce Suffolk identity and access management policies and procedures for on-premises and cloud-based services by supporting access reviews, role-based access controls, privileged access controls, secure authentication practices, and remediation of access-related findings.
  • Support identity manageability, access governance, provisioning, security, and privacy. Implement and manage solutions for secure identity through third-party providers.
  • Provide operational assistance with vulnerability scanning, gap analysis, and security initiatives. Monitor findings, validate risk and ownership, triage remediation priorities, track corrective actions, and report progress for Suffolk systems.
  • Help identify, investigate, and resolve security issues from development through operations by collaborating with application, infrastructure, service desk, and business teams to understand root causes, document findings, and coordinate practical remediation.
  • Maintain Suffolk information security dashboards, review security metrics, and perform risk analysis to help management understand trends, prioritize remediation, and track progress against security initiatives.
  • Support Suffolk’s enterprise security systems and manage comprehensive, data-driven review processes to enhance critical security infrastructure
  • Mentor Help Desk Analysts, developing skillsets through exposure to security administration while promoting Suffolk information security standards.
  • Remain informed about evolving security challenges in IT and how they affect Suffolk. Maintain an understanding of the current threat and attack landscape, latest security trends, and Suffolk information systems.
  • Support Suffolk’s information security posture in accordance with Suffolk’s evolving business requirements by contributing to security operations, control improvements, and risk reduction initiatives.
  • Apply security controls and operational practices across enterprise cloud environments, including identity configuration, logging and monitoring, secure access, vulnerability remediation, and support for cloud workload protection in Azure, AWS, or similar platforms.

Skills and Knowledge

  • Strong interpersonal skills, including collaboration, communication, negotiation, and mediation
  • Strong peer influence skills with the ability to enable secure solutions while maintaining effective working relationships with business partners.
  • Excellent written documentation ability, including the flexibility to deliver varied content to varied audiences
  • Demonstrated experience designing, installing, and configuring enterprise security solutions while meeting enterprise architecture, security, and privacy needs.
  • Technical foundation in systems security and network security. Experience with pen testing, security scanning, threat modeling, and incident management are desirable.
  • Familiarity and experience with industry standard enterprise security solutions such as Microsoft security tools, vulnerability management platforms, cloud security platforms, and security monitoring solutions.
  • Familiarity and experience with information security frameworks (NIST, ISO 27001, etc.) and understanding of security configuration guides (DISA STIG, CIS, etc.)
  • Familiarity and experience with current regulatory and contractual security requirements and the ability to support organizational compliance efforts, including PCI, MA 201 CMR 17.00, CCPA, HIPAA, and similar requirements.
  • Strong working knowledge of endpoint and server operating systems (e.g. Windows, MacOS, Linux) and relevant security risks, controls, and vulnerabilities.
  • Strong collaboration skills with development, engineering, and DevOps teams, enabling the successful integration of security requirements, controls, and automation into software delivery pipelines. 
Qualifications
  • BS degree in computer science, information systems management, or a related technical discipline or the equivalent combination of education, technical training, or work/military experience.
  • At least one industry certificate is desirable (CISSP, CISA, etc.)
  • 3+ years of experience with enterprise information security, preferably within complex organizations.
  • 3+ years of experience with enterprise cloud-based solutions (Azure, AWS, etc.)
  • 3+ years of experience with large, distributed systems.
  • At least 5 years of relevant work experience in IT and/or information security required, including hands-on experience supporting enterprise systems, security tools, or security operations.
  • Project management and audit experience desired.
Working Conditions

While performing the duties of this job, the employee is regularly required to sit for long periods of time; talk or hear; perform fine motor, hand and finger skills in the use of a keyboard, telephone, or writing. The employee is frequently required to stands; walk; and reach with arms and/or hands. Specific vision abilities include close vision, distance vision, depth perception and the ability to adjust focus. The employee will spend their time in an office environment with a quiet to moderate noise level. Job site walking.

EEO Statement

Suffolk provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, sexual orientation, pregnancy or maternity, national origin, citizenship, genetic information, disability, protected veteran, gender identity, age or any other status protected by law.  This policy applies to recruiting, hiring, transfers, promotions, terminations, compensation, benefits, and all other terms and conditions of employment.  Suffolk will not tolerate any unlawful discrimination toward, or harassment of, applicants or employees by anyone at Suffolk, or anyone working on behalf of Suffolk.

Compensation Information

Where required by law, pay ranges can be found in Suffolk's job postings. Base Salary for this position is just one component of Suffolk’s total rewards package for employees. Actual salaries may be based on several factors including, but not limited to, a candidate's skill set, experience, education and other qualifications. Suffolk offers a comprehensive benefits package as part of its overall total rewards strategy. Salary ranges are reviewed regularly to reflect market trends.

About Suffolk

Suffolk is a national enterprise that builds, innovates, and invests. We provide value across the entire project lifecycle through our core construction management services and complementary business lines in real estate investment, design, self-perform construction, and technology start-up investment (Suffolk Technologies). By integrating data, artificial intelligence, and advanced technology through our Seamless Platform, we connect design, construction, and operations to deliver smarter, more predictable results and redefine how America builds. 


Suffolk – America’s Contractor – is a national company with more than $9 billion in annual revenue, 3,000 employees, and 17 offices, including Boston (headquarters), New York City, Miami, West Palm Beach, Tampa, Estero, Dallas, Los Angeles, San Francisco, San Diego, Las Vegas, Herndon, U.S. Virgin Islands, and other key markets. Suffolk manages some of the most complex and transformative projects in the country, serving clients across healthcare, life sciences, education, gaming, aviation, transportation, government, mission critical, and commercial sectors. Suffolk is privately held and is led by founder, chairman and CEO John Fish. Suffolk is ranked #8 on ENR’s list of “Top CM-at-Risk Contractors.” For more information, visit www.suffolk.com and follow Suffolk on Facebook, Twitter, LinkedIn, YouTube, and Instagram. 


At Suffolk, we believe that our total rewards program should offer you and your family the support you need when it matters most. That’s why we have created a program that provides employees with access to a wide variety of options that can be personalized to support you and your loved ones physically, emotionally, and financially. 


Benefits include, competitive salaries, auto allowances and gas cards for certain roles, access to market leading medical and emotional and mental health benefits, dental, and vision insurance plans, virtual care options for physical therapy and primary care, generous paid time off, 401k plan with employer match and access to expert financial resources, company paid and voluntary life insurance, tax deferred savings accounts, 10 backup daycare days each year, short- and long-term disability, commuter benefits and more.? For more information, click?here. 


HQ

Suffolk Construction Boston, Massachusetts, USA Office

65 Allerton Street, Boston, MA, United States, 02119

Similar Jobs

44 Minutes Ago
Remote or Hybrid
US
160K-180K Annually
Senior level
160K-180K Annually
Senior level
Cloud • eCommerce • Information Technology • Professional Services • Software
Owns Cleo’s application and product security strategy across SaaS and customer-hosted products. Responsibilities include maturing the SSDLC, threat modeling, security scanning, vulnerability triage, penetration testing, coordinated disclosure, CVE management, product security controls, customer-facing advisories, and NIST CSF evidence. The role also leads security enablement, roadmap prioritization, AI security reviews, and hands-on exploit reproduction and patch validation while guiding engineers and security partners.
Top Skills: APIsAWSBurp SuiteCi/CdContainer ScanningCyclonedxEksGitGithub Advanced SecurityGoIac ScanningJavaJenkinsKubernetesNist Ai RmfNist CsfOwasp AsvsOwasp SammOwasp Top 10 For Llm ApplicationsPolicy-As-CodePythonRbacSAMLSastScaSecrets ScanningSemgrepSlsaSnykSpdxSsoTerraformTypescriptVex
3 Days Ago
Hybrid
Boston, MA, USA
192K-240K Annually
Senior level
192K-240K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software • Cybersecurity • Data Privacy
Secures Snyk’s GCP and AWS cloud platforms through threat modeling, IAM hardening, Kubernetes and container security, Terraform and pipeline fixes, CSPM integration, and secure configuration baselines. Uses AI coding agents and MCP integrations to scale infrastructure remediation while reviewing changes for unsafe defaults, excessive permissions, and agent-related risks. Works consultatively with platform teams to implement and measure security improvements.
Top Skills: Ai Coding AgentsArtifact RegistryAWSBinary AuthorizationCi/CdClaude CodeCloud InfrastructureContainer SecurityCspmEksGCPGitopsGkeIamKubernetesMcp ServersRbacTerraformWorkload Identity Federation
3 Days Ago
Hybrid
Boston, MA, USA
99K-120K Annually
Mid level
99K-120K Annually
Mid level
Fintech • Payments • Software
Designs and automates application, cloud, infrastructure, and AI security controls across CI/CD pipelines and public-cloud environments. Conducts penetration testing, red teaming, source-code audits, and cloud exploitation. Leads incident containment, forensic collection, threat detection engineering, and SIEM automation. Partners with software engineering and SRE teams on secure architecture, Zero Trust, container security, and Infrastructure-as-Code scanning while mentoring junior engineers and aligning controls with financial-sector compliance standards.
Top Skills: AWSClaudeDockerDoraEdrGitlab Ci/CdJavaKubernetesLlm ApisMitre Att&CkNode.jsOauth2OidcPcapPci-DssPythonRuby On RailsSAMLSIEMSoc 1Soc 2TerraformZero Trust Iam

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account