Responsibilities
- Oversee and implement secure, scalable, and highly available cybersecurity solutions across diverse platforms, with a primary focus on cloud-based environments.
- Architect, deploy, and maintain security infrastructure components, including Intrusion Detection/Prevention Systems (IDS/IPS), Security Information and Event Management (SIEM) platforms, Endpoint Detection and Response (EDR) solutions, and Web Application Firewalls (WAFs).
- Collaborate with development and engineering teams to integrate security into the software development lifecycle through activities such as code reviews, threat modeling, and vulnerability assessments.
- Develop and maintain CI/CD pipelines with a strong emphasis on security checks, tests, and analysis of code and dependencies.
- Manage advanced security tools (e.g., SAST, DAST, IAST) and endpoint protection solutions to proactively detect, monitor, and respond to threats and security incidents.
- Conduct risk assessments, threat analyses, and forensic investigations, addressing vulnerabilities and responding to security incidents in a timely and effective manner.
- Contribute to the development, maintenance, and execution of incident response plans, ensuring readiness for potential security events.
- Stay current with emerging technologies and industry trends, offering expert guidance on best practices to enhance the organization’s security posture.
Requirements
- 5+ years of advanced technical experience in cybersecurity or security engineering roles.
- Comprehensive understanding of cloud security services, including AWS (e.g., IAM, Security Groups, GuardDuty) and GCP (e.g., Cloud Armor, Security Command Center).
- Experience with Cloudflare for DNS, CDN, and WAF services.
- In-depth knowledge of security systems, intrusion detection, encryption technologies, network protocols, and best practices for securing cloud environments.
- Proficiency with security tools such as vulnerability scanners, SIEM, DAST, and intrusion detection systems (e.g., Wazuh, Zeek, Suricata), as well as endpoint protection solutions (e.g., Sentinel One).
- Expertise in vulnerability assessments and incident response processes.
- Familiarity with security standards (e.g., OAuth, OpenID Connect, SSL/TLS) and compliance frameworks (e.g., ISO 27001, NIST 800-61, SANS, SOC 2).
- Proficiency in scripting languages such as Python, PowerShell, or Bash for security automation and tool integration.
- Relevant certifications such as CISSP, OSCP, or CISM are highly preferred.
- Strong problem-solving skills with the ability to respond effectively to security incidents and vulnerabilities.
Top Skills
Similar Jobs
About Us
At Hiya, we’re revolutionizing voice communication. Our mission is to modernize voice with intelligence for security and productivity
Since 2015, when we introduced the first mobile caller ID and spam-blocking apps, we’ve been at the forefront of voice intelligence innovation. In 2016, we partnered with Samsung and AT&T ...
Dandy is transforming the massive and antiquated dental industry—an industry worth over $200B. Backed by some of the world’s leading venture capital firms, we’re on an ambitious mission to simplify and modernize every function of the dental practice through technology. As we expand our reach globally, Dandy is building the operating system for dental offices around the world—empowering clinicians and their teams with te...
What you need to know about the Boston Tech Scene
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories