Security Engineer Remote Jobs in Massachusetts (US)
This page tracks remote security engineer openings that are location-eligible for Massachusetts.
This page tracks remote security engineer openings that are location-eligible for Massachusetts.
Open jobs
4,046
Hiring companies this week
9
Salary sample
$60 - $220,000
Jobs added last hour
0
4046 Jobs
2026 Companies
Role Description AECOM is seeking a Transit Safety Security Specialist to lead project tasks for internal and external clients across the United States through a committed approach to risk management using processes developed by FTA and industry standards from APTA. The ideal candidate will be well-organized, a self-starter, and capable of completing any assignment with minimal oversight from senior management. This professional chosen for this key role will provide direction and guidance for multi-disciplined colleagues and junior staff for various tasks. Responsibilities for any project may include, but may not be limited to: - Development of PHAs/TVAs and associated mitigations/countermeasures - Holding workshops with multi-disciplinary groups/committees - CEL/CIL Development - Development of DCCCs/CSCCs - Direct interaction with agency clients and project managers - SSC document and report preparation - PTASP development, annual reviews, and updates - SSC peer reviews - SSC training for internal and external clients If you possess proven project task lead experience inclusive of Public Transportation Safety Certification Training Programs (PTSCTP, TSSP), State Safety Oversight (SSO) and successful experience in U.S. domestic Cybersecurity and SS, AECOM wants to talk to you! Qualifications - Minimum Requirements: - BA/BS + 6 years of related experience or demonstrated equivalency of experience and/or education. - U.S. citizenship - Ability to pass MVR check. - Possess or Ability to attain U.S. Security Clearance - Preferred Qualifications: - Public Transportation Safety Certification (PTSCTP and/or TSSP) - Certified Safety Professional (CSP) - Possess FTA TSSP Bus/Rail Certification - Working proficiency with CPTED Design Standards - Working proficiency and project delivery compliance involving ADA Design Standards - Working proficiency and project deliveries involving NFPA 130 Design Standards - Proven proficiency with the FTA Safety & Security Certification Process - Proven proficiency with APTA Safety & Security Certification Standards - Proven proficiency with PTASP Development and Annual Review Process - Proven proficiency with Safety & Security Certification Documentation - Proven proficiency and project deliveries involving Safety & Security Design Review - Proven proficiency and project deliveries involving Hazard and Vulnerability Analysis/Assessments. Requirements - U.S. citizenship required. - Relocation not offered. - Sponsorship is not offered for this position now or in the future. - All newly hired employees are required to attend an in-person Day 1 onboarding at an AECOM office location as a condition of employment. Benefits - Medical, dental, vision, life, AD&D, disability benefits - Paid time off, leaves of absences - Voluntary benefits, perks, flexible work options - Well-being resources, employee assistance program - Business travel insurance, service recognition awards - Retirement savings plan, employee stock purchase plan
Providing the best and most efficient layover experience for our clients and their team members.
Role Description The Director of Cybersecurity will lead API’s global cyber defense program, reporting to the SVP and CISO. This leader is accountable for security operations, threat detection, and incident response — and for building resilient defenses across API’s applications, infrastructure, networks, and cloud environments. A critical focus is cloud security. The Director will manage API’s security posture in AWS and Azure, embed security into product development, and lead the SOC MSSP partnership. This role requires deep technical expertise, executive-level communication, and the ability to translate threat intelligence into action. Key Responsibilities - Cyber Defense & Threat Intelligence: Own API’s cyber defense strategy across threat intelligence, detection, incident response, and product fraud and abuse. Translate adversarial research into actionable controls, detection rules, and response procedures. - SOC Operations: Lead and manage the SOC MSSP, ensuring 24x7x365 monitoring, investigation, and response. Set performance standards, drive operational accountability, and continuously improve SOC effectiveness. - Cloud Security: Manage API’s cloud security posture across AWS and Azure, applying defense-in-depth best practices to protect cloud-native and hybrid environments. - Security Engineering Partnership: Partner with engineering to embed security into product development from the ground up — ensuring secure-by-default practices across cloud-hosted workloads and applications. - Incident Response: Lead containment, recovery, and postmortem activities for security incidents. Establish measurable benchmarks to track program maturity and drive continuous improvement. - Frameworks & Architecture: Apply NIST, MITRE ATT&CK, and the Cyber Kill Chain to guide security architecture, detection strategy, and response procedures. Maintain current security architecture diagrams and documentation. - Metrics & Reporting: Develop and maintain scorecards that measure SOC effectiveness and organizational risk. Report regularly to security and business leadership with clear, actionable insights. - Automation & Innovation: Identify and implement automation technologies to improve threat detection, prevention, and response at scale. - Team Development: Empower and develop SOC analysts and team members, fostering a culture of accountability, continuous learning, and strong cybersecurity practice. Success Metrics - SOC performance metrics demonstrate measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR). - Cloud security posture scores improve consistently in AWS and Azure environments. - Security is embedded into the product development lifecycle with no critical vulnerabilities at release. - Incident response playbooks are documented, tested, and continuously refined. - High team engagement and development of SOC analyst capabilities. - Security risks are communicated clearly to executive leadership with actionable recommendations. Qualifications - 7–10+ years of progressive cybersecurity experience, with demonstrated leadership in security operations, threat detection, and incident response. - Proven track record managing a SOC or MSSP relationship, including 24x7 operational oversight and performance management. - Hands-on experience with AWS and Azure, including cloud security posture management and securing cloud-native and hybrid environments. - Strong background in threat intelligence and adversarial techniques, applying frameworks such as NIST, MITRE ATT&CK, and the Cyber Kill Chain. - Experience developing security metrics and scorecards for both operational teams and executive leadership. - Proven ability to lead incident response from containment through postmortem, with measurable program improvement benchmarks. - Background in security engineering and architecture — particularly designing defensible systems — is a plus. Technical Skills - Working knowledge of CASB, SASE, firewalls, VPN, IDS, endpoint security, DLP, EDR/AV, and SIEM. - Strong experience with Microsoft O365 security capabilities and administration. - Familiarity with automation technologies supporting threat detection, prevention, and response. Leadership & Competencies - Proven ability to lead, develop, and motivate technical teams including SOC analysts. - Communicates effectively at staff and executive levels — translating complex security risks into clear business context. - Balances security requirements with business operations and innovation, building credibility across technology and business units. - Organized, efficient self-starter capable of managing multiple priorities with minimal supervision. Education & Certifications - Bachelor’s degree in Cybersecurity, Computer Science, MIS, or equivalent experience; Master’s degree desirable. - Preferred certifications (not required): GSEC, GCIA, GCIH, GCFE, GCFA, CISSP, CISM, or CISA. Compensation $170,000 - $190,000 USD, Commensurate with experience. Other Duties Duties, responsibilities and activities may change at any time according to business needs. Work Environment This position operates in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines. Physical Demands The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. While performing the duties of this job, the employee is regularly required to talk or hear. The employee frequently is required to stand, walk; use hands to finger, handle or feel; and reach with hands and arms. AAP/EEO Statement Accommodations Plus International is an Equal Opportunity Employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, alienage or national origin, ancestry, citizenship status, age, disability or handicap, sex, marital status, veteran status, sexual orientation, genetic information, arrest record, or any other characteristic protected by applicable federal, state or local laws. Our management team is dedicated to this policy with respect to recruitment, hiring, placement, promotion, transfer, training, compensation, benefits, employee activities and general treatment during employment. Privacy Statement API may use the contact information you provide to communicate about this role, including via text message. See our Privacy Policy for details. By clicking "Apply" you agree to Rippling's Terms of Service / User Privacy Notice .
Baxter, founded in 1931, is an established global leader in the production of medical product development and manufacturing. This company has developed a vast p
Title: Senior Product Security Engineer Location: United States of America - Remote time type Full time job requisition id JR - 205862 Job Description: This is where your work makes a difference. At Baxter, we believe every person—regardless of who they are or where they are from—deserves a chance to live a healthy life. It was our founding belief in 1931 and continues to be our guiding principle. We are redefining healthcare delivery to make a greater impact today, tomorrow, and beyond. Our Baxter colleagues are united by our Mission to Save and Sustain Lives. Together, our community is driven by a culture of courage, trust, and collaboration. Every individual is empowered to take ownership and make a meaningful impact. We strive for efficient and effective operations, and we hold each other accountable for delivering exceptional results. Here, you will find more than just a job—you will find purpose and pride. Job Description Your role at Baxter At Baxter Healthcare Corporation, we invite a driven Senior Product Security Engineer who is passionate about contributing to healthcare improvements. This opportunity puts you on the frontline of cybersecurity, developing world-class products that touch millions of lives. Your responsibility will be essential in establishing cybersecurity standards and technologies for both present and new products, assuring that our solutions are consistently highly secure. This is where your expertise helps people Your expertise will be instrumental in helping people by ensuring the safety and security of our healthcare products. You will play a meaningful role in safeguarding sensitive data and preserving the privacy of our customers and patients. You will work alongside various groups during every stage of development to guarantee our products uphold the highest levels of security and privacy. Identifying possible threats, assessing security risks, and cooperating to address findings will be important parts of your role. What you'll be doing - Working together with the product development teams to establish cyber security requirements, plans, and policies. - Establish governance around vulnerability management in products. - Assist in responses to and recovery from a security breach in conjunction with other team members and business units. - Use tools to scan for and test possible product vulnerabilities; investigate security breaches. - Stay ahead of and advised about industry zero day discoveries and react to assess products. - Build technical documentation around the security of a product including threat modeling, privacy assessments, whitepapers, etc. - Participate in project planning and prioritisation of security related deliverables and activities. What you'll bring - Bachelor’s degree or equivalent experience in Computer Science or a related field desired. - 2+ years of secure software development life-cycle experience. - Experience developing or analyzing secure coding practices with technologies such as ASP.Net (C#), SQL Server, HTML, C++. - Experience in crafting secure networks, systems, and application architectures. - Certification in security such as CAP, CCSP, or equivalent preferred but not required. - Keen attention to detail, critical thinking, and analytical abilities. - Proven interpersonal and communication (verbal, written, presentation) skills. - Proven understanding of application security throughout the software life-cycle. - Experience in addressing OWASP Top 10 vulnerabilities. Baxter prioritizes accommodating flexibility in the workplace. This is reflected in our flexible workplace policy, which requires employees to be on-site a minimum number of days weekly. The policy supports in-person interaction and teamwork to further our Mission. It is governed by local legal standards and requirements. Baxter reserves the right to modify, suspend, or terminate the policy as business demands shift. We understand compensation is an important factor as you consider the next step in your career. At Baxter, we are committed to equitable pay for all employees, and we strive to be more transparent with our pay practices. The estimated base salary for this position is $96,000 - $132,000 annually. The estimated range is meant to reflect an anticipated salary range for the position. We may pay more or less than the anticipated range based upon market data and other factors, all of which are subject to change. Individual pay is based upon location, skills and expertise, experience, and other relevant factors. This position may also be eligible for discretionary bonuses. For questions about this, our pay philosophy, and available benefits, please speak to the recruiter if you decide to apply and are selected for an interview. Applicants must be authorized to work for any employer in the U.S. We cannot sponsor or transfer employment visas at this time. #LI-TV1 US Benefits at Baxter (except for Puerto Rico) This is where your well-being matters. Baxter offers comprehensive compensation and benefits packages for eligible roles. Our health and well-being benefits include medical and dental coverage that start on day one, as well as insurance coverage for basic life, accident, short-term and long-term disability, and business travel accident insurance. Financial and retirement benefits include the Employee Stock Purchase Plan (ESPP), with the ability to purchase company stock at a discount, and the 401(k) Retirement Savings Plan (RSP), with options for employee contributions and company matching. We also offer Flexible Spending Accounts, educational assistance programs, and time-off benefits such as paid holidays, paid time off ranging from 20 to 35 days based on length of service, family and medical leaves of absence, and paid parental leave. Additional benefits include commuting benefits, the Employee Discount Program, the Employee Assistance Program (EAP), and childcare benefits. Join us and enjoy the competitive compensation and benefits we offer to our employees. For additional information regarding Baxter US Benefits, please speak with your recruiter or visit our Benefits site: Benefits | Baxter Equal Employment Opportunity Baxter is an equal opportunity employer. Baxter evaluates qualified applicants without regard to race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, protected veteran status, disability/handicap status or any other legally protected characteristic. Know Your Rights: Workplace Discrimination is Illegal Reasonable Accommodations Baxter is committed to working with and providing reasonable accommodations to individuals with disabilities globally. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the application or interview process, please click on the link here and let us know the nature of your request along with your contact information. Recruitment Fraud Notice Baxter has discovered incidents of employment scams, where fraudulent parties pose as Baxter employees, recruiters, or other agents, and engage with online job seekers in an attempt to steal personal and/or financial information. To learn how you can protect yourself, review our Recruitment Fraud Notice.
• Improve Indico’s technical security posture across AWS, Kubernetes, CI/CD, product security, internal systems, and incident response. • Partner with the CISO and CTO to turn security priorities into practical technical controls, standards, reviews, and operating processes. • Review Engineering work against security standards, with authority to request changes where needed. • Partner with Engineering on AWS security controls, including IAM, networking, account structure, logging, encryption, key management, backups, production access, and customer-dedicated environments. • Review and improve Kubernetes and container security controls, including workload identity, RBAC, network boundaries, image security, runtime monitoring, and deployment patterns. • Define and improve secure CI/CD patterns, including GitHub permissions, branch protections, privileged workflows, secrets handling, release controls, and deployment access. • Define and oversee processes for vulnerability management, committed-secret response, secure development, incident response, and access control while Engineering, Platform, IT/Ops, and system owners operate them in their domains. • Provide product security support, including secure design review, threat modeling for sensitive features, scanner tuning, and high-risk change review. • Improve detection and response coverage across tools such as CloudTrail, GuardDuty, CrowdStrike, SIEM/logging platforms, vulnerability scanners, and secrets detection. • Own day-to-day security monitoring and response operations, including alert routing, triage expectations, escalation paths, and detection improvements. • Coordinate technical containment during security incidents across Engineering, Platform, IT/Ops, and leadership. • Maintain incident response runbooks and partner with the CISO on severity, executive escalation, counsel/compliance coordination, and customer communication strategy. • Create practical security guidance, standards, procedures, and runbooks for security-sensitive work such as production access, secrets handling, vulnerability remediation, incident response, customer data handling, and secure engineering. • Maintain reusable technical security documentation, standard responses, and evidence packages for customer due diligence and compliance support. • Evaluate security tools and vendors with a focus on technical coverage, operational fit, and reducing manual work. • Build or sponsor lightweight automation, checks, dashboards, and workflows that make security controls repeatable.
Addiction Treatment & Healing. Aegis. Recovery Works. HealthQwest. And More. A Pinnacle Family of Companies.
• Serve as Pinnacle's cybersecurity leader and Security Officer while overseeing enterprise networking and infrastructure security initiatives. • Develop and execute Pinnacle's multi-year cybersecurity strategy and roadmap. • Lead information security governance, risk management, compliance, and security operations. • Direct enterprise security monitoring and incident response practices • Conduct security assessments, audits, and risk mitigation initiatives. • Drive security awareness and best practices across the organization. • Partner with Compliance and business leaders to maintain a strong security culture. • Manage and optimize enterprise security technologies including: SIEM platforms, Endpoint Protection (EPP), Data Loss Prevention (DLP), Firewalls, Vulnerability Management, PKI, RADIUS, Network Access Control (NAC). • Lead enterprise LAN, WAN, and wireless networking strategy. • Design and implement scalable, resilient network solutions. • Drive modernization and simplification initiatives across multi-site environments. • Ensure secure connectivity for all Pinnacle facilities and applications. • Lead security strategy and governance for Microsoft 365, Microsoft Azure, Conditional Access, Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), Microsoft Intune, Windows AutoPilot. • Lead and mentor a team of security and network engineers. • Manage vendor partnerships, procurement, and technology investments. • Establish effective escalation and on-call support processes. • Communicate project status and strategic initiatives to executive stakeholders.
• Provide Information Assurance Engineering Support for the Information Technology R&D program. • Analyze emerging R&D Information Systems and Operational Technology. • Review existing and proposed policies for compliance. • Develop standards for implementation of IA/Cybersecurity solutions. • Conduct risk assessments for R&D projects.
• performs a variety of routine project tasks applied to specialized Cybersecurity problems • involves integration of electronic processes or methodologies to resolve total system problems • analyzes information security requirements • provides security engineering support for planning, design, development, testing, demonstration, and integration of information systems
Role Description The Cybersecurity Assessment & Authorization (A&A) Subject Matter Expert (SME) executes DoD/DLA cybersecurity processes to authorize information systems, maintain authorization of information systems, and serves as a Subject Matter Expert for systems undergoing the Risk Management Framework (RMF) process. The Cybersecurity Assessment & Authorization SME possesses an understanding of how security controls identified in NIST SP 800-53 apply to the process of assessing and authorizing a large organization's IT infrastructure such as DLA, including: - Large and small enclaves - Cloud Hosted Services - Operational Technology - AIS applications - Outsourced IT processes The SME determines the residual risk of identified vulnerabilities and evaluates the potential impact on a system's current or future authorization while briefing senior management on the progress and results of systems undergoing the RMF process. Qualifications - Five (5) years of relevant C&A experience - Risk Management Framework (RMF) and NIST C&A experience - DoD cybersecurity experience - Experience assessing security controls and conducting authorization reviews for large, complex organizations - Experience supporting Authorization to Operate (ATO) packages and RMF documentation preferred - DoD Approved 8570/8140 Baseline Certification: Category IAM Level III - Active Secret clearance with a Moderate Risk, Non-Critical Sensitive, Tier 3 (T3)/NACLC/ANACI investigation at the time of proposal submission Location Although position is remote, candidates must reside within 150 miles of one of the following DLA locations: - Battle Creek, MI - Columbus, OH - New Cumberland, PA - Philadelphia, PA - Fort Belvoir, VA (HQ) - Richmond, VA
IT & Engineering for a better tomorrow.
• Lead the assessment, scoping, and architectural design of strategic RACF and USS security project solutions • Define target-state architectures and technical designs • Support deployment of security solutions • Assess technical feasibility and trade-offs of proposed solutions • Collaborate with various teams to gather requirements • Create and maintain security monitoring, automation, and reporting solutions • Monitor, analyze, and report on key performance indicators
• You will own the following areas: Internal IT, Security, Governance, Risk & Compliance, and Enterprise incident response. • Set strategy and own the roadmap while being comfortable with hands-on tasks. • Report directly to the CEO and lead an existing SecOps team. • Build something meaningful from the ground up and lead the migration of our IT function from our MSP to an in-house team.
4,036more opportunities are still waiting for you.Log in now and take your next shot before someone else does.
Azure, Cyber Security, AWS, Firewalls, SSO, Observability/Monitoring