This is a contract position for a Security Assurance Engineer located in Boston, Massachusetts. The role is available for a duration of 6 or more months and will focus on defining and validating security controls, coordinating testing activities, and guiding stakeholders through vulnerability remediation and risk management in a complex application environment.
Responsibilities
- Define security requirements and review application architectures, data flows, integrations, and technical controls
- Coordinate SAST, DAST, and penetration testing activities, and validate remediation or retest evidence
- Perform risk analysis and vulnerability triage, develop remediation plans, implement or support technical remediation, and track findings to closure
- Implement security controls and guide agency or business personnel on control ownership, operation, evidence, exceptions, and ongoing management
- Document security findings, residual risk, control decisions, and production-readiness recommendations
- Coordinate security work across project teams, vendors, shared-service organizations, and managed security service providers
- Manage concurrent work against milestones, release schedules, acceptance criteria, and project reporting requirements
- Communicate technical risks clearly to both technical and non-technical stakeholders
- Work independently, maintain accurate evidence, and elevate risks or blockers promptly
Qualifications
- Required
- Five or more years of professional experience in application security, cloud security, product security, security engineering, or a closely related field
- Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field. A Certified Information Systems Security Professional (CISSP) credential, or a comparable security certification, together with relevant professional experience will be considered equivalent to the bachelor's degree requirement
- Demonstrated experience defining security requirements and reviewing application architectures, data flows, integrations, and technical controls
- Experience coordinating SAST, DAST, and penetration testing and validating remediation or retest evidence
- Demonstrated experience performing risk analysis and vulnerability triage, developing remediation plans, implementing or supporting technical remediation, and tracking findings to closure
- Experience implementing security controls and guiding agency or business personnel on control ownership, operation, evidence, exceptions, and ongoing management
- Working familiarity with Jira, Salesforce-based applications, Tenable Cloud, Veracode static and dynamic testing, GitHub, and GitHub Copilot or comparable approved tools
- Experience using AI-assisted capabilities responsibly for vulnerability testing, source-code or configuration review, finding analysis, or remediation planning
- Working knowledge of identity, data protection, logging, deployment, cloud, and infrastructure controls for complex applications
- Experience documenting security findings, residual risk, control decisions, and production-readiness recommendations
- Experience coordinating security work across project teams, vendors, shared-service organizations, and managed security service providers
- Ability to manage concurrent work against milestones, release schedules, acceptance criteria, and project reporting requirements
- Excellent written and verbal communication skills, including the ability to explain technical risks to technical and non-technical stakeholders
- Ability to work independently, maintain accurate evidence, and elevate risks or blockers promptly
- Preferred
- Experience securing AWS, Salesforce, public-facing digital services, or regulated application environments
- Experience supporting legacy-platform modernization, cloud re-platforming, or complex application integrations
- Experience working with AI solutions and infrastructure, including RAG pipelines, LLM models, or voice models
- Familiarity with security considerations for AI-enabled services, document uploads, constituent data, and regulated workflows
- Hands-on experience using Jira, Tenable Cloud, Veracode, GitHub, GitHub Copilot, and Salesforce-based applications in an enterprise or public-sector delivery environment
- Knowledge of National Institute