Security Sr. Engineer

MFS International Australia Pty Ltd

Boston (MA)

Hybrid

USD 88,000 - 126,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

MFS seeks a Sr. Security Engineer to implement and maintain security measures protecting personnel, property, and information assets. You will contribute across enterprise security domains, support automation, and collaborate with stakeholders to strengthen controls.

Required 3+ years in information security, CC, and strong knowledge of AD, cloud platforms, databases, and encryption. The role favors hybrid on-site work and ongoing professional development in a regulated environment.

Qualifications

  • Bachelor’s degree or equivalent in a security-related field.
  • 2–5+ years technology experience with 3+ years in Information Security-specific work.
  • ISC2 Certified in Cybersecurity (CC) required; CISSP preferred; CISM/CRISC optional.
  • Solid demonstrated ability and application of core concepts, frameworks and practices of enterprise-class security programs.
  • Experience with identity and access management, cloud and application security, incident response and vulnerability management.

Responsibilities

  • Subject matter expert in one or more cyber security disciplines, guiding security controls and monitoring across enterprise systems.
  • Support automation, scripting, and workflow improvements to reduce manual effort and improve data quality.
  • Assist with governance, risk, and compliance activities and maintain security documentation.

Skills

Active Listening
Critical Thinking
Problem Solving
Attention to detail
Collaboration
Effective communication
Time Management

Education

Bachelor’s degree or equivalent experience in a related security field

Tools

Active Directory
Domain Controllers
Azure Cloud
AWS Cloud
SaaS/PaaS/IaaS
Windows OS
Unix/Linux OS
Oracle
SQL Server

Job description

At MFS, you will find a culture that supports you in doing what you do best. Our employees work together to reach better outcomes, favoring the strongest idea over the strongest individual. We put people first and demonstrate care and compassion for our community and each other. Because what we do matters – to us as valued professionals and to the millions of people and institutions who rely on us to help them build more secure and prosperous futures.

THE ROLE

A technical security resource responsible for implementing, and maintaining security measures to protect personnel, property, and information assets. This role combines demonstrated abilities in various information security disciplines across multiple security domains with solid understanding of security technologies and platforms. The role also requires a developed understanding of modern technology, with a solid understanding of related IT disciplines and how they interoperate. Some characteristics include troubleshooting efforts of multiple security technologies and controls, developing control design(s), supporting monitoring efforts, maintaining a solid understanding of the field, its practices and controls, and its related technologies, and staying current of current technologies, threats, vulnerabilities and exposures. The Sr. Security Engineer is an active participant and contributor multiple security-related activities and may participate one or more program(s), project(s), scope of work, or processes that drive results. This role requires some oversight and guidance.

WHAT YOU WILL DO

Subject matter resource in one or more disciplines in the field of Cyber/Information Security, while maintaining a solid understanding of the field, its programs, practices and controls, and its related technologies, threats, vulnerabilities, risks and exposures. Influences the implementation, integration and maintenance of enterprise-class security programs and solutions with quality outcomes, such as incident response, identity and access management, cloud, application and network security, key and certificate management, vulnerability management, threat detection, security information and event management and able to quickly learn and adapt solutions as introduced to the security technology portfolio. Support efforts for the assessment, establishment and monitor countermeasures that protect, detect and/or deter when an unauthorized and/or suspicious activity. Works closely with senior security practitioners and technology and business groups to assess, identify, design and implement security controls, processes, procedures and solutions within risk tolerance. Supporting the assessment, identification, design and implementation of approved methods and technologies to automate manual security-related tasks, improving efficiency and quality wherever practicable and appropriate. Supports and administers enterprise identity, authentication, access governance, privileged access, and Application Identity Management (AIM) processes, helping ensure appropriate access controls are maintained throughout the identity lifecycle. Monitors and analyzes database access and activity, privileged user activity, and sensitive data access patterns to identify unauthorized, suspicious, or policy-violating behavior. Maintains and supports security governance, risk, compliance, policy, and control management processes, including the Archer control registry, control validation, evidence collection, issue tracking, and audit support. Develops and implements security automation, scripting, orchestration, reporting, and workflow improvements that reduce manual effort, improve data quality, and strengthen control effectiveness. Evaluates and applies artificial intelligence and machine learning capabilities in accordance with approved AI policy and governance to enhance security operations, monitoring, analysis, investigation, and operational efficiency, while assessing and helping defend against AI-related risks. Delivers peer-reviewed security risk assessment and due diligence outcomes to methodically analyze technology, solutions and processes, identifying risks from both a technical and business perspective, and recommending strategies to mitigate within risk tolerances. Assists with security investigations according to documented procedures and management’s directives. Maintains confidentiality in these matters and works to ensure the confidentiality of other information which is encountered during the discharge of security responsibilities. Advances projects of moderate complexity, having broad goals and agreed upon outcomes, under some supervision. Accountable for meeting assigned performance and project objectives, including timelines and budget, provides innovative suggestions for solutions and executes plans. Effectively communicates to supervisor, often technical, cyber security concepts clearly and accurately through non-technical means, to ensure that all stakeholders are suitably informed. Collaborates with key stakeholders to assess and resolve security-related problems within risk appetite. Continuously learns, grows and adapts knowledge of security practices, technologies and MFS business practices with the intent to analyze, recommend and implement improvements for the reliability, scalability, performance, and security as appropriate.

WHAT WE ARE LOOKING FOR

Bachelor’s degree or equivalent experience in a related security, technical field.

2-5+ years of technology experience with 3+ years of Information Security-specific work experience is required.

ISC2 Certified in Cybersecurity (CC) CompTIA Security+ CISSP preferred, with CISM, CRISC optional

Professional Knowledge and Experience Solid demonstrated ability and application of core concepts, frameworks, practices and procedures of enterprise-class security program, solutions and technologies, such as incident response, threat management vulnerability, compliance, cloud and application security and identity and access, etc.

Solid demonstrated skill and/or application of modern technologies and associated administrative, technical, and physical controls for Active Directory, Domain Controllers, Cloud (Azure, AWS, SaaS, PaaS, IaaS), Window and Unix/Linux OS, Oracle and SQL server, Database architecture, encryption, end-point devices, and basic networking Firm demonstrated understanding of basic risk assessment methodology concepts, such as risk review, challenge, acceptance, mitigation strategies, and risk appetite associated with Enterprise Risk Management, NIST Cyber Security Framework Firm demonstrated understanding of basic technology-related concepts, frameworks and practices (e.g., Incident, Problem and Change Management, ITIL) Firm demonstrated understanding of project management concepts and able to manage multiple tasks and activities simultaneously (e.g., task identification, interdependencies, prioritization, time management, delivering quality outcomes) Demonstrated understanding of business practices, processes and procedures of a particular business process and/or application (e.g., transfer agency, trading, research, portfolio management, distribution, etc.) Solid demonstrated ability and application of identity and access management concepts, including authentication, authorization, privileged access, Application Identity Management (AIM), access governance, role-based access controls, service and application accounts, and identity lifecycle management. Solid demonstrated skill and/or application of database security concepts, database access and activity monitoring, sensitive data protection, security logging, alert analysis, reporting, and investigation techniques. Experience supporting governance, risk, compliance, policy management, the Archer control registry, control assessments, issue management, audit evidence, and regulatory or client assurance activities. Experience designing, implementing, or supporting security process automation, scripting, orchestration, integrations, data analysis, dashboarding, and workflow optimization. Demonstrated understanding of artificial intelligence and machine learning technologies, responsible use requirements, AI governance, data protection considerations, and emerging security risks and opportunities associated with AI-enabled systems. Experience analyzing and interpreting security telemetry, identity and access activity, database activity, user behavior, control data, and operational metrics to identify trends, anomalies, risks, and opportunities for improvement.

Core Competencies (demonstrated)
  • Active Listening
  • Critical Thinking
  • Problem solving
  • Attention to detail
  • Collaboration and teamwork
  • Effective communication
  • Time Management
  • Taking initiative
  • Conflict resolution
  • Coaching Mindset
  • Tactical Mindset

Must be in office at a minimum during the 3 core days (Tuesday, Wednesday and Thursday) May be required to work at off-hours such as nights and weekends to prevent interruption to business operations.

PREFERRED SKILLS, QUALIFICATIONS AND EXPERIENCE

5+ year of technology experience independent of the 3+ years of Information Security-specific work experience May have held previous positions, such as: Security engineer Engineer within a technology discipline where some security aspects were within role Professional designations available that certify an individual’s potential ability to apply knowledge and execute at this level: CISSP (Optional but required once tenure qualification met for certification. Firm will sponsor.) ISSEP (optional) SSCP (optional) GIAC (required) Core Competency considerations: Strong analytical, problem solving, writing and organizational skills; Adapts swiftly to changing priorities, showing flexibility and resilience in a fast-paced work environment. Demonstrated ability to interact, build relationships, and communicate well with members of team and management; makes and delivers effective presentations. Strong interpersonal, communication, and negotiation skills. Demonstrates solid financial skills, strategic and tactical planning. Proven ability to manage projects efficiently and effectively and to meet project deadlines Ability to multitask and shift priorities when necessary.

REQUIRED LICENSES AND CERTIFICATIONS

ISC2 Certified in Cybersecurity (CC) (required)

CompTIA Security+ (required)

Base Salary Range: $88,000.00 - $126,000.00 This position is eligible for competitive incentive bonus. At MFS, we believe in fair and transparent compensation. For that reason, we’re including the salary range for this position. This range reflects our good‑faith expectation for what we’ll pay depending on the candidate’s experience, training and education. In addition to the salary, we also offer significant and competitive incentive compensation based on both individual and company performance.

Other components of our Total Rewards Package include:

  • MFS contributes an amount equal to 15% of your base salary to your retirement account that is separate from the company -sponsored 401(k)
  • Education Assistance: MFS contributes $100 monthly up to $10,000 lifetime maximum directly to loan provider
  • Education Assistance: Tuition reimbursement up to $8,000 annually
  • Education Assistance: Access to discounted tutors and college coaches
  • Generous time off and fully paid leaves including 20-weeks for maternity, 12-weeks for parental and caregiver leaves
  • Choice of medical and dental plans and an and an employer contribution into the Health Savings Account
  • Tax deferred commuter benefits & flexible spending accounts (medical & dependent care)
  • Wellness Programs: Robust wellness webinars, employee assistance program with a focus on mental health, subsidized fitness benefit via Wellhub (formerly Gympass), where you can workout at gyms, studios and boutique fitness locations near you, join virtual personal training sessions and access a wide variety of well-being apps

Our compensation philosophy is to pay competitively for talent while ensuring equity across employees performing comparable work. We are committed to transparency – if you have questions about how we arrived at this range or what additional benefits and bonus opportunities come with the role, we’ll be happy to discuss them #LI-HYBRID

MFS is an hybrid work environment (remote/onsite) unless otherwise stated in the job posting.

At MFS, we are dedicated to building a diverse, inclusive and authentic workplace.

MFS is an Equal Opportunity Employer and it is our policy to not discriminate against any employee or applicant for employment because of race, color, religion, sex, national origin, age, marital status, sexual orientation, gender identity, genetic information, disability, veteran status, or any other status protected by federal, state or local laws. Employees and applicants of MFS will not be subject to harassment on the basis of their status. Additionally, retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing or have otherwise sought to obtain their legal rights under any Federal, State, or local EEO law is prohibited. Please see the Know Your Rights: Workplace Discrimination is Illegal document, linked for your reference.

For almost a century, investors around the world have trusted MFS to achieve their investment goals. Since 1924, when our founders invented the mutual fund, collaboration, a long-term focus and skilled active research have fueled our success. As a leading global investment manager, we hire employees who share our values, align with investors who share our long-term philosophy, and always act in the best interest of our clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineering Architect
Software Engineering Architect

MFS International Australia Pty Ltd • Boston (MA)

Hybrid
USD 123,000 - 178,000
Education assistance: loans
Tuition reimbursement
Wellness programs
+2
Sr. Manager, Derivative Trading Technology
Sr. Manager, Derivative Trading Technology

MFS International Australia Pty Ltd • Boston (MA)

On-site
USD 145,000 - 219,000
15% 401(k) match
Tuition reimbursement
Education assistance
+2
Software Engineering, Senior Data Engineer
Software Engineering, Senior Data Engineer

MFS International Australia Pty Ltd • Boston (MA)

Hybrid
USD 99,000 - 142,000
Retirement match 15%
Education assistance
Tuition reimbursement
+1
Business Systems Sr. Analyst
Business Systems Sr. Analyst

MFS International Australia Pty Ltd • Boston (MA)

Hybrid
USD 70,000 - 101,000
Retirement contribution (15%)
Tuition assistance
Paid maternity/paternity leaves
Enterprise Risk Officer
Enterprise Risk Officer

MFS International Australia Pty Ltd • Boston (MA)

Hybrid
USD 133,000 - 199,000
Retirement plan with company match
Tuition reimbursement
Education assistance
+1
Manager - Platform Support
Manager - Platform Support

MFS International Australia Pty Ltd • Boston (MA)

Hybrid
USD 120,000 - 190,000
Retirement contribution
Student loan assistance
Tuition reimbursement
+5
Lead Software Engineer - Investment Trading Technology
Lead Software Engineer - Investment Trading Technology

MFS International Australia Pty Ltd • Boston (MA)

On-site
USD 99,000 - 142,000
Hybrid work environment
Competitive incentive bonus
Retirement plan contribution
+1
Client & Sales Engagement Team Lead
Client & Sales Engagement Team Lead

MFS International Australia Pty Ltd • Boston (MA)

Hybrid
USD 88,000 - 126,000
Retirement match (15% of base)
Education assistance: loan repayment
Tuition reimbursement
+2
Compensation Consultant
Compensation Consultant

MFS International Australia Pty Ltd • Boston (MA)

Hybrid
USD 88,000 - 126,000
Bonus program
Retirement contribution 15%
Education assistance
+4
Business Systems Lead Engineer – Investment & Ops Technology
Business Systems Lead Engineer – Investment & Ops Technology

MFS Investment Management • Boston (MA)

Hybrid
USD 99,000 - 142,000
Hybrid work environment