Enable job alerts via email!

Senior Information Security Engineer

Geode Capital Management

Boston (MA)

Hybrid

USD 90,000 - 150,000

Full time

12 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Senior Information Security Engineer to drive security initiatives and enhance their risk management practices. This hybrid role offers the opportunity to collaborate with cross-functional teams, ensuring effective security measures are in place throughout the Software Development Life Cycle. You'll leverage your extensive experience in information security, vulnerability management, and cloud environments to protect sensitive data and promote a culture of security awareness. If you're passionate about mitigating risks and thrive in a dynamic environment, this position is perfect for you.

Qualifications

  • 7+ years of experience in software development and information security.
  • Strong knowledge of vulnerability management and OWASP Top 10 vulnerabilities.
  • Familiarity with frameworks like CIS, NIST, ISO 27001, and SOC.

Responsibilities

  • Lead security initiatives throughout the Software Development Life Cycle.
  • Support key security initiatives such as vulnerability management and cloud migration.
  • Assist in implementing information security requirements and policies.

Skills

Software Development
Information Security
Cloud Environments
Vulnerability Management
Security Testing Tools
Problem-Solving
Interpersonal Skills

Education

Bachelor’s degree in Computer Science
Bachelor’s degree in Engineering
Bachelor’s degree in Computer Security
Bachelor’s degree in Information Systems

Tools

Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
AWS
Azure

Job description

Join to apply for the Senior Information Security Engineer role at Geode Capital Management.

Geode Capital Management, LLC is seeking a Senior Information Security Engineer. The primary responsibilities include supporting Geode’s Information Security and Technology Transformation initiatives. This position reports to the Director of Information Security and collaborates closely with the Technology and Risk Management teams. The ideal candidate is passionate about identifying, managing, communicating, and mitigating risks, fostering a risk-focused culture, and promoting effective Information Security practices at Geode.

This is a hybrid work environment opportunity located in Boston, MA with a weekly in-office schedule of Tuesdays, Wednesdays, and Thursdays, and remote work from home on Mondays and Fridays.

Responsibilities
  • Lead security initiatives throughout Geode’s Software Development Life Cycle (SDLC) by utilizing Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools. Act as a subject matter expert and assist the Technology team in remediating application vulnerabilities.
  • Support Geode’s key security initiatives such as vulnerability management, application security, DevSecOps, access governance, and cloud migration (AWS, Azure).
  • Assist in implementing information security requirements, including policies, standards, and controls, by collaborating with the Risk Management team.
  • Partner with Technology, Internal Audit, and other teams to analyze security controls to ensure security requirements are met for effective security posture.
  • Provide support and input for audits or examinations from internal/external parties and collaborate to ensure findings are remediated.
  • Assist with risk assessments, identify gaps, and document action items.
  • Prepare data and metrics-based analysis to proactively monitor and report on risks across the company using Key Risk Indicators (‘KRIs’).
  • Perform additional duties as required.
Skills You Bring
  • Bachelor’s degree in Computer Science, Engineering, Computer Security, or Information Systems.
  • 7+ years of experience in software development, information security, and cloud environments, with broad knowledge of information systems and latest technologies.
  • Strong knowledge of vulnerability management and security testing tools, as well as OWASP Top 10 vulnerabilities.
  • Experience with frameworks such as CIS, NIST, ISO 27001, and SOC.
  • Certifications such as CISSP, CISM, and CEH are preferred but not required.
  • Strong interpersonal and communication skills, with problem-solving abilities.
  • Ability to work independently across multiple streams and thrive in a fast-paced, small company culture environment.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Information Security Engineer

Penn Mutual Life Insurance Co.

Remote

USD 130,000 - 160,000

Yesterday
Be an early applicant

Senior Information Security Engineer

PML Penn Mutual Life Insurance Company

Remote

USD 130,000 - 160,000

2 days ago
Be an early applicant

Sr Information Security Engineer

Lumen Argentina

Remote

USD 82,000 - 111,000

2 days ago
Be an early applicant

Sr Lead Information Security Engineer

Lumen Technologies

Remote

USD 129,000 - 173,000

5 days ago
Be an early applicant

Senior Information Security Engineer

Motion Recruitment

Boston

Hybrid

USD 80,000 - 130,000

4 days ago
Be an early applicant

Senior Information Security Engineer

Lumen Technologies

Remote

USD 82,000 - 111,000

9 days ago

Sr Lead Information Security Engineer

Lumen Argentina

Remote

USD 129,000 - 173,000

7 days ago
Be an early applicant

STATEWIDE SENIOR INFORMATION SECURITY ENGINEER

Arizona State Government

Hyde Park Township

On-site

USD 85,000 - 95,000

4 days ago
Be an early applicant

Sr Information Security Engineer

SmartLight Analytics

Plano

Remote

USD 90,000 - 150,000

27 days ago