Senior Systems Engineer

Wellington Management Company LLP

United States

Hybrid

USD 150,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Wellington Management Company LLP is seeking a Lead Security Engineer to minimize attack surfaces via vulnerability management, cloud assessments, threat intel, and policy automation. You will partner with CI/CD teams, mentor peers, and drive hardening baselines across the firm.

You will work with CNAPP and vulnerability tools (e.g., WIZ CNAPP, Qualys), automate workflows with Python, and coordinate with Third-Party Risk. Hybrid in-office and remote work supports a flexible security posture.

Qualifications

  • BS degree in Information Systems or related discipline or equivalent IT work experience.
  • Experience communicating security risk to stakeholders.
  • Experience developing and maturing security baselines and processes.

Responsibilities

  • Perform vulnerability and misconfiguration assessments and communicate risk to stakeholders.
  • Leverage CNAPP tooling to assess findings and guide application custodians.
  • Serve as security liaison across SDLC and CI/CD pipelines to secure code.
  • Lead urgent vulnerability responses and misconfiguration events.
  • Automate workflows with scripting and AI to shorten output times.
  • Develop internal security baselines aligned with CIS Controls and threats.
  • Stay current on cyber threats and map them to the attack surface.
  • Review threat intel sources for vulnerabilities and vendor exposures.
  • Collaborate with Third-Party Risk to assess vendor exposure to critical flaws.
  • Contribute to team and firmwide documentation and policy development.

Skills

Self-motivation
Communication skills
Mentoring
Global collaboration
Curiosity

Education

BS in Information Systems or related discipline

Tools

WIZ CNAPP
Qualys
Python scripting
IaC (AWS)
Splunk
JFrog Artifactory
JFrog Curation
ServiceNow
AWS Services
MS Azure
MS Intune
Anthropic Claude

Job description

The Attack Surface Management team is seeking a Lead Security Engineer to be a key member of our team. This engineer will assist in the minimization of potential attack surfaces through vulnerability management, cloud configuration assessments, incorporating threat intelligence from public and private sources, and work internally to build, enhance, and automate policies, standards, and processes. They will be working with various technologies that surface vulnerabilities, misconfigurations, end-of-life software, and other vectors. The ideal candidate is one that has a passion for cyber-security, is naturally curious, and is willing to think outside the box to find creative solutions to challenges.

Detailed responsibilities
  • Perform assessments and communicate to stakeholders on the likelihood of exploitation and potential impact of vulnerabilities, misconfiguration findings, and other potential vectors to determine the appropriate course of action to mitigate potential risk.
  • Leverage Cloud Native Application Protection Platform (CNAPP) technology to assess findings and contribute guidance and expertise to application custodians on fixing issues.
  • Act as a security liaison between Information Security and the Development staff to bring a security mindset to the software development lifecycle. Assess and understand the Wellington CI/CD pipeline to be able to provide recommendations to developers for securing their code.
  • Lead urgent vulnerability response, misconfiguration events, or otherwise assist with Cyber Defense as needed.
  • Use scripting and AI to automate manual workflows, assist with data assessments, and shorten time gaps from ideas to outputs.
  • Develop and mature an internal security hardening and baselines program. This effort develops standards and processes to ensure attack surface risk is reduced, and configuration baselines are met both according to CIS Controls and cyber threats actively targeting the firm.
  • Stay up to date with current and relevant cyber security threats as well as any associated countermeasures. Participate in internal meetings to map industry cyber threats to our current attack surface.
  • Review of both internal and open-source threat intelligence sources for recently disclosed vulnerabilities at risk of introduction into the Wellington environment.
  • Work with our Third-Party Risk team to engage third parties in Wellington's vendor ecosystem to understand when third and fourth parties may be exposed to critical vulnerabilities.
  • Contribute to team documentation for updates to existing processes, new processes, assessment tool infrastructure details and workflows.
  • Contribute to firmwide documentation by being an SME contributor to policies and standards.

We believe that in person interactions inspire and energize our community and are essential to our culture. In support of this commitment, our employees work from our offices 4 days a week with flexibility to work remotely 1 day a week. We believe that this approach ultimately supports our mission to deliver investment excellence to our clients and their beneficiaries over the long term.

A Passion for cyber-security is a must.

Ability to self-motivate, with an eagerness to dig into potential risks. Ask questions, be curious, dig deeper.

BS degree in Information Systems/related discipline or equivalent IT work experience

Experience in developing new processes and procedures that match evolving attack surfaces.

Excellent oral and written communication skills with a proven ability to effectively interact with teams representing a wide variety of technical disciplines.

Ability to work with global teams effectively.

Ability to mentor junior team members and share discoveries about your work.

TECHNICAL QUALIFICATIONS
  • Experience working with both WIZ CNAPP and Qualys vulnerability management platforms.
  • Hands-on experience with vulnerability assessment software and prioritizing results using a combination of various frameworks tied to internal objects (CVE, CVSS, EPSS, etc.).
  • Knowledge of common cyber-attack types such as DDoS, SQLi, XSS, and others. This experience is relied upon to make rational decisions in our baselines program.
  • Previous experience assessing, documenting, and communicating information security risk, particularly related to cyber vulnerabilities is preferred.
  • Experience in the use of common scripting languages such as python to automate job functions.
  • Working knowledge of IaC (Infrastructure as Code) concepts, especially with AWS.
  • Knowledge in the areas of network architecture and engineering and software application development
  • Working knowledge of the use of threat intelligence feeds and resources
  • Preferred: Experience working with Splunk, JFrog Artifactory, JFrog Curation (or similar), ServiceNow, AWS Services, MS Azure, MS Intune, Anthropic Claude
  • Preferred: Home labs, security practitioner meetups, research, we would love to hear it!

Wellington Management offers comprehensive investment management capabilities that span nearly all segments of the global capital markets. Our investment solutions, tailored to the unique return and risk objectives of institutional clients in more than 60 countries, draw on a robust body of proprietary research and a collaborative culture that encourages independent thought and healthy debate. As a private partnership, we believe our ownership structure fosters a long-term view that aligns our perspectives with those of our clients.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Security Engineer - Attack Surface & Automation
Lead Security Engineer - Attack Surface & Automation

Wellington Management Company LLP • United States

Hybrid
USD 150,000 - 210,000
Security Operations Manager
Security Operations Manager

Wellington Management • Massachusetts

On-site
USD 90,000 - 180,000
Hybrid work schedule
Comprehensive benefits package
Security Operations Manager
Security Operations Manager

Wellington Management Company • Boston (MA)

On-site
USD 90,000 - 180,000
Retirement plan
Health benefits
Dental
+10
Security Operations Manager
Security Operations Manager

Koitecc Solutions • Boston (MA), Northern (KY)

On-site
USD 90,000 - 180,000
Security Operations Manager
Security Operations Manager

CFA Institute • Boston (MA)

On-site
USD 90,000 - 180,000
Retirement plan
Health & wellbeing benefits
Commuter program
+2
Lead Software Engineer
Lead Software Engineer

Quest Oracle Community • Boston (MA)

Hybrid
USD 120,000 - 225,000
4 days on-site, 1 remote day
Competitive compensation
Retirement plan
+3
Portfolio Analytics Systems Lead
Portfolio Analytics Systems Lead

Wellington Management • Boston (MA)

Hybrid
USD 90,000 - 180,000
Health and wellbeing coverage
Flexible work environment
Retirement plan
Senior Software Engineer
Senior Software Engineer

Quest Oracle Community • Boston (MA), Northern (KY)

Hybrid
USD 90,000 - 180,000
Strategic Market Intelligence Lead – Asset Management
Strategic Market Intelligence Lead – Asset Management

Wellington Management • Boston (MA)

Hybrid
USD 120,000 - 225,000
Comprehensive benefits package
Flexible work arrangements
Discretionary bonuses
Solution Architect
Solution Architect

Wellington Management Company • Town of Boston (NY), Northern (KY)

On-site
USD 120,000 - 225,000
Retirement plan
Health coverage
Dental/Vision
+5