Information Security Engineer III
Somerville, NJ - USA
Job Summary
Mass General Brigham relies on a wide range of professionals including doctors nurses business people tech experts researchers and systems analysts to advance our mission. As a not-for-profit we support patient care research teaching and community service striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.
Job Summary
The OpportunityMass General Brigham is seeking an Information Security Engineer III to serve as a senior leader within the Digital Information Security Architecture this role you will evaluate a wide variety of technologies business initiatives operational processes and strategic projects to identify security risks and provide practical risk-based guidance. Working closely with technical teams business stakeholders vendors and security professionals you will help ensure that security considerations are incorporated into decision making throughout the organization.
The ideal candidate possesses strong analytical and problem-solving abilities can rapidly develop an understanding of unfamiliar technologies and business challenges and is comfortable working across a diverse range of technical and operational domains. Success in this role requires exceptional analytical communication and consulting skills. The ideal candidate can rapidly understand unfamiliar technologies and business challenges identify meaningful cybersecurity risks develop practical recommendations and clearly articulate those recommendations to both technical and non-technical audiences.
You will help shape security strategy support enterprise initiatives evaluate emerging technologies contribute to organizational security standards and serve as a trusted advisor on cybersecurity matters. As a senior member of the team you will also mentor junior and mid-level employees and help foster a culture of collaboration sound judgment and continuous learning.
What Youll Do
Analyze technologies business initiatives operational processes and proposed solutions to identify security risks and provide practical risk-based guidance that supports informed decision making.
Quickly assess unfamiliar technologies platforms and business challenges develop an understanding of their security implications and translate that understanding into actionable recommendations.
Apply cybersecurity principles industry frameworks organizational standards and professional analyses to evaluate complex situations and recommend appropriate security controls safeguards or courses of action.
Collaborate with technical teams business stakeholders vendors project leaders and security professionals to address security concerns and help ensure that security considerations are incorporated into decision-making processes.
Research emerging technologies evolving threats regulatory requirements and industry practices to determine their relevance and potential impact on the organization.
Perform security reviews architectural evaluations and other analytical activities to identify weaknesses opportunities for improvement and areas requiring additional safeguards or oversight.
Develop clear concise and well-reasoned security guidance recommendations assessments standards reports and other written deliverables that enable stakeholders to make informed business and technology decisions.
Communicate complex technical concepts risks tradeoffs and recommendations effectively to audiences ranging from engineers and project teams to business leaders and executive stakeholders.
Present findings facilitate discussions answer questions and build consensus among stakeholders by explaining security concerns and recommended approaches in a clear practical and persuasive manner.
Serve as a trusted advisor by helping stakeholders understand cybersecurity risks evaluate available options and make balanced decisions that align with organizational objectives and risk tolerance.
Exercise independent judgment in situations that may involve incomplete information competing priorities evolving technologies or ambiguous requirements.
Contribute to the development and continuous improvement of security standards methodologies assessment approaches and best practices that strengthen the organizations overall security posture
Mentor junior and mid-level team members by sharing technical knowledge analytical approaches communication skills and professional expertise.
Qualifications
- Bachelors degree in Computer Science or a related field required; equivalent experience may be accepted in lieu of a degree.
- 5-7 years of experience as a systems engineer security engineer security architect cybersecurity consultant or in a related role required.
- Strong understanding of cybersecurity principles risk management concepts and industry-standard security frameworks.
- Demonstrated ability to rapidly understand new technologies business processes and operational environments and evaluate their security implications.
- Experience performing security assessments architecture reviews risk analyses technology evaluations or similar analytical activities.
- Ability to identify complex security issues evaluate potential solutions and develop practical risk-based recommendations.
- Strong knowledge of enterprise technologies including familiarity with cloud platforms identity and access management networking applications infrastructure security operations and emerging technologies.
- Understanding of security concepts such as Zero Trust least privilege defense-in-depth data protection secure software development threat modeling and vulnerability management.
- Strong verbal communication and presentation skills including the ability to explain complex technical concepts influence stakeholders and facilitate productive discussions.
- Strong analytical critical-thinking and problem-solving skills with the ability to work effectively in complex and ambiguous environments.
- Ability to mentor junior engineers and lead cross-functional technical initiatives.
Additional Job Details (if applicable)
- Hybrid role with onsite work required; candidates must be flexible based on weekly or monthly business needs.
- Monday-Friday schedule during Eastern business hours.
- On remote workdays employees must work from a stable secure and compliant workstation in a quiet environment. Teams video is required and must be accessed using Mass General Brigham-provided equipment.
Remote Type
Work Location
Scheduled Weekly Hours
Employee Type
Work Shift
Pay Range
$93953.60 - $136739.20/AnnualGrade
7EEO Statement:
At Mass General Brigham our competency framework defines what effective leadership looks like by specifying which behaviors are most critical for successful performance at each job level. The framework is comprised of ten competencies (half People-Focused half Performance-Focused) and are defined by observable and measurable skills and behaviors that contribute to workplace effectiveness and career success. These competencies are used to evaluate performance make hiring decisions identify development needs mobilize employees across our system and establish a strong talent pipeline.
Required Experience:
IC
About Company
Patients at Mass General have access to a vast network of physicians, nearly all of whom are Harvard Medical School faculty and many of whom are leaders within their fields.