Senior Information Security Engineer, Marlborough or Chelmsford, MA, Hybrid
Job in
Marlborough, Middlesex County, Massachusetts, 01752, USA
Listed on 2026-08-03
Listing for:
Socket.dev
Full Time
position Listed on 2026-08-03
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Schedule
Mon - Fri: 8 AM - 5 PM (40 Hours)
What You’ll DoJob Summary
This role provides independent Second Line of Defense (2
LOD) oversight and risk assessment of the organization's information security program, controls, and technology environment. The position supports the identification, assessment, monitoring, and reporting of information security risks to ensure alignment with the organization's risk appetite, regulatory expectations, and industry standards. Through risk analysis, control evaluations, and effective challenge, this role helps strengthen the organization's cybersecurity posture and operational resilience.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Perform independent assessments of information security risks, controls, and processes across technology environments, applications, infrastructure, and third‑party relationships.
- Evaluate the design and effectiveness of security controls against established frameworks, regulatory requirements, and industry best practices.
- Identify, analyze, and communicate cybersecurity risks, vulnerabilities, control weaknesses, and emerging threats to risk and business stakeholders.
- Support governance and oversight of security domains including identity and access management, vulnerability management, cloud security, application security, data protection, and cybersecurity operations.
- Conduct risk assessments for new technologies, projects, systems, and business initiatives to evaluate potential security and operational risks.
- Provide effective challenge to first‑line security practices, risk decisions, control implementations, and remediation strategies.
- Monitor and assess information security metrics, key risk indicators (KRIs), control effectiveness measures, and trends to identify emerging risks and opportunities for improvement.
- Support development and maintenance of information security risk management policies, standards, methodologies, and governance processes.
- Participate in regulatory examinations, internal audits, risk reviews, and compliance assessments by preparing analysis, documentation, and responses to requests.
- Partner with Technology, Information Security, Compliance, Enterprise Risk, Internal Audit, and business stakeholders to strengthen risk management practices and improve control maturity.
- Prepare reporting and presentations that communicate technical risks, control gaps, and security trends to a variety of audiences.
- Support oversight of third‑party technology providers and critical vendor security risk management activities.
- Stay current on cybersecurity threats, regulatory developments, emerging technologies, and industry practices to evaluate potential impacts to the organization.
- Applies best practices and knowledge of internal/external business challenges to improve products, processes or services. Is accountable for small projects or programs with manageable risks and resource requirements. Resolves difficult and complex problems using judgment and analysis; contributes to problem solving in collaborative settings. Interprets policies and adapts them to new situations.
- Demonstrates judgment in selecting methods to solve problems that have cross‑functional impacts or require balancing competing priorities. Applies advanced knowledge of job area with experienced understanding of functional area.
- Typically receives little instruction on daily work. Works independently within defined specialties; adapts methods and procedures for routine work with minimal oversight. Accountable for deliverables. May mentor others and coach or review their work.
- Required
Education:
Bachelors degree in field relevant to role (or 4 additional years of relevant experience in lieu of a degree) - Required Experience:
4 - 6 years of relevant experience
- Knowledge of information security frameworks and standards such as NIST CSF, NIST 800‑53, ISO 27001, CIS Controls, or FFIEC guidance. Familiarity with regulatory expectations applicable to financial services environments.
- Understanding of cybersecurity…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×