×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Engineer

Job in Worcester, Worcester County, Massachusetts, 01609, USA
Listing for: Harvard University
Full Time position
Listed on 2026-09-09
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant, Systems Engineer
Salary/Wage Range or Industry Benchmark: 130000 - 180000 USD Yearly USD 130000.00 180000.00 YEAR
Job Description & How to Apply Below

By working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expertise. We are dedicated to creating a diverse and welcoming environment where everyone can thrive.

Why join Harvard Medical School?

Harvard Medical School's mission is to nurture a diverse, inclusive community dedicated to alleviating suffering and improving health and well-being for all through excellence in teaching and learning, discovery and scholarship, and service and leadership.

You’ll be at the heart of biomedical discovery, education, and innovation, working alongside world-renowned faculty and a community dedicated to improving human health. This is more than a job - it’s an opportunity to shape the future of medicine.

The Senior Security Engineer will have responsibility for supporting and advancing Harvard Medical School's application security, Secure SDLC, and penetration testing programs. This role will partner closely with others across HMS IT and Security to enable the HMS mission by implementing Secure SDLC practices, operating application security testing platforms, identifying security weaknesses through penetration testing, and collaborating with development teams to improve security throughout the software lifecycle.

On a daily basis, this role will perform penetration testing of applications, systems, and emerging technologies; support the administration of application security platforms; conduct threat research; identify security risks and remediation opportunities; and help mature the organization's application security capabilities. This role will partner with Sec Ops when required during security incidents and investigations. The Senior Security Engineer, as part of the IT Security team, will partner with others across Security and IT to establish strategic and tactical roadmaps and help mature application and offensive security capabilities.

Principal duties and responsibilities:
  • Perform penetration testing of applications, systems, infrastructure, cloud environments, and emerging technologies.
  • Identify security weaknesses and provide remediation recommendations through technical testing.
  • Support Secure SDLC initiatives and collaborate with development teams to improve application security.
  • Administer and support application security platforms and testing tools.
  • Assist with implementation and operation of SAST, SCA, DAST, API Security, Secrets Detection, and related application security capabilities.
  • Conduct threat research and stay current on emerging attack techniques, vulnerabilities, adversary activity, and security trends.
  • Inform the organization of emerging threats, attack techniques, vulnerabilities, and risks.
  • Serve as an information security subject matter expert in penetration testing and application security.
  • Research, evaluate, and recommend new security tools, technologies, and processes that improve HMS security capabilities.
  • Abide by and follow Harvard University IT technical standards, policies, and Code of Conduct.
Basic Qualifications:
  • Minimum of seven years’ post-secondary education or relevant work experience.
Additional

Qualifications and Skills:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field; or equivalent combination of education and relevant experience.
  • Experience using common security testing and analysis tools.
  • Ability to communicate technical security findings and remediation recommendations to both technical and non-technical audiences.
  • Hands-on experience performing penetration testing of web applications, systems, networks, cloud environments, or APIs.
  • Familiarity with common offensive security tools, techniques, and methodologies.
  • Experience identifying, validating, and helping remediate common web application vulnerabilities (OWASP Top 10).
  • Experience with Secure SDLC concepts and application security testing tools such as Checkmarx, Burp Suite, Veracode, Git Hub Advanced Security, or similar platforms.
  • Experience administering or supporting application security platforms preferred.
  • Familiarity with…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary