Security Engineer
$110k - $150kKeystone
Keystone is a premier economics, technology, and strategy consulting firm built to help companies lead through transformation. As breakthrough innovations reshape industries, redefine competition and change our society, complex and highly competitive ecosystems emerge. Keystone advises technology leaders, Fortune 100 companies, their legal counsel, and governments on business, economic, litigation, and regulatory strategy in relation to these innovations and competitive eco-systems. We operate globally from offices in New York City, Boston, San Francisco, Seattle, London, Dubai, and Washington, D.C. We’re growing quickly and looking for a Security Engineer with governance, risk and compliance (GRC) proficiency who will be responsible for strengthening the organization’s cybersecurity posture through the execution of governance, risk management, and compliance activities. This role will be building and maintaining structured governance by formalizing policies, controls, and accountability across the organization, enabling proactive risk management through continuous assessment, threat modeling, and mitigation strategies, and ensuring compliance efforts can scale effectively alongside company growth, evolving regulatory requirements, and increasing complexity in systems, data handling, and third-party relationships. About the Security Engineer – GRC Role Reporting to the Director, IT Security you will work cross-functionally with IT, product, compliance, and leadership team, and in some cases directly with clients or auditor, to ensure our security posture meets both technical and regulatory expectations across commercial and regulated environments. This role focuses on developing, documenting, and refining security standards and procedures; performing risk and control assessments; and ensuring alignment with government regulatory and security frameworks, including ISO, industry standards, and organizational policies. This role is ideal for a technically strong security professional who enjoys building secure systems and translating regulatory and business requirements into practical, scalable security solutions. Key Responsibilities Security Engineering & Technical Controls Design, implement, and maintain security controls across cloud and SaaS environments (AWS, Azure, GCP) Implement and manage IAM solutions (SSO, MFA, RBAC, least privilege) Support vulnerability management, secure configuration, and system hardening initiatives Support logging, monitoring, and alerting integrations (SIEM, cloud-native tools) Assist with incident response planning, tabletop exercises, and post-incident reviews Evaluate and implement security tooling to improve visibility, protection, and automation Partner with engineering teams to embed security into the SDLC (secure design reviews, threat modeling, security requirements) Governance, Risk & Compliance (GRC) Enforce and maintain cybersecurity governance, risk, and control frameworks aligned with applicable laws and industry standards Perform cybersecurity risk assessments, maturity assessments, and Business Impact Analyses (BIA) Conduct control readiness and effectiveness assessments Maintain risk registers, POA&Ms, and remediation timelines Serve as a trusted advisor on control design, risk treatment, and security architecture decisions Regulatory & Audit Support Support compliance initiatives such as FedRAMP Moderate/High, ISO 27001, and similar frameworks Develop and maintain compliance documentation, including: System Security Plans (SSPs) Policies, procedures, and SOPs Control implementation statements Coordinate evidence collection and technical validation for internal and external audits Work directly with auditors, 3PAOs, and internal stakeholders during assessments Support continuous monitoring activities (vulnerability scans, control testing, compliance reporting) Program Execution & Improvement Track security control implementation with leadership and IT teams Drive automation and tooling improvements to scale compliance and monitoring Support third-party risk management, including technical vendor assessments and questionnaires Research and apply evolving security standards, regulatory requirements, and threat trends Lead process improvements to enhance security efficiency and operational maturity What You’ll Bring Required Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience 5–8+ years of experience in security engineering, GRC, or hybrid security/IT roles Strong hands-on experience with: Cloud platforms (AWS, Azure, GCP) IAM, network security, encryption, and secure system design Vulnerability management and secure configuration Strong working knowledge of security frameworks and compliance standards: NIST SP 800-53 (Rev. 5), NIST RMF (800-37), NIST CSF FedRAMP Moderate/High (including SSPs, POA&Ms, and audits)
ISO 27001, CIS
Experience translating compliance requirements into technical implementations Excellent technical writing, documentation, and stakeholder communication skills Ability to operate independently, manage multiple initiatives, and influence without authority Preferred Experience with FedRAMP 20x, GovRAMP, CMMC, TX-RAMP, or HIPAA Familiarity with GRC platforms (JupiterOne or similar) Experience with SIEM, WAF, CSPM, CNAPP, and vulnerability scanning tools Background in incident response, threat modeling, or penetration testing Scripting or automation experience (Python, Bash, Terraform) Cybersecurity certifications such as CISSP, CISA, CRISC, CCSP, Security+ In addition to annual salary, we provide an annual discretionary bonus, 401k contribution, and competitive benefits package. Actual Compensation within the range will depend upon the level the individual is hired into based on their skills, experience, and qualifications. Annual Salary Range$110,000—$150,000 USD
At Keystone we believe diversity matters. At every level of our firm, we seek to advance and promote diversity, foster an inclusive culture, and ensure our colleagues have a deep sense of respect and belonging. If you are interested in growing your career with colleagues from varied backgrounds and cultures, consider Keystone.$104k - $156k
...Posting Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate security controls that protect Relativity's employee endpoints and the enterprise systems they access. You will help...SuggestedRemote work- ...Job ID: 10426788 | Amazon Web Services, Inc. - A97 Employer: Amazon Web Services, Inc. | Position: Security Engineer II - AMZ27256.1 | Location: Boston, MA Multiple Positions Available Responsibilities Provide frontline support for all information security related issues...SuggestedRelocation package
- ...Identity And Access Management Engineer – Officer Location: Boston and Quincy, MA and Austin, TX, Atlanta Georgia, Princeton or Clifton... ...will have a broad range of responsibilities of IAM and CIAM security design and resiliency changes with aggressive execution timelines...Suggested
$159.3k - $202.4k
...Description Employer: Amazon Web Services, Inc. Position: Security Engineer II - AMZ27256.1 Location: Boston, MA Multiple Positions Available: Provide frontline support for all information security related issues, such as penetration testing, network and...SuggestedRelocation package$130k - $170k
...WHOOP IAM Security Engineer At WHOOP, we're on a mission to unlock human performance and healthspan. Our wearable technology provides personalized insights that help millions of members better understand their bodies and make smarter decisions about training, recovery...SuggestedFull timeWork at officeRelocation- ...Reporting to the manager of the IT Networking & Security team, this position is part of the IT Infrastructure group. The IT Security Engineer has responsibility for the design and implementation of security technology and policies that protect the Client's data and systems...
$152.41k - $179.3k
...foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase Corporate Security (CorpSec) is seeking a Security Engineer to design, implement, and automate security solutions that protect corporate infrastructure, user devices,...Local area$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you'll collaborate with...Work at officeRemote work$130k - $160k
...A well-known, highly respected organization is looking for a sharp Endpoint Security Engineer to join their infrastructure team. This is a high-impact role sitting at the intersection of endpoint security, OS engineering, and incident response. What you'll own:...$62.4k - $78k
DraftKings is seeking a Security Technology Engineer to drive the protection and scalability of our global operations. You will manage electronic security platforms and lead system upgrades while ensuring compliance and optimization. The ideal candidate has over 5 years...- Pylon is seeking a candidate to help build B2B post-sales support features, particularly focusing on security. The role includes responsibilities such as leading security reviews and engaging in both pre- and post-sales conversations. The ideal candidate should have experience...
$107k - $135k
CarGurus LLC in Boston is looking for a Security Engineer II to strengthen their Threat Detection and Response Team. This hands-on role involves identifying and mitigating cybersecurity threats while building effective detection platforms using the latest technology. The...- IT SECURITY ENGINEER , Information Systems and Technology (IS&T), will be a subject matter expert and final escalation point for cybersecurity events, applying analytical expertise and technical knowledge of networks and systems to protect the Institute's digital infrastructure...Full timeWork experience placementRemote work
$125k - $205k
...performance so campaigns don't just look good-they deliver results. Learn more at later.com. About this position: As a Senior Security Engineer at Later, you will play a critical role in strengthening and scaling the security foundations that power our platform. This...Permanent employmentLocal areaRemote work$141.6k - $212.4k
...Senior Security Engineer - Detection and Response IT & Security At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyos brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences...$222k - $278k
...About Semgrep Semgrep, the leader in code security for builders, empowers invention without friction. Teams catch, flag, and fix real... ...Semgrep's greater security mission; and partners closely with the Engineering, People Ops and Go‑to‑Market teams. About the role As a Senior...Currently hiringLocal areaRemote workWeekend work3 days per week$130k - $170k
...healthcare costs. Come work at Elucid and be part of delivering on our mission to prevent heart attacks and strokes! You are a security engineer who likes being close to the technology, partnering with the organization and solving real security problems in a complex...Work at officeRemote workFlexible hours$186.07k - $218.9k
...collaboration, connection, and alignment. Attendance is expected and fully supported. The Application Security org at Coinbase is hiring for a Senior Offensive Security Engineer, Offensive Security. We are seeking a highly skilled and experienced Penetration Tester with a...Local area$166k - $253k
...vision, sensor fusion, and networking technology to the military in months, not years. ABOUT THE JOB We're seeking a Security Software Engineer to develop novel security tooling for securing embedded Linux systems and Android devices. The ideal candidate can...Full timeWork experience placementImmediate start- We are seeking a Senior Security Engineer to join our team, focusing on defining security workflows and incident response (IR) strategies. Our AI Security Engineers are at the forefront of the Agentic Security revolution, working directly with our customers to ensure the...
$150k - $250k
...your family. World-class facilities and the technology you need to thrive - in our offices or yours. Job Summary The Security Engineer - Google collaborates with account and specialty teams to assess customer cybersecurity needs. They will be a customer-facing...Work experience placementWork at officeRemote workWorldwideFlexible hours- ...Network Security Engineer Boston, MA Must be onsite in Boston 3 days a week. ~ Must have strong Palo Alto, Juniper, and heavy Security ~5+ years of Network Security ~ Industry certifications (e.g., Palo Alto PCNSE, Juniper JNCIS-SEC...Contract work3 days per week
$124.22k - $132k
...Basic Qualifications Requires a Bachelor’s degree in Systems Engineering, or a related Science, Engineering, Technology or Mathematics... .... CLEARANCE REQUIREMENTS: Department of Defense Secret security clearance is required at time of hire. Applicants selected will...Flexible hours$108.25k - $130k
WHERE YOU’LL FIT WITHIN THE TEAM The SaaS security engineer will lead and scale our SaaS security program, with primary ownership of our SaaS security posture management (SSPM) platform and related initiatives. The role is technical, and candidates must possess a solid...Full timeWork experience placementWork at office1 day per week$130k - $170k
...members to perform at a higher level through a deeper understanding of their bodies and daily lives. WHOOP is seeking a Security Detection Engineer to serve as a key technical contributor within our Information Security team, reporting to the Information Security Manager...Full time$148.5k - $237.6k
...change. Constantly grow as you work hard for a mission that matters at a company where you matter. Your Impact As a Senior Security Operations Engineer, you'll play a key role in ensuring the reliability, performance, and scalability of our security infrastructure. You'll...Work experience placementWork at officeRemote work- About the Role Hopper's Security team is small by design and consequential by impact—and this role sits at the centre of it. As a Senior Security Engineer, you'll own the tooling, automation, and processes that keep our applications secure across their entire lifecycle...Work from homeShift work
- A leading marketing automation platform in Boston is looking for a Senior Security Engineer to enhance its security observability capabilities. The role involves building systems for detection and response, developing AI-first security solutions, and responding to security...
- A leading financial institution is seeking a Senior Ethical Hacker to evaluate the security of applications and technologies within its Cyber Security Assurance group. The ideal candidate will have over 5 years of experience in pentesting or ethical hacking, alongside...Work at office
- A leading cybersecurity organization is looking for an IT Security Engineer to act as a subject matter expert in cybersecurity. This role requires a Bachelor's degree or equivalent experience, along with over five years in the field. Candidates should have thorough knowledge...Remote jobFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
- senior application security engineer Boston, MA
- IT security engineer Boston, MA
- cloud security engineer Boston, MA
- network security engineer Boston, MA
- sr security engineer Boston, MA
- senior security operations engineer Boston, MA
- security infrastructure engineer Boston, MA
- sr information security engineer Boston, MA
- product security engineer Boston, MA
- information technology security engineer Boston, MA

