- Salary
- $94k – $137k
- Location
- 399 Revolution Drive Somerville (Assembly Row Main Building), United States of America
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Experience
- 5+ years
- Education
- Bachelor
- Source
- Workday
Description
Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As a not-for-profit, we support patient care, research, teaching, and community service, striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.
Job Summary
The OpportunityMass General Brigham is seeking an Information Security Engineer III to serve as a senior leader within the Digital Information Security Architecture team. In this role, you will evaluate a wide variety of technologies, business initiatives, operational processes, and strategic projects to identify security risks and provide practical, risk-based guidance. Working closely with technical teams, business stakeholders, vendors, and security professionals, you will help ensure that security considerations are incorporated into decision making throughout the organization.
The ideal candidate possesses strong analytical and problem-solving abilities, can rapidly develop an understanding of unfamiliar technologies and business challenges, and is comfortable working across a diverse range of technical and operational domains. Success in this role requires exceptional analytical, communication, and consulting skills. The ideal candidate can rapidly understand unfamiliar technologies and business challenges, identify meaningful cybersecurity risks, develop practical recommendations, and clearly articulate those recommendations to both technical and non-technical audiences.
You will help shape security strategy, support enterprise initiatives, evaluate emerging technologies, contribute to organizational security standards, and serve as a trusted advisor on cybersecurity matters. As a senior member of the team, you will also mentor junior and mid-level employees and help foster a culture of collaboration, sound judgment, and continuous learning.
What You'll Do
• Analyze technologies, business initiatives, operational processes, and proposed solutions to identify security risks and provide practical, risk-based guidance that supports informed decision making.
• Quickly assess unfamiliar technologies, platforms, and business challenges, develop an understanding of their security implications, and translate that understanding into actionable recommendations.
• Apply cybersecurity principles, industry frameworks, organizational standards, and professional analyses to evaluate complex situations and recommend appropriate security controls, safeguards, or courses of action.
• Collaborate with technical teams, business stakeholders, vendors, project leaders, and security professionals to address security concerns and help ensure that security considerations are incorporated into decision-making processes.
• Research emerging technologies, evolving threats, regulatory requirements, and industry practices to determine their relevance and potential impact on the organization.
• Perform security reviews, architectural evaluations, and other analytical activities to identify weaknesses, opportunities for improvement, and areas requiring additional safeguards or oversight.
• Develop clear, concise, and well-reasoned security guidance, recommendations, assessments, standards, reports, and other written deliverables that enable stakeholders to make informed business and technology decisions.
• Communicate complex technical concepts, risks, tradeoffs, and recommendations effectively to audiences ranging from engineers and project teams to business leaders and executive stakeholders.
• Present findings, facilitate discussions, answer questions, and build consensus among stakeholders by explaining security concerns and recommended approaches in a clear, practical, and persuasive manner.
• Serve as a trusted advisor by helping stakeholders understand cybersecurity risks, evaluate available options, and make balanced decisions that align with organizational objectives and risk tolerance.
• Exercise independent judgment in situations that may involve incomplete information, competing priorities, evolving technologies, or ambiguous requirements.
• Contribute to the development and continuous improvement of security standards, methodologies, assessment approaches, and best practices that strengthen the organization's overall security posture
• Mentor junior and mid-level team members by sharing technical knowledge, analytical approaches, communication skills, and professional expertise.
Qualifications
- Bachelor's degree in Computer Science or a related field required; equivalent experience may be accepted in lieu of a degree.
- 5-7 years of experience as a systems engineer, security engineer, security architect, cybersecurity consultant, or in a related role required.
- Strong understanding of cybersecurity principles, risk management concepts, and industry-standard security frameworks.
- Demonstrated ability to rapidly understand new technologies, business processes, and operational environments and evaluate their security implications.
- Experience performing security assessments, architecture reviews, risk analyses, technology evaluations, or similar analytical activities.
- Ability to identify complex security issues, evaluate potential solutions, and develop practical, risk-based recommendations.
- Strong knowledge of enterprise technologies, including familiarity with cloud platforms, identity and access management, networking, applications, infrastructure, security operations, and emerging technologies.
- Understanding of security concepts such as Zero Trust, least privilege, defense-in-depth, data protection, secure software development, threat modeling, and vulnerability management.
- Strong verbal communication and presentation skills, including the ability to explain complex technical concepts, influence stakeholders, and facilitate productive discussions.
- Strong analytical, critical-thinking, and problem-solving skills, with the ability to work effectively in complex and ambiguous environments.
- Ability to mentor junior engineers and lead cross-functional technical initiatives.
Additional Job Details (if applicable)
- Hybrid role with onsite work required; candidates must be flexible based on weekly or monthly business needs.
- Monday-Friday schedule during Eastern business hours.
- On remote workdays, employees must work from a stable, secure, and compliant workstation in a quiet environment. Teams video is required and must be accessed using Mass General Brigham-provided equipment.
Remote Type
Work Location
Scheduled Weekly Hours
Employee Type
Work Shift
Pay Range
$93,953.60 - $136,739.20/Annual
Grade
7
EEO Statement:
Mass General Brigham Competency Framework
At Mass General Brigham, our competency framework defines what effective leadership “looks like” by specifying which behaviors are most critical for successful performance at each job level. The framework is comprised of ten competencies (half People-Focused, half Performance-Focused) and are defined by observable and measurable skills and behaviors that contribute to workplace effectiveness and career success. These competencies are used to evaluate performance, make hiring decisions, identify development needs, mobilize employees across our system, and establish a strong talent pipeline.