EngineerJobs.io
← Back to all jobs
Information Technology Department

Principal Cybersecurity Engineer

Boston, MA $120k - $180k/yr Full time Posted 22d ago

Job Description

Based in Boston, the Information Technology Department is seeking a Principal Cybersecurity Engineer to design, implement, and operate enterprise security controls across network, endpoint, cloud, identity, data, and security operations for an asset management financial services organization. This senior role combines hands-on engineering with strategic security leadership to strengthen defenses, support regulatory requirements, and advance zero-trust and threat-hunting initiatives. The position offers a salary range of USD 119,742 to 180,205 per year.

Responsibilities

  • Design and maintain security controls across network, endpoint, cloud, and identity platforms.
  • Support Zero Trust architecture across systems, applications, infrastructure, and access models.
  • Define and validate security requirements for new systems, applications, platforms, and technology changes.
  • Embed security into system design, SDLC, and DevSecOps processes.
  • Develop, tune, and improve detection use cases across SIEM, XDR, and related monitoring tools.
  • Lead incident response activities, including investigation, containment, eradication, recovery, remediation, and post-incident analysis.
  • Perform threat hunting for suspicious activity, adversary behavior, indicators of compromise, and potential incidents.
  • Improve security operations through automation, orchestration, playbooks, and response workflows.
  • Secure AWS, Azure, Microsoft 365, and other cloud platforms through control design, configuration, logging, monitoring, and workload protection.
  • Implement and manage CSPM, cloud workload protection, and cloud security posture capabilities.
  • Review cloud architectures, services, integrations, and deployments for security risk.
  • Strengthen IAM, PAM, authentication, authorization, access governance, privileged access management, least privilege, and identity-based controls.
  • Support identity-driven Zero Trust initiatives involving access policy, device trust, segmentation, and continuous verification.
  • Support data classification, data protection, data monitoring, secure handling, and governance of sensitive information.
  • Improve data protection capabilities beyond traditional DLP.
  • Ensure secure data exchange with third parties, vendors, external partners, applications, and business platforms.
  • Support vulnerability management through risk-based prioritization, remediation guidance, exposure analysis, and coordination with technology owners.
  • Use threat intelligence to improve detection coverage, vulnerability prioritization, response planning, and control effectiveness.
  • Evaluate emerging threats, attacker techniques, exploitation trends, and security control gaps.
  • Support cybersecurity compliance related to internal policies, SEC, FINRA, audit requirements, regulatory obligations, and industry frameworks.
  • Partner with risk, audit, compliance, governance, engineering, infrastructure, cloud, application, and business teams.
  • Contribute to cybersecurity metrics, leadership reporting, governance documentation, and SIRT activities.
  • Support vendor management, tool evaluation, process improvement, security awareness, and continuous improvement of cybersecurity capabilities.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience.
  • 8+ years of experience in cybersecurity engineering, security infrastructure, enterprise security operations, or related technical security roles.
  • Experience with network security, endpoint security, cloud security, identity security, infrastructure security, or security engineering.
  • Experience with detection engineering, incident response, threat detection, investigations, SIEM, XDR, or security monitoring tools.
  • Experience with IAM, PAM, authentication, authorization, access governance, privileged access management, and least privilege.
  • Strong knowledge of cybersecurity principles, security architecture, control design, and NIST CSF.
  • Experience with incident response, including triage, investigation, containment, eradication, remediation, recovery, and post-incident review.
  • Knowledge of networks, servers, operating systems, endpoints, cloud platforms, identity systems, and business applications.
  • Strong analytical, problem-solving, documentation, collaboration, and communication skills.

Technologies

  • AWS, Azure, Microsoft 365, SIEM, XDR, CSPM, Cloud workload protection, IAM, PAM, Python, PowerShell, MITRE ATT&CK

Benefits

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Employee assistance program
  • Employee discount
  • Flexible schedule
  • Flexible spending account
  • Health insurance
  • Health savings account
  • Life insurance
  • Paid time off
  • Parental leave
  • Professional development assistance
  • Referral program
  • Retirement plan
  • Tution reimbursement
  • Vision insurance

Principal/Senior Cybersecurity Engineer Preferred Qualifications

  • CISSP, GIAC, GCIA, GCIH, GCED, or related security certifications.
  • Cloud security certification or hands-on experience with AWS, Azure, Microsoft 365, or similar cloud environments.
  • Experience in financial services, banking, capital markets, fintech, insurance, or highly regulated environments.
  • Knowledge of SEC, FINRA, audit requirements, internal security policies, regulatory expectations, and control frameworks.
  • Experience with Python, PowerShell, scripting, automation, workflow optimization, or operational tooling.
  • Knowledge of MITRE ATT&CK, threat frameworks, adversary tactics, and attack techniques.
  • Experience with Zero Trust, DevSecOps, CSPM, cloud workload protection, threat hunting, vulnerability management, identity security, SIEM, XDR, IAM, PAM, and security operations improvement.
  • Additional Requirements: Risk-based decision making; ability to work across cybersecurity, engineering, infrastructure, application, cloud, risk, compliance, audit, and business teams; ability to operate in a fast-paced environment with evolving threats and priorities; commitment to staying current on cybersecurity threats, tools, technologies, frameworks, and industry trends.

Work Location

In person in Boston, MA

Similar Jobs