Staff Security Engineer
Job Description
Bain & Company is seeking a Staff Security Engineer to lead the security posture of Bain's private equity platform on Azure with AKS. The role emphasizes zero trust, supply chain security, data boundary enforcement, and AI egress controls, while embedding security into the development lifecycle across cross-functional teams.
Responsibilities
- Manage and operate the platform security posture end to end across core controls including HashiCorp Vault and/or Azure Key Vault, Istio mTLS, Cilium network policy, Pod Security Standards, and OPA/Gatekeeper policies.
- Design and implement a zero-trust security architecture across the estate, applying defense in depth, least privilege, and explicit security boundary design.
- Perform lightweight threat modelling (STRIDE) for new services and major features prior to implementation; document risks, mitigations, and residual risk decisions.
- Oversee supply chain security controls such as container image scanning, image signing, SBOM generation, and dependency vulnerability management.
- Define and enforce identity and access controls, covering SAML/OIDC integration patterns, JWT/OAuth concepts, and enterprise IdP integration guidance (Okta/Entra).
- Define and maintain data classification controls and enforce them at the platform layer with governed access patterns, masking/tokenization, and API-layer enforcement.
- Own runtime detection controls by operating Falco rules and escalation pathways; integrate signals with the central SIEM and minimize alert noise while preserving actionable insight.
- Lead security incident response for the platform, driving containment, remediation, and post-incident reviews with clear follow-up actions.
- Conduct regular security reviews of the AI layer, including Agent Gateway egress controls, prompt injection risks, PII handling, and data exfiltration controls for model interactions.
- Maintain security runbooks and conduct quarterly internal security reviews across teams to ensure controls are tested, auditable, and kept current.
- Embed in select PE squad ceremonies (refinement, planning, design reviews) to identify security concerns early and define testability and operability requirements.
- Collaborate with Platform Engineering to create secure-by-default templates and guardrails, including policy-as-code libraries, reusable CI checks, and pre-commit hooks to reduce repetitive effort.
- Partner with the Data Governance Lead on PII classification, tokenization policy, and regulatory requirements (SOC 2 Type II, ISO 27001, GDPR).
- Work with the centralized Application Security team to promote secure AI tooling, accelerate threat modelling, security policy drafting, and CVE triage; validate outputs with expert judgement.
- Communicate security risks in business-impact terms and prioritize controls that materially reduce risk.
Requirements
- Hybrid work model with in-office presence at least one day per week.
- Bachelor’s degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related field, or equivalent practical experience.
- 6+ years of experience in security engineering, infrastructure security, SRE/DevOps with a security focus, or platform engineering roles with hands-on security ownership.
- Experience implementing and operating security controls in Kubernetes-based production environments, including policy enforcement, workload isolation, network controls, and runtime detection.
- Experience designing and operating secrets management and identity/access controls (HashiCorp Vault and/or Azure Key Vault, PKI, OIDC/SAML patterns, enterprise IdP integration).
- Experience implementing supply chain security practices (scanning, signing, SBOMs, dependency management) and integrating controls into CI/CD pipelines.
- Experience leading or contributing to security incident response, including post-incident review and remediation planning.
- Proven ability to collaborate cross-functionally as an enabling partner, raising security standards without blocking delivery unnecessarily.
Technologies
- HashiCorp Vault, Azure Key Vault
- Istio, Cilium, Pod Security Standards, OPA, Gatekeeper
- SAML 2.0, OIDC, JWT, OAuth 2.0
- Okta, Azure AD
- Falco, Trivy, Cosign, Sigstore, Syft, Dependabot, Renovate
- Kubernetes, Kyverno, Rego
- Python, Bash
- AWS Macie
Benefits
- Health coverage for medical, dental, and vision premiums for employees.
- Paid time off, including parental leave, sick leave, and holidays.
- Fully vested 401(k) company contribution.
- 4.5% 401(k) company contribution, increasing after three years of service and 100% vesting from start date.
- Paid life insurance and long-term disability coverage.
- Annual fitness reimbursements.
Compensation and Location
Location: Boston, MA, hybrid work arrangement with in-office presence at least one day per week.
Salary range: For Boston, the good-faith annualized base range is $147,250 to $176,750, with placement within this range depending on experience, education, and skill level.
Total compensation: Compensation includes base salary, an annual discretionary performance bonus, a 401(k) plan with employer contributions, and Bain’s comprehensive benefits package.
The 401(k) contribution is 4.5 percent and increases after three years of service, with full vesting at the start date. Bain provides full premium coverage for medical, dental, and vision insurance, generous paid time off, and additional wellness programs as part of its benefits offering.