Security Engineer (Boston HQ)
WinnCompanies · Boston, Massachusetts, United States · $80K–$110K/yr
Real Estate · 1,001-5,000 employees
About the role
The Security Engineer will manage identity and access processes, conduct third-party risk assessments, and coordinate incident detection and response. They will also work closely with the Director of Information Security to develop security strategy and deploy security tools.
What they look for
Requirements
Candidates must have 2–5 years of hands-on experience in security engineering or operations with practical knowledge of IAM and incident response tools. Strong communication skills and the ability to work independently in a lean team environment are essential.
Benefits
Full description
WinnCompanies is looking for a Security Engineer to join our team in Boston, MA to help drive our progress forward.
Our organization manages affordable housing communities and supports approximately 3,000 corporate and property-based employees. We are building out a maturing security program and are looking for a hands-on Security Engineer to help drive it forward.
Reporting to the Director of Information Security & Risk Management, you will be a core member of a lean security team. This is a high impact role with broad exposure: where you will work across core domains including identity and access management (IAM), third-party risk, and incident detection and response while working closely with the Director of Information Security to strengthen overall security architecture and program strategy. You will work closely with our internal IT team and our managed security service provider (MSSP) to deploy, configure, and tune security tools, improve monitoring and alerting, and support incident response activities.
The salary range for this role is $80,000 to $110,000 per year, dependent on experience.
Responsibilities:
Identity & Access Management
- Administer and manage identity and access management (IAM) processes and tools across a large, distributed workforce.
- Manage the high-volume onboarding and offboarding process common in property management environments.
- Implement and tune access controls, role-based access, multi-factor authentication, and least-privilege practices.
- Support access reviews, partnering with IT and business owners to validate findings.
Vendor & Third-Party Risk
- Conduct vendor and third-party risk assessments using the firm's third-party assessment tool.
- Evaluate vendor security postures, document findings, track remediation, and advise stakeholders on acceptable risk.
- Help refine the third-party risk process and reporting as the program matures.
Incident Detection & Response
- Serve as a key point of contact for security incident detection and response, working alongside our managed detection and response (MDR) provider.
- Triage, investigate, and coordinate response to alerts
- 24/7 on call for incidents escalated by the MDR service.
- Contribute to and help mature incident response playbooks, runbooks, and post-incident reviews.
Program Development & Implementation
- Work directly with the Director of Information Security & Risk Management to shape the strategy, roadmap, and priorities of the security program.
- Work with internal IT and the IT MSSP to implement, configure, and operate security tools and controls.
- Contribute to policy development, security awareness training, and compliance-supporting activities as needed.
- Take on related security responsibilities as the program evolves.
Requirements
- 2–5 years of hands-on experience in security engineering, security operations, IT security, or a closely related role.
- Practical experience with identity and access management concepts and tooling (e.g., directory services, SSO, MFA, user provisioning/deprovisioning).
- Experience working with security incident detection and response tools, including working with SIEM, EDR, or MDR- services.
- Understanding of third-party / vendor risk assessment principles.
- Proven ability to collaborate effectively with internal IT teams and external service providers (MSSP, MDR).
- Strong written and verbal communication skills, with the ability to clearly document findings and articulate risks to non-technical stakeholders.
- Self-directed and capable of working independently, demonstrating a strong problem-solving mindset in a lean and rapidly growing security program
Preferred
- Experience supporting a large or distributed workforce, ideally across multiple physical sites.
- Hands-on experience implementing controls for the protection of sensitive data (PII),
- Familiarity with common security and privacy frameworks (e.g., NIST CSF, CIS Controls) and associated regulatory considerations.
- Relevant certifications such as Security+, SSCP, GSEC, or progress toward CISSP.
- Experience using scripting or automation tools (e.g., PowerShell, Python) to streamline IAM and security operational tasks
Our Benefits:
Regular full-time US employees are eligible to participate in the following benefits:
- Generous time off policies (including 11 paid holidays (12 for MA employees); Generous Accrued Time Off increasing with years of service; Generous paid sick time; Annual day of service; Floating Holiday)
- 401(k) plan options with a company match
- Various Comprehensive Medical, Dental, & Vision plan options
- Flexible Spending Account, Dependent Care Flexible Spending Account, Health Savings Account options with HSA annual employer contribution
- Long Term Disability and voluntary Short Term Disability; Basic Term Life Insurance and AD&D; optional supplemental life insurance
- Health Expense Reimbursement program (including gym memberships, equipment, and subscriptions)
- Tuition Reimbursement program and continuous training and development opportunities
- Wellbeing program (group challenges, seminars, opportunities to earn points to reduce medical premiums), Employee Assistance Program, & Commuter and Parking Reimbursement options
- Employee Corporate Discount Programs
- Flexible and/or Hybrid schedules are available for certain roles
- Employee Relief Program supporting employees with unexpected hardships that place undue financial stress on them and their families
- To learn more, visit winnbenefits.com
Why WinnCompanies?
A job you can be proud of: WinnCompanies is a nationally recognized leader in apartment community management and development. Our team members are committed to helping people in the communities we serve and making a positive difference in their lives.
A job that challenges you: Our employees are responsible for our growth and success, and we challenge our team members to always be their best in our fast-paced, dynamic and rewarding workplace.
A job you can learn from: We offer multi-faceted leadership and learning opportunities to support our team members’ career growth and professional development.
A team that cares: We value teamwork, innovation, diversity and mutual respect. Through our recognition and rewards programs, we’re committed to celebrating and uplifting our team members.
About Us:
WinnCompanies is a mission-driven, national business focused on building and operating top quality affordable housing communities for individuals and families of all incomes, including members of the U.S. Armed Forces and their families. Our people are the source of our success – 4,300+ team members working together to create the best possible living communities in 27 states, Washington, D.C., and Puerto Rico.
Whether your skills are in operations, maintenance, leasing, compliance, marketing, IT, HR, accounting or finance, there’s a role for you at WinnCompanies. Your passion for excellence can help us make a positive impact in the lives of real people every day.
If you are a California Resident, please see our Notice of Collection here.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Salary will vary based on job responsibilities and scope, geographic location, candidate’s relevant experience, and other factors.
Internal candidates, please apply here: Internal Careers Hub