Mass General Brigham

Information Security Engineer III

Mass General Brigham Somerville, Massachusetts, United States · $94K–$137K/yr

Hospitals and Health Care · 10,001+ employees

Yesterday
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Information Security Engineer III will evaluate technologies and business initiatives to identify security risks and provide practical, risk-based guidance. They will also collaborate with stakeholders to ensure security considerations are integrated into decision-making processes and mentor junior team members.

What they look for

Information Security Risk Management Cybersecurity Principles Security Architecture Threat Modeling Vulnerability Management Zero Trust Identity And Access Management Cloud Platforms Network Security Data Protection Secure Software Development Analytical Skills Communication Skills Consulting Mentoring

Requirements

Candidates must have a bachelor's degree in Computer Science or a related field and 5-7 years of experience in systems engineering or cybersecurity. Strong knowledge of enterprise technologies, security frameworks, and the ability to communicate complex technical concepts to diverse audiences are required.

Benefits

Health Insurance Career Advancement Opportunities Differentials Premiums Bonuses Recognition Programs

Full description

Site: Mass General Brigham Incorporated  

Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As a not-for-profit, we support patient care, research, teaching, and community service, striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.

 

Job Summary

The Opportunity Mass General Brigham is seeking an Information Security Engineer III to serve as a senior leader within the Digital Information Security Architecture team. In this role, you will evaluate a wide variety of technologies, business initiatives, operational processes, and strategic projects to identify security risks and provide practical, risk-based guidance. Working closely with technical teams, business stakeholders, vendors, and security professionals, you will help ensure that security considerations are incorporated into decision making throughout the organization. The ideal candidate possesses strong analytical and problem-solving abilities, can rapidly develop an understanding of unfamiliar technologies and business challenges, and is comfortable working across a diverse range of technical and operational domains. Success in this role requires exceptional analytical, communication, and consulting skills. The ideal candidate can rapidly understand unfamiliar technologies and business challenges, identify meaningful cybersecurity risks, develop practical recommendations, and clearly articulate those recommendations to both technical and non-technical audiences. You will help shape security strategy, support enterprise initiatives, evaluate emerging technologies, contribute to organizational security standards, and serve as a trusted advisor on cybersecurity matters. As a senior member of the team, you will also mentor junior and mid-level employees and help foster a culture of collaboration, sound judgment, and continuous learning.

What You'll Do

  • Analyze technologies, business initiatives, operational processes, and proposed solutions to identify security risks and provide practical, risk-based guidance that supports informed decision making.
  • Quickly assess unfamiliar technologies, platforms, and business challenges, develop an understanding of their security implications, and translate that understanding into actionable recommendations.
  • Apply cybersecurity principles, industry frameworks, organizational standards, and professional analyses to evaluate complex situations and recommend appropriate security controls, safeguards, or courses of action.
  • Collaborate with technical teams, business stakeholders, vendors, project leaders, and security professionals to address security concerns and help ensure that security considerations are incorporated into decision-making processes.
  • Research emerging technologies, evolving threats, regulatory requirements, and industry practices to determine their relevance and potential impact on the organization.
  • Perform security reviews, architectural evaluations, and other analytical activities to identify weaknesses, opportunities for improvement, and areas requiring additional safeguards or oversight.
  • Develop clear, concise, and well-reasoned security guidance, recommendations, assessments, standards, reports, and other written deliverables that enable stakeholders to make informed business and technology decisions.
  • Communicate complex technical concepts, risks, tradeoffs, and recommendations effectively to audiences ranging from engineers and project teams to business leaders and executive stakeholders.
  • Present findings, facilitate discussions, answer questions, and build consensus among stakeholders by explaining security concerns and recommended approaches in a clear, practical, and persuasive manner.
  • Serve as a trusted advisor by helping stakeholders understand cybersecurity risks, evaluate available options, and make balanced decisions that align with organizational objectives and risk tolerance.
  • Exercise independent judgment in situations that may involve incomplete information, competing priorities, evolving technologies, or ambiguous requirements.
  • Contribute to the development and continuous improvement of security standards, methodologies, assessment approaches, and best practices that strengthen the organization's overall security posture
  • Mentor junior and mid-level team members by sharing technical knowledge, analytical approaches, communication skills, and professional expertise.

 

Qualifications

  • Bachelor's degree in Computer Science or a related field required; equivalent experience may be accepted in lieu of a degree.
  • 5-7 years of experience as a systems engineer, security engineer, security architect, cybersecurity consultant, or in a related role required.
  • Strong understanding of cybersecurity principles, risk management concepts, and industry-standard security frameworks.
  • Demonstrated ability to rapidly understand new technologies, business processes, and operational environments and evaluate their security implications.
  • Experience performing security assessments, architecture reviews, risk analyses, technology evaluations, or similar analytical activities.
  • Ability to identify complex security issues, evaluate potential solutions, and develop practical, risk-based recommendations.
  • Strong knowledge of enterprise technologies, including familiarity with cloud platforms, identity and access management, networking, applications, infrastructure, security operations, and emerging technologies.
  • Understanding of security concepts such as Zero Trust, least privilege, defense-in-depth, data protection, secure software development, threat modeling, and vulnerability management.
  • Strong verbal communication and presentation skills, including the ability to explain complex technical concepts, influence stakeholders, and facilitate productive discussions.
  • Strong analytical, critical-thinking, and problem-solving skills, with the ability to work effectively in complex and ambiguous environments.
  • Ability to mentor junior engineers and lead cross-functional technical initiatives.

 

Additional Job Details (if applicable)

  • Hybrid role with onsite work required; candidates must be flexible based on weekly or monthly business needs.
  • Monday-Friday schedule during Eastern business hours.
  • On remote workdays, employees must work from a stable, secure, and compliant workstation in a quiet environment. Teams video is required and must be accessed using Mass General Brigham-provided equipment.

 

Remote Type

Hybrid  

Work Location

399 Revolution Drive  

Scheduled Weekly Hours

40  

Employee Type

Regular  

Work Shift

Day (United States of America)

 

Pay Range

$93,953.60 - $136,739.20/Annual  

Grade

7  

At Mass General Brigham, we believe in recognizing and rewarding the unique value each team member brings to our organization. Our approach to determining base pay is comprehensive, and any offer extended will take into account your skills, relevant experience if applicable, education, certifications and other essential factors. The base pay information provided offers an estimate based on the minimum job qualifications; however, it does not encompass all elements contributing to your total compensation package. In addition to competitive base pay, we offer comprehensive benefits, career advancement opportunities, differentials, premiums and bonuses as applicable and recognition programs designed to celebrate your contributions and support your professional growth. We invite you to apply, and our Talent Acquisition team will provide an overview of your potential compensation and benefits package.  

EEO Statement:

0100 Mass General Brigham Incorporated is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religious creed, national origin, sex, age, gender identity, disability, sexual orientation, military service, genetic information, and/or other status protected under law. We will ensure that all individuals with a disability are provided a reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. To ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Veteran’s Readjustment Act of 1974, and Title I of the Americans with Disabilities Act of 1990, applicants who require accommodation in the job application process may contact Human Resources at (857)-282-7642.  

Mass General Brigham Competency Framework

At Mass General Brigham, our competency framework defines what effective leadership “looks like” by specifying which behaviors are most critical for successful performance at each job level. The framework is comprised of ten competencies (half People-Focused, half Performance-Focused) and are defined by observable and measurable skills and behaviors that contribute to workplace effectiveness and career success. These competencies are used to evaluate performance, make hiring decisions, identify development needs, mobilize employees across our system, and establish a strong talent pipeline.

Similar roles