New
Information Security Engineer III, Application Security Lead
![]() | |
![]() United States, Massachusetts, Somerville | |
![]() 399 Revolution Drive (Show on map) | |
![]() | |
Summary
The Information Security Engineer III assumes a leadership role within their security team at Mass General Brigham. The Information Security Engineer III is tasked with designing and implementing innovative security solutions while also optimizing existing security infrastructure. They are adept at leading complex projects, coordinating efforts across teams, and overseeing the work of junior engineers. In this capacity, the Information Security Engineer III provides technical guidance and mentorship to team members, fostering their professional development. The Information Security Engineer III may represent the organization in industry forums or regulatory discussions. Additionally, this role actively engages with external partners, vendors, and stakeholders to establish collaborative security strategies and ensure alignment with industry trends and best-in-class security practices. The Mass General Brigham (MGB) Information Security Engineer III - Application Security Lead will be responsible for elevating the existing foundations of the MGB Application Security capability. This role will be involved in the implementation of a secure coding process and pipeline through interfacing with developers and relevant stakeholders, implementing application security scanning technologies at appropriate levels, policy creation for developers to adhere to, and leading other engineers in the execution of the program. The ideal candidate is a deeply technical minded security professional focused on secure coding practices or development engineering with experience designing and executing strategic / programmatic roadmaps. They should have prior experience in one or more of the following areas: *Strategic program build and design *Secure Code Development *Application Security Testing Tools *CI/CD Pipeline Hardening *Application and Code Vulnerability Analysis Duties include *Programmatic Vision: Collaboratively design the application security program to meet the needs of Mass General Brigham. Lead engineers in the execution of the strategic roadmap. *Static Code Analysis: Implement and maintain static analysis tools to identify security vulnerabilities in code before deployment. Collaborate with development teams to integrate these tools into workflows and provide actionable insights to remediate identified issues, fostering a proactive approach to secure coding practices. *Compiled Binary Analysis: Perform analysis of compiled binaries to detect potential security flaws and hidden vulnerabilities. Support cross-functional teams by translating complex findings into actionable recommendations, ensuring alignment with the organization's security standards and incident response capabilities. *Open Source Library Analysis: Monitor and assess open source libraries and dependencies for known vulnerabilities and licensing risks. Work closely with development teams to address these risks promptly and maintain updated documentation, helping safeguard applications against supply chain threats. *CI/CD Pipeline Hardening: Strengthen the security of CI/CD pipelines by implementing robust controls, such as automated security testing, access management, and secret protection. Collaborate with DevOps teams to ensure secure integration and delivery processes, while documenting best practices for ongoing improvement *Cross-functional Collaboration: Work closely with IT, network, and application teams to ensure a cohesive approach to security. Facilitate communication and collaboration across departments to ensure alignment with security goals. *Incident Response Support: Support the incident response team by providing insights into potential attack vectors and vulnerabilities that may be exploited during a cyber incident. *Written Documentation: Create, review, and update documentation related to the information security and information privacy controls. *Communication: Clear and concise written and verbal communication including long-form documentation, enterprise broadcast communications, and executive presentations; special attention required to translate technical detail into language the intended audience can understand. *Industry Knowledge: Maintain awareness of new technologies and related opportunities for impact on system or application security. *MGB Values: Uses the Mass General Brigham values to govern decisions, actions and behaviors. These values guide how we get our work done: Patients, Affordability, Accountability & Service Commitment, Decisiveness, Innovation & Thoughtful Risk; and how we treat each other: Diversity & Inclusion, Integrity & Respect, Learning, Continuous Improvement & Personal Growth, Teamwork & Collaboration. *Other duties as assigned.
Skills for Success
Mass General Brigham Incorporated is an Equal Opportunity Employer. By embracing diverse skills, perspectives and ideas, we choose to lead. All qualified applicants will receive consideration for employment without regard to race, color, religious creed, national origin, sex, age, gender identity, disability, sexual orientation, military service, genetic information, and/or other status protected under law. We will ensure that all individuals with a disability are provided a reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. |