Jobs and Careers
United Statesfull_timeVerifiedPosted 9 Mar 2026
💰 $94,000/yr($91,000/yr$94,000/yr)

About the role

Security Engineer

Department: Information Technology

Employment Type: Permanent - Full Time

Location: Downtown Boston - Tremont Street

Compensation: $91,000 - $94,000 / year


Description

The Information Security Engineer is responsible for safeguarding ABCD’s systems, networks, and sensitive client and employee information across a 40+ site, multi-program environment.

This role serves as ABCD’s primary internal cybersecurity subject matter expert. The Engineer leads security operations, incident response, risk management, and security program development while strengthening the organization’s overall cybersecurity maturity. The position combines hands-on technical execution with practical governance and risk oversight to support mission-critical community services.




Key Responsibilities

Security Operations & Monitoring
  • Monitor, investigate, and respond to security alerts across cloud and on-premises systems.
  • Maintain and improve detection rules, alerting, and response playbooks.
  • Oversee log visibility and security monitoring across identity, endpoint, email, and network systems.

Incident Response & Investigation
  • Lead end-to-end incident response (phishing, malware, account compromise, data exposure, suspicious activity).
  • Coordinate containment, eradication, recovery, documentation, and post-incident reviews.
  • Conduct periodic incident response exercises and ensure lessons learned result in strengthened controls.
  • Escalate significant risk conditions to ITS leadership with clear remediation recommendations.

Vulnerability & Risk Management
  • Manage vulnerability scanning, remediation tracking, and risk prioritization.
  • Partner with infrastructure and support teams to ensure timely patching and mitigation.
  • Conduct risk assessments for new systems, integrations, and cloud services.
  • Maintain secure configuration baselines aligned with recognized frameworks (NIST, CIS Controls).

Identity, Access & Data Protection
  • Strengthen identity and access management controls (MFA, conditional access, privileged access, lifecycle management).
  • Maintain least-privilege standards and periodic access reviews.
  • Advance data protection practices including encryption, secure sharing, and retention controls.
  • Support data classification and protection of highly sensitive program information.

Governance, Compliance & Reporting
  • Develop and maintain security policies, standards, and procedures.
  • Support compliance with applicable federal, state, and grant-based cybersecurity and privacy requirements.
  • Coordinate security documentation required for audits and cyber insurance renewals.
  • Track and report key security metrics and risk trends to ITS leadership.
  • Contribute to the development of a multi-year cybersecurity roadmap aligned with organizational risk.

Security Awareness & Risk Reduction
  • Deliver or coordinate security awareness initiatives, including phishing simulations.
  • Improve secure email handling and reporting workflows across the organization.
  • Partner with program leadership to reinforce secure practices in field and client-facing environments.

Third-Party & Vendor Risk
  • Conduct security reviews of vendors and systems (questionnaires, SOC reports, risk analysis).
  • Track vendor remediation commitments and contract-related security obligations.

Business Continuity & Disaster Recovery
  • Support business impact analysis and recovery planning.
  • Coordinate backup validation and participate in recovery testing to ensure operational resilience.

Technology Environment (Examples)

Experience with some of the following is helpful (not all required):
  • Google Workspace security and administration
  • Endpoint security / EDR and device management
  • Network security appliances, firewalls, VPN, DNS filtering
  • Vulnerability management platforms
  • SIEM or centralized log management tools


Skills, Knowledge and Expertise

  • 3–7 years of progressive experience in security engineering, security operations, or IT security administration.
  • Strong working knowledge of identity and access management, endpoint security, email security, network fundamentals, vulnerability management, and incident response.
  • Demonstrated ability to translate

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Action for Boston Community Development

View company profile →