InfoSec Engineer III Pentesting Program Lead

3 months ago


Somerville, United States Partners HealthCare Full time

Description

About Us: 

As a not-for-profit organization, Mass General Brigham is committed to supporting patient care, research, teaching, and service to the community by leading innovation across our system. Founded by Brigham and Women’s Hospital and Massachusetts General Hospital, Mass General Brigham supports a complete continuum of care including community and specialty hospitals, a managed care organization, a physician network, community health centers, home care and other health-related entities. Several of our hospitals are teaching affiliates of Harvard Medical School, and our system is a national leader in biomedical research.

We’re focused on a people-first culture for our system’s patients and our professional family. That’s why we provide our employees with more ways to achieve their potential. Mass General Brigham is committed to aligning our employees’ personal aspirations with projects that match their capabilities and creating a culture that empowers our managers to become trusted mentors. We support each member of our team to own their personal development—and we recognize success at every step.

Our employees use the Mass General Brigham values to govern decisions, actions and behaviors. These values guide how we get our work done: Patients, Affordability, Accountability & Service Commitment, Decisiveness, Innovation & Thoughtful Risk; and how we treat each other: Diversity & Inclusion, Integrity & Respect, Learning, Continuous Improvement & Personal Growth, Teamwork & Collaboration.

General Summary/ Overview: 

The Mass General Brigham (MGB) Information Security Engineer III – Attack Surface Management Lead will be responsible for leading initiatives related to the identification, validation, and evaluation of attack surface risks across our digital and physical technology environments, measuring defensive resilience against emerging threats. This role will also require the technical testing of security controls deployed throughout the environment to confirm defenses are functioning as expected; or lead efforts to mitigate risks where necessary. The ideal candidate will be deeply technical minded security professional with prior experience in one or more of the following areas:

· Penetration testing

· Web application security testing

· Vulnerability management

· Application development security 

· Incident response

· Security controls validation

· Scripting languages 

Principal Duties and Responsibilities: 

· Attack Surface Analysis: Conduct comprehensive assessments to identify risks within the organization's network, applications, and systems. This includes both internal and external assets.

· Threat Intelligence Integration: Leverage threat intelligence to anticipate and prepare for emerging threats. Ensure that relevant threat intelligence is integrated into the assessment of the attack surface.

· Vulnerability Management: Integrate with and support existing vulnerability management processes, including identification, evaluation, mitigation, and reporting of security vulnerabilities. 

· Cross-functional Collaboration: Work closely with IT, network, and application teams to ensure a cohesive approach to security. Facilitate communication and collaboration across departments to ensure alignment with security goals.

· Incident Response Support: Support the incident response team by providing insights into potential attack vectors and vulnerabilities that may be exploited during a cyber incident.

· Team Leadership and Development: Lead, mentor, and develop a team of security professionals. Foster a culture of continuous learning and improvement.

· Written Documentation: Create, review, and update documentation related to the information security and information privacy controls.

· Strategic Planning: Lead efforts to drive strategic change initiatives designed to mitigate attack surface risks across the enterprise.

· Communication: Clear and concise written and verbal communication including long-form documentation, enterprise broadcast communications, and executive presentations; special attention required to translate technical detail into language the intended audience can understand.

· Industry Knowledge: Maintain awareness of new technologies and related opportunities for impact on system or application security.

· MGB Values: Use/s the Mass General Brigham values to govern decisions, actions and behaviors. These values guide how we get our work done: Patients, Affordability, Accountability & Service Commitment, Decisiveness, Innovation & Thoughtful Risk; and how we treat each other: Diversity & Inclusion, Integrity & Respect, Learning, Continuous Improvement & Personal Growth, Teamwork & Collaboration.

· Other duties as assigned.

Working Conditions:  
· FTE

· Normal Office conditions in Hybrid Remote/Office Context

· Possible local travel to Mass General Brigham sites 

· While performing the duties of this job, the employee is frequently required to sit; talk; or hear; use hands to finger; handle; or feel; reach with hands and arms. The employee is occasionally required to stand; walk; and stoop; kneel; or crouch. The employee must frequently lift and/or move up to 5 pounds and occasionally lift and/or move up to 20 pounds. Specific vision abilities required by this job include close vision, distance vision and depth perception.

· The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Normal office working conditions. The noise level in the work environment is quiet to moderate.

Qualifications

· Bachelor’s degree (B.A. / B.S.) in Information Security, Computer Science, Computer Engineering or equivalent from an accredited college or university required.

· 5+ years of experience in Information Technology or Information Security required.

· ​​Broad general understanding of cybersecurity concepts. 

· ​Basic knowledge of tools used in day-to-day processes with ability to learn new tools and skills. 

· ​Ability to apply defined processes to resolve a wide variety of issues. 

· ​Critical thinking and problem-solving skills sufficient to identify and communicate key issues or understand when escalation support is required. 

· ​An understanding of business needs and commitment to delivering high-quality, prompt and efficient service to the business. 

· ​Ability to collaborate effectively with team members, providing assistance and support as needed.​ 

· Knowledge of NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27K, is desirable.

· Preferred certifications include: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), GIAC Penetration Tester Certification (GPEN), GIAC Experienced Penetration Tester (GX-PT), GIAC Certified Red Team Professional (GRTP), GIAC Security Operations Certified (GSOC), GIAC Security Expert (GSE), etc.

Skills/Abilities/Competencies: 

· Possess strong interpersonal skills to effectively communicate with cross functional teams.

· Strong time management and organizational skills required, project management skills are desired.

· An ability to work under the required guidelines and deliver on business/project requirements.

· Strong vocabulary, written and verbal communication and effective interpersonal skills is critical.

· Comfortable working in a dynamic environment with multiple work streams, goals, and objectives.

· Must know how to use common M365 Office Suite of products.

· Ability to work independently with appropriate supervision.

· Ability to successfully negotiate and collaborate with others of different skill sets, backgrounds an levels within and external to the organization.

· Experience in one or more of the following technologies preferred: endpoint detection and response (EDR), vulnerability scanners, static and dynamic source-code analysis, SIEM, privileged access management (PAM), network technologies, cloud hosting platforms, IoT search engines, OSINT tools, etc.

· Strong problem solving and critical thinking skills.



  • Somerville, United States AbbVie Full time

    Company Description AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas immunology, oncology, neuroscience, and eye care and products and services in our...


  • Somerville, Massachusetts, United States Formlabs Full time

    About the RoleWe are seeking a highly experienced Senior Advanced Manufacturing Engineering Manager to join our global headquarters team in Boston. As a key member of our manufacturing team, you will be responsible for leading the activities of a team of manufacturing engineering professionals responsible for supporting an extended team of global...


  • Somerville, Massachusetts, United States Formlabs Full time

    Manufacturing Test Manager Department: Manufacturing To transform an industry, assembling the finest team is essential. Formlabs is at the forefront of delivering innovative professional 3D printers to designers, engineers, researchers, and artists globally. Our teams are responsible for developing the mechanical and software components that operate in our...


  • Somerville, Massachusetts, United States Formlabs Full time

    Join Formlabs as a Lead Advanced Manufacturing Engineering StrategistTo transform an industry, assembling a remarkable team is crucial. At Formlabs, you will play a pivotal role in making state-of-the-art professional 3D printers accessible to designers, engineers, researchers, and artists worldwide.Our manufacturing team is passionate about developing...


  • Somerville, United States Russell Tobin Full time

    Russell Tobin has a need for a Electrical Staff Engineer (Oil and Gas, steel or refinery) in PA or Somerville, NJ! This is a direct hire position.Salary range: 95k-120kLocations: Wexford, PA - Bethlehem, PA - Wilkes-Barre, PA or Somerville, NJ. This is a hybrid position!Job Description:The Client Company is a national consulting group seeking a talented...


  • Somerville, United States Russell Tobin Full time

    Russell Tobin has a need for a Electrical Staff Engineer (Oil and Gas, steel or refinery) in PA or Somerville, NJ! This is a direct hire position.Salary range: 95k-120kLocations: Wexford, PA - Bethlehem, PA - Wilkes-Barre, PA or Somerville, NJ. This is a hybrid position!Job Description:The Client Company is a national consulting group seeking a talented...


  • Somerville, Massachusetts, United States RISE Robotics Full time

    Position OverviewRISE Robotics, a pioneering technology firm established by MIT and RISD graduates, is at the forefront of creating zero-emission heavy machinery. Our mission is to replace traditional hydraulic systems with innovative, efficient alternatives. We are seeking a dedicated and experienced Senior Manager, Test Engineering & Reliability to play a...


  • Somerville, United States Flagship Ventures Full time

    What if you could join a rapidly growing company and play a critical role in bringing new medicines to patients through looking at and treating disease in a revolutionary way? What this position is all about : The Genomics team at Cellarity Inc. seeks a Laboratory Automation Engineer to work as the primary engineering resource at a small (100 person) and...


  • Somerville, Massachusetts, United States Formlabs Full time

    Lead Strategist for Advanced Manufacturing EngineeringDepartment: ManufacturingLocation: Somerville, MAAre you driven by a passion for innovation and eager to join a team that is transforming the landscape of professional 3D printing? At Formlabs, we aim to democratize access to cutting-edge 3D printing technology for designers, engineers, researchers, and...


  • Somerville, United States Flagship Ventures Full time

    What if you could join a rapidly growing company and play a critical role in bringing new medicines to patients through looking at and treating disease in a revolutionary way? What this position is all about: Genomics team at Cellarity Inc. seeks a Laboratory Automation Engineer to work as the primary engineering resource at a small (100 person) and growing...


  • Somerville, Massachusetts, United States Formlabs Full time

    Department: ManufacturingLocation: Somerville, MAAt Formlabs, we are dedicated to transforming the 3D printing landscape by assembling a world-class team. Our mission is to deliver innovative professional 3D printers to designers, engineers, researchers, and artists globally.Our enthusiasm lies in crafting and developing cutting-edge 3D printing...


  • Somerville, Massachusetts, United States RISE Robotics Full time

    Job OverviewRISE Robotics, established by MIT and RISD graduates, is a rapidly expanding technology firm focused on revolutionizing heavy machinery through innovative, zero-emission solutions. Our commitment to sustainability drives us to develop the most efficient alternatives to traditional hydraulic systems, collaborating with top-tier suppliers, OEMs,...


  • Somerville, Massachusetts, United States RISE Robotics Full time

    Job OverviewRISE Robotics, established by MIT and RISD graduates, is at the forefront of innovation in Zero Emission heavy machinery. We are dedicated to transforming traditional hydraulic systems into more efficient and sustainable alternatives. Our partnerships with Tier 1 suppliers, OEMs, and the US Department of Defense are pivotal in this...


  • Somerville, Massachusetts, United States Google Full time

    Minimum qualifications:Bachelor's degree or equivalent practical experience.5 years of experience in software engineering across various programming languages, alongside expertise in data structures and algorithms. 3 years of experience in testing, maintaining, or launching software products, with at least 1 year in software design and architecture.Preferred...


  • Somerville, Massachusetts, United States Google Full time

    Minimum qualifications:Bachelor's degree or equivalent practical experience.5 years of experience in software development utilizing one or more programming languages, along with expertise in data structures and algorithms. 3 years of experience in testing, maintaining, or launching software products, and at least 1 year of experience in software design and...


  • Somerville, Massachusetts, United States Novartis Full time

    Company OverviewNovartis Institutes for BioMedical Research (NIBR) stands as the global pharmaceutical research arm of Novartis. With a workforce of around 6,000 scientists and medical professionals worldwide, our focus is on pioneering innovative medications that transform healthcare.Culture and MissionAt NIBR, we foster an open and entrepreneurial...


  • Somerville, Massachusetts, United States Novartis Full time

    Company OverviewNovartis Institutes for BioMedical Research (NIBR) is the global pharmaceutical research arm of Novartis. With a workforce of approximately 6,000 scientists and physicians worldwide, our research is dedicated to the discovery of groundbreaking new medications that will transform medical practices.Culture and MissionWe foster an open and...


  • Somerville, Massachusetts, United States Novartis Full time

    Company OverviewNovartis Institutes for BioMedical Research (NIBR) stands as the global pharmaceutical research arm of Novartis. With a dedicated team of approximately 6,000 scientists and physicians worldwide, our focus is on pioneering innovative therapies that transform medical practices.Our CultureWe foster an open and entrepreneurial environment that...


  • Somerville, Massachusetts, United States Google Full time

    Minimum qualifications:Bachelor's degree or equivalent practical experience.5 years of experience in software development using one or more programming languages, along with a solid understanding of data structures and algorithms. 3 years of experience in testing, maintaining, or launching software products, and at least 1 year of experience in software...


  • Somerville, Massachusetts, United States Google Full time

    Minimum qualifications:Bachelor's degree or equivalent practical experience.5 years of experience in software development utilizing one or more programming languages, along with a strong foundation in data structures and algorithms. Additionally, 3 years of experience in testing, maintaining, or launching software products, and at least 1 year of experience...