Senior Security Engineer

Posted 3 Days Ago
Be an Early Applicant
Boston, MA, USA
Hybrid
Senior level
Edtech
The Role
Lead application and offensive security efforts: perform penetration tests across apps, systems, cloud, and APIs; operate and support AppSec testing platforms (SAST/DAST/SCA); conduct threat research; recommend remediation; partner with development and SecOps to mature Secure SDLC and incident response capabilities.
Summary Generated by Built In
Company Description

By working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expertise. We are dedicated to creating a diverse and welcoming environment where everyone can thrive.

Why join Harvard Medical School?

Harvard Medical School's mission is to nurture a diverse, inclusive community dedicated to alleviating suffering and improving health and well-being for all through excellence in teaching and learning, discovery and scholarship, and service and leadership.

You’ll be at the heart of biomedical discovery, education, and innovation, working alongside world-renowned faculty and a community dedicated to improving human health. This is more than a job - it’s an opportunity to shape the future of medicine.

Job Description

The Senior Security Engineer will have responsibility for supporting and advancing Harvard Medical School's application security, Secure SDLC, and penetration testing programs. This role will partner closely with others across HMS IT and Security to enable the HMS mission by implementing Secure SDLC practices, operating application security testing platforms, identifying security weaknesses through penetration testing, and collaborating with development teams to improve security throughout the software lifecycle. On a daily basis, this role will perform penetration testing of applications, systems, and emerging technologies; support the administration of application security platforms; conduct threat research; identify security risks and remediation opportunities; and help mature the organization's application security capabilities. This role will partner with SecOps when required during security incidents and investigations. The Senior Security Engineer, as part of the IT Security team, will partner with others across Security and IT to establish strategic and tactical roadmaps and help mature application and offensive security capabilities.

Principal duties and responsibilities:

  • Perform penetration testing of applications, systems, infrastructure, cloud environments, and emerging technologies.
  • Identify security weaknesses and provide remediation recommendations through technical testing.
  • Support Secure SDLC initiatives and collaborate with development teams to improve application security.
  • Administer and support application security platforms and testing tools.
  • Assist with implementation and operation of SAST, SCA, DAST, API Security, Secrets Detection, and related application security capabilities.
  • Conduct threat research and stay current on emerging attack techniques, vulnerabilities, adversary activity, and security trends.
  • Inform the organization of emerging threats, attack techniques, vulnerabilities, and risks.
  • Serve as an information security subject matter expert in penetration testing and application security.
  • Research, evaluate, and recommend new security tools, technologies, and processes that improve HMS security capabilities.
  • Abide by and follow Harvard University IT technical standards, policies, and Code of Conduct.

Qualifications

Basic Qualifications:

  • Minimum of seven years’ post-secondary education or relevant work experience.

Additional Qualifications and Skills:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field; or equivalent combination of education and relevant experience.
  • Experience using common security testing and analysis tools.
  • Ability to communicate technical security findings and remediation recommendations to both technical and non-technical audiences.
  • Hands-on experience performing penetration testing of web applications, systems, networks, cloud environments, or APIs.
  • Familiarity with common offensive security tools, techniques, and methodologies.
  • Experience identifying, validating, and helping remediate common web application vulnerabilities (OWASP Top 10).
  • Experience with Secure SDLC concepts and application security testing tools such as Checkmarx, Burp Suite, Veracode, GitHub Advanced Security, or similar platforms.
  • Experience administering or supporting application security platforms preferred.
  • Familiarity with software development practices and modern application architectures.
  • Experience conducting threat research and analyzing emerging threats, vulnerabilities, attack techniques, and adversary activity.
  • Experience creating technical reports and communicating security findings and remediation recommendations.
  • Participation in cyber competitions (CTFs), cyber ranges, security research projects, bug bounty programs, red team exercises, or similar activities is highly desirable.
  • Demonstrated analytical, problem-solving, and technical investigation skills.
  • Demonstrated team performance skills, service-oriented mindset, and ability to collaborate effectively with technical and non-technical stakeholders.
  • Strong desire to continuously learn and develop expertise in offensive security, application security, and emerging technologies.

Certificates and Licenses:

  • Completion of Harvard IT Academy Information Security Foundations course (or external equivalent) preferred.
  • IT Security Certification preferred; e.g., OSCP, CSSLP, GIAC GWAPT, CISSP, PenTest+

Additional Information

  • Standard Hours/Schedule: 35 hours per week
  • Visa Sponsorship Information: Harvard University is unable to provide visa sponsorship for this position.
  • Pre-Employment Screening: Identity, Criminal
  • Staying Informed About Your Application: Due to the high volume of applications, we may not always be able to reach out right away, but you can track your status anytime through the Careers@Harvard portal.

#LI-DK1

Work Format Details

This position has been determined by school or unit leaders that some of the duties and responsibilities can be effectively performed at a non-Harvard location. The work schedule and location will be set by the department at its discretion and based upon operational needs. When not working at a Harvard or Harvard-designated location, employees in hybrid positions must work in a Harvard registered state in compliance with the University’s Policy on Employment Outside of Massachusetts. Additional details will be discussed during the interview process. Certain visa types and funding sources may limit work location. Individuals must meet work location sponsorship requirements prior to employment.

Salary Grade and Ranges

This position is salary grade level 059. Please visit  Harvard's Salary Ranges  to view the corresponding salary range and related information. 

Benefits

Harvard offers a comprehensive benefits package that is designed to support a healthy work-life balance and your physical, mental and financial wellbeing. Because here, you are what matters. Our benefits include, but are not limited to: 

  • Generous paid time off including parental leave 
  • Medical, dental, and vision health insurance coverage starting on day one 
  • Retirement plans with university contributions 
  • Wellbeing and mental health resources 
  • Support for families and caregivers 
  • Professional development opportunities including tuition assistance and reimbursement 
  • Commuter benefits, discounts and campus perks 

Learn more about these and additional benefits on our Benefits & Wellbeing Page. 

EEO/Non-Discrimination Commitment Statement

Harvard University is committed to equal opportunity and non-discrimination. We seek talent from all parts of society and the world, and we strive to ensure everyone at Harvard thrives. Our differences help our community advance Harvard's academic purposes.

Harvard has an equal employment opportunity policy that outlines our commitment to prohibiting discrimination on the basis of race, ethnicity, color, national origin, sex, sexual orientation, gender identity, veteran status, religion, disability, or any other characteristic protected by law or identified in the university's non-discrimination policy. Harvard's equal employment opportunity policy and non-discrimination policy help all community members participate fully in work and campus life free from harassment and discrimination.

Skills Required

  • Minimum of seven years' post-secondary education or relevant work experience.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field; or equivalent experience.
  • Experience using common security testing and analysis tools.
  • Hands-on experience performing penetration testing of web applications, systems, networks, cloud environments, or APIs.
  • Familiarity with common offensive security tools, techniques, and methodologies.
  • Experience identifying, validating, and helping remediate common web application vulnerabilities (OWASP Top 10).
  • Experience with Secure SDLC concepts and application security testing tools such as Checkmarx, Burp Suite, Veracode, GitHub Advanced Security, or similar platforms.
  • Ability to communicate technical security findings and remediation recommendations to technical and non-technical audiences.
  • Familiarity with software development practices and modern application architectures.
  • Experience conducting threat research and analyzing emerging threats, vulnerabilities, and attack techniques.
  • Experience creating technical reports and communicating security findings and remediation recommendations.
  • Demonstrated analytical, problem-solving, and technical investigation skills.
  • Demonstrated team performance skills, service-oriented mindset, and ability to collaborate with technical and non-technical stakeholders.
  • Experience administering or supporting application security platforms.
  • Participation in CTFs, cyber ranges, security research projects, bug bounty programs, red team exercises, or similar activities.
  • Completion of Harvard IT Academy Information Security Foundations course (or external equivalent).
  • IT Security Certification preferred; e.g., OSCP, CSSLP, GIAC GWAPT, CISSP, PenTest+.

Harvard Business School Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Harvard Business School and has not been reviewed or approved by Harvard Business School.

  • Leave & Time Off Breadth Time off is considered broad, covering vacation, sick and personal days, numerous paid holidays including a winter recess, and paid parental leave. This breadth is positioned as a core part of the total rewards package.
  • Healthcare Strength Health coverage includes multiple medical plan options alongside dental, vision, FSAs/HSAs, and specialized support for high medical costs. This range of options is framed as competitive with large private employers.
  • Retirement Support Retirement programs include a university tax‑deferred 403(b) with automatic enrollment and escalation plus additional pension/retirement programs for eligible groups. These features are presented as part of a strong long‑term financial benefits offering.

Harvard Business School Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
Year Founded: 1908

What We Do

Founded in 1908 as part of Harvard University, Harvard Business School is located on a 40-acre campus in Boston. Its faculty of more than 250 offers full-time programs leading to the MBA and PhD degrees, as well as more than 175 Executive Education programs, and Harvard Business School Online, the School’s digital learning platform. For more than a century, faculty have drawn on their research, their experience in working with organizations worldwide, and their passion for teaching, to educate leaders who make a difference in the world. The School and its curriculum attract the boldest thinkers and the most collaborative learners who will go on to shape the practice of business and entrepreneurship around the globe. Community Guidelines: We may hide or block persons or hide or delete comments that include obscenities or are explicit, are spam or duplicate posts, spread misinformation, are irrelevant to the post, or are otherwise deemed inappropriate.

Similar Jobs

Braze Logo Braze

Senior Security Engineer

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
Boston, MA, USA
2000 Employees
149K-261K Annually

Crexi Logo Crexi

Senior Security Engineer

Real Estate • Sales • Software • PropTech
Easy Apply
Remote or Hybrid
United States
400 Employees
167K-227K Annually
In-Office or Remote
50 Locations
17989 Employees
103K-165K Annually
In-Office or Remote
4 Locations
20990 Employees
55K-122K Hourly

Similar Companies Hiring

ReUp Education Thumbnail
Social Impact • Edtech
Austin, TX
180 Employees
Learneo Thumbnail
Software • Machine Learning • Edtech • Artificial Intelligence
NL
397 Employees
CodePath.org Thumbnail
Edtech • Social Impact
San Francisco, CA
55 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account