Senior Security Engineer

New Yesterday

At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes. Our cloud-based platform, StudyTeam, brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively. StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries. Join us in our mission to advance clinical research and improve patient care. One mission. One team. That's OneStudyTeam. We are seeking a Senior Security Engineer to become a leading subject matter expert on the security of modern web applications, APIs, cloud infrastructure, and corporate environment security. You will collaborate closely with technical advisors and staff engineers to assess the security of new applications, features, partner integrations, data flows, and internal configuration/administration tools. You will also lead incident response and vulnerability management efforts. What You'll Be Working On Assess the security of new applications, features, partner integrations, data flows, and internal configuration/administration tools in collaboration with data and software engineering teams. Develop solutions to enhance the security of our services and infrastructure on Azure and AWS, including mechanisms to identify and prevent security incidents and improve response times. Coordinate and validate remediation of vulnerabilities identified through third-party penetration testing and internal scans with engineering teams. Select, design, configure, and utilize vulnerability scanning technologies such as container scanning, SCA/SBOM, SAST, DAST, IAST, and RASP. Lead incident response efforts for web applications and infrastructure. Recommend and implement improvements to our Security Program, integrating it within the SDLC. Document security findings and outline mitigation strategies through formal risk assessments, delegating tasks to team members when appropriate. What You'll Bring to OneStudyTeam Seven or more years of experience in a dedicated technical security role. At least two years of experience with Azure. Five or more years of experience with Azure and AWS. Experience with Microsoft Sentinel or Exabeam SIEM. Experience with Crowdstrike. Proficiency in Python for data analysis and automation. Deep understanding of modern application stacks, including microservices, containerization, CI/CD, and IaC in cloud environments like AWS or Azure. Solid knowledge of OWASP Top 10, including attack vectors and mitigation strategies. Understanding of modern source control systems such as Git and GitHub. Desire to mentor team members and collaborate with senior engineers. Experience working with Data, Engineering, DevOps/SRE, and Product teams to assess security risks. Leading incident response or vulnerability management experience is a strong plus. We value the unique contributions of each team member and do not discriminate based on race, color, religion, gender, sexual orientation, age, marital status, veteran status, or disability. Note : OneStudyTeam cannot sponsor work visas at this time. Non-U.S. applicants should note that we work with a Professional Employer Organization. All employees must adhere to organizational security and privacy policies. This organization participates in E-Verify. E-Verify's Right to Work guidance can be found here .
#J-18808-Ljbffr
Location:
Boston, MA, United States
Salary:
$200,000 - $250,000
Category:
Engineering

We found some similar jobs based on your search