Full-Time

Senior Security Engineer

Harvard University

Harvard University

No salary listed

No H1B Sponsorship

Boston, MA, USA

Hybrid

Hybrid role; when not on Harvard site, work must be in a Harvard registered state.

Bachelor's

Category
IT & Security (1)
Required Skills
Vulnerability Analysis
Penetration Testing
Requirements
  • Minimum of seven years’ post-secondary education or relevant work experience.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field; or equivalent combination of education and relevant experience.
  • Experience using common security testing and analysis tools.
  • Ability to communicate technical security findings and remediation recommendations to both technical and non-technical audiences.
  • Hands-on experience performing penetration testing of web applications, systems, networks, cloud environments, or APIs.
  • Familiarity with common offensive security tools, techniques, and methodologies.
  • Experience identifying, validating, and helping remediate common web application vulnerabilities (OWASP Top 10).
  • Experience with Secure SDLC concepts and application security testing tools such as Checkmarx, Burp Suite, Veracode, GitHub Advanced Security, or similar platforms.
  • Experience administering or supporting application security platforms (preferred).
  • Familiarity with software development practices and modern application architectures.
  • Experience conducting threat research and analyzing emerging threats, vulnerabilities, attack techniques, and adversary activity.
  • Experience creating technical reports and communicating security findings and remediation recommendations.
  • Demonstrated analytical, problem-solving, and technical investigation skills.
  • Demonstrated team performance skills, service-oriented mindset, and ability to collaborate effectively with technical and non-technical stakeholders.
  • Strong desire to continuously learn and develop expertise in offensive security, application security, and emerging technologies.
Responsibilities
  • Perform penetration testing of applications, systems, infrastructure, cloud environments, and emerging technologies.
  • Identify security weaknesses and provide remediation recommendations through technical testing.
  • Support Secure SDLC initiatives and collaborate with development teams to improve application security.
  • Administer and support application security platforms and testing tools.
  • Assist with implementation and operation of SAST, SCA, DAST, API Security, Secrets Detection, and related application security capabilities.
  • Conduct threat research and stay current on emerging attack techniques, vulnerabilities, adversary activity, and security trends.
  • Inform the organization of emerging threats, attack techniques, vulnerabilities, and risks.
  • Serve as an information security subject matter expert in penetration testing and application security.
  • Research, evaluate, and recommend new security tools, technologies, and processes that improve HMS security capabilities.
  • Abide by and follow Harvard University IT technical standards, policies, and Code of Conduct.
Desired Qualifications
  • Participation in cyber competitions (CTFs), cyber ranges, security research projects, bug bounty programs, red team exercises, or similar activities is highly desirable.
  • Completion of Harvard IT Academy Information Security Foundations course (or external equivalent) preferred.
  • IT Security Certification preferred; e.g., OSCP, CSSLP, GIAC GWAPT, CISSP, PenTest+

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A