Security Engineer (Boston HQ)
WinnCompanies manages affordable housing communities and supports approximately 3,000 corporate and property-based employees. We are building out a maturing security program and seek a hands-on Security Engineer to help drive it forward as a core member of a lean security team.
About the role
Reporting to the Director of Information Security & Risk Management, you will work across core domains including identity and access management (IAM), third-party risk, and incident detection and response while strengthening overall security architecture and program strategy. You will collaborate with our internal IT team and managed security service provider (MSSP) to deploy, configure, and tune security tools, improve monitoring and alerting, and support incident response activities.
Responsibilities
- Identity & Access Management
- Administer and manage identity and access management (IAM) processes and tools across a large, distributed workforce.
- Manage the high-volume onboarding and offboarding process common in property management environments.
- Implement and tune access controls, role-based access, multi-factor authentication, and least-privilege practices.
- Support access reviews, partnering with IT and business owners to validate findings.
- Vendor & Third-Party Risk
- Conduct vendor and third-party risk assessments using the firm’s third-party assessment tool.
- Evaluate vendor security postures, document findings, track remediation, and advise stakeholders on acceptable risk.
- Help refine the third-party risk process and reporting as the program matures.
- Incident Detection & Response
- Serve as a key point of contact for security incident detection and response, working alongside our managed detection and response (MDR) provider.
- Triage, investigate, and coordinate response to alerts.
- 24/7 on-call for incidents escalated by the MDR service.
- Contribute to and help mature incident response playbooks, runbooks, and post-incident reviews.
- Program Development & Implementation
- Work directly with the Director of Information Security & Risk Management to shape the strategy, roadmap, and priorities of the security program.
- Work with internal IT and the IT MSSP to implement, configure, and operate security tools and controls.
- Contribute to policy development, security awareness training, and compliance-supporting activities as needed.
- Take on related security responsibilities as the program evolves.
Requirements
- 2–5 years of hands-on experience in security engineering, security operations, IT security, or a closely related role.
- Practical experience with identity and access management concepts and tooling (e.g., directory services, SSO, MFA, user provisioning/deprovisioning).
- Experience working with security incident detection and response tools, including SIEM, EDR, or MDR services.
- Understanding of third-party / vendor risk assessment principles.
- Proven ability to collaborate effectively with internal IT teams and external service providers (MSSP, MDR).
- Strong written and verbal communication skills, with the ability to clearly document findings and articulate risks to non-technical stakeholders.
- Self-directed and capable of working independently, demonstrating a strong problem-solving mindset in a lean and rapidly growing security program.
Preferred Qualifications
- Experience supporting a large or distributed workforce, ideally across multiple physical sites.
- Hands-on experience implementing controls for the protection of sensitive data (PII).
- Familiarity with common security and privacy frameworks (e.g., NIST CSF, CIS Controls) and associated regulatory considerations.
- Relevant certifications such as Security+, SSCP, GSEC, or progress toward CISSP.
- Experience using scripting or automation tools (e.g., PowerShell, Python) to streamline IAM and security operational tasks.
Benefits
- Generous time off policies (including 11 paid holidays (12 for MA employees); accrued time off increasing with years of service; paid sick time; annual day of service; floating holiday).
- 401(k) plan options with a company match.
- Comprehensive medical, dental, and vision plan options.
- Flexible Spending Account, Dependent Care Flexible Spending Account, Health Savings Account options with HSA annual employer contribution.
- Long-term disability and voluntary short-term disability; basic term life insurance and AD&D; optional supplemental life insurance.
- Health expense reimbursement program (including gym memberships, equipment, and subscriptions).
- Tuition reimbursement program and continuous training and development opportunities.
- Wellbeing program (group challenges, seminars, opportunities to earn points to reduce medical premiums), Employee Assistance Program, and commuter and parking reimbursement options.
- Employee corporate discount programs.
- Flexible and/or hybrid schedules available for certain roles.
- Employee Relief Program supporting employees with unexpected hardships.
Pay
The salary range for this role is $80,000 to $110,000 per year, dependent on experience.
About Us
WinnCompanies is a mission-driven, national business focused on building and operating top-quality affordable housing communities for individuals and families of all incomes, including members of the U.S. Armed Forces and their families. Our team of 4,300+ employees works together to create the best possible living communities in 27 states, Washington, D.C., and Puerto Rico.