Information Security Engineer III

Mass General BrighamSomerville, MA
$93,954 - $136,739Hybrid

About The Position

Mass General Brigham is seeking an Information Security Engineer III to serve as a senior leader within the Digital Information Security Architecture team. In this role, you will evaluate a wide variety of technologies, business initiatives, operational processes, and strategic projects to identify security risks and provide practical, risk-based guidance. Working closely with technical teams, business stakeholders, vendors, and security professionals, you will help ensure that security considerations are incorporated into decision making throughout the organization. The ideal candidate possesses strong analytical and problem-solving abilities, can rapidly develop an understanding of unfamiliar technologies and business challenges, and is comfortable working across a diverse range of technical and operational domains. Success in this role requires exceptional analytical, communication, and consulting skills. The ideal candidate can rapidly understand unfamiliar technologies and business challenges, identify meaningful cybersecurity risks, develop practical recommendations, and clearly articulate those recommendations to both technical and non-technical audiences. You will help shape security strategy, support enterprise initiatives, evaluate emerging technologies, contribute to organizational security standards, and serve as a trusted advisor on cybersecurity matters. As a senior member of the team, you will also mentor junior and mid-level employees and help foster a culture of collaboration, sound judgment, and continuous learning.

Requirements

  • Bachelor's degree in Computer Science or a related field required; equivalent experience may be accepted in lieu of a degree.
  • 5-7 years of experience as a systems engineer, security engineer, security architect, cybersecurity consultant, or in a related role required.
  • Strong understanding of cybersecurity principles, risk management concepts, and industry-standard security frameworks.
  • Demonstrated ability to rapidly understand new technologies, business processes, and operational environments and evaluate their security implications.
  • Experience performing security assessments, architecture reviews, risk analyses, technology evaluations, or similar analytical activities.
  • Ability to identify complex security issues, evaluate potential solutions, and develop practical, risk-based recommendations.
  • Strong knowledge of enterprise technologies, including familiarity with cloud platforms, identity and access management, networking, applications, infrastructure, security operations, and emerging technologies.
  • Understanding of security concepts such as Zero Trust, least privilege, defense-in-depth, data protection, secure software development, threat modeling, and vulnerability management.
  • Strong verbal communication and presentation skills, including the ability to explain complex technical concepts, influence stakeholders, and facilitate productive discussions.
  • Strong analytical, critical-thinking, and problem-solving skills, with the ability to work effectively in complex and ambiguous environments.
  • Ability to mentor junior engineers and lead cross-functional technical initiatives.

Responsibilities

  • Analyze technologies, business initiatives, operational processes, and proposed solutions to identify security risks and provide practical, risk-based guidance that supports informed decision making.
  • Quickly assess unfamiliar technologies, platforms, and business challenges, develop an understanding of their security implications, and translate that understanding into actionable recommendations.
  • Apply cybersecurity principles, industry frameworks, organizational standards, and professional analyses to evaluate complex situations and recommend appropriate security controls, safeguards, or courses of action.
  • Collaborate with technical teams, business stakeholders, vendors, project leaders, and security professionals to address security concerns and help ensure that security considerations are incorporated into decision-making processes.
  • Research emerging technologies, evolving threats, regulatory requirements, and industry practices to determine their relevance and potential impact on the organization.
  • Perform security reviews, architectural evaluations, and other analytical activities to identify weaknesses, opportunities for improvement, and areas requiring additional safeguards or oversight.
  • Develop clear, concise, and well-reasoned security guidance, recommendations, assessments, standards, reports, and other written deliverables that enable stakeholders to make informed business and technology decisions.
  • Communicate complex technical concepts, risks, tradeoffs, and recommendations effectively to audiences ranging from engineers and project teams to business leaders and executive stakeholders.
  • Present findings, facilitate discussions, answer questions, and build consensus among stakeholders by explaining security concerns and recommended approaches in a clear, practical, and persuasive manner.
  • Serve as a trusted advisor by helping stakeholders understand cybersecurity risks, evaluate available options, and make balanced decisions that align with organizational objectives and risk tolerance.
  • Exercise independent judgment in situations that may involve incomplete information, competing priorities, evolving technologies, or ambiguous requirements.
  • Contribute to the development and continuous improvement of security standards, methodologies, assessment approaches, and best practices that strengthen the organization's overall security posture.
  • Mentor junior and mid-level team members by sharing technical knowledge, analytical approaches, communication skills, and professional expertise.

Benefits

  • comprehensive benefits
  • career advancement opportunities
  • differentials
  • premiums
  • bonuses
  • recognition programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service