Security Engineer (Boston HQ)

WinnCompaniesBoston, MA
Onsite

About The Position

WinnCompanies is looking for a Security Engineer to join our team in Boston, MA to help drive our progress forward. Our organization manages affordable housing communities and supports approximately 3,000 corporate and property-based employees. We are building out a maturing security program and are looking for a hands-on Security Engineer to help drive it forward. Reporting to the Director of Information Security & Risk Management, you will be a core member of a lean security team. This is a high impact role with broad exposure: where you will work across core domains including identity and access management (IAM), third-party risk, and incident detection and response while working closely with the Director of Information Security to strengthen overall security architecture and program strategy. You will work closely with our internal IT team and our managed security service provider (MSSP) to deploy, configure, and tune security tools, improve monitoring and alerting, and support incident response activities. The salary range for this role is $80,000 to $110,000 per year, dependent on experience.

Requirements

  • 2–5 years of hands-on experience in security engineering, security operations, IT security, or a closely related role.
  • Practical experience with identity and access management concepts and tooling (e.g., directory services, SSO, MFA, user provisioning/deprovisioning).
  • Experience working with security incident detection and response tools, including working with SIEM, EDR, or MDR- services.
  • Understanding of third-party / vendor risk assessment principles.
  • Proven ability to collaborate effectively with internal IT teams and external service providers (MSSP, MDR).
  • Strong written and verbal communication skills, with the ability to clearly document findings and articulate risks to non-technical stakeholders.
  • Self-directed and capable of working independently, demonstrating a strong problem-solving mindset in a lean and rapidly growing security program.

Nice To Haves

  • Experience supporting a large or distributed workforce, ideally across multiple physical sites.
  • Hands-on experience implementing controls for the protection of sensitive data (PII).
  • Familiarity with common security and privacy frameworks (e.g., NIST CSF, CIS Controls) and associated regulatory considerations.
  • Relevant certifications such as Security+, SSCP, GSEC, or progress toward CISSP.
  • Experience using scripting or automation tools (e.g., PowerShell, Python) to streamline IAM and security operational tasks.

Responsibilities

  • Administer and manage identity and access management (IAM) processes and tools across a large, distributed workforce.
  • Manage the high-volume onboarding and offboarding process common in property management environments.
  • Implement and tune access controls, role-based access, multi-factor authentication, and least-privilege practices.
  • Support access reviews, partnering with IT and business owners to validate findings.
  • Conduct vendor and third-party risk assessments using the firm's third-party assessment tool.
  • Evaluate vendor security postures, document findings, track remediation, and advise stakeholders on acceptable risk.
  • Help refine the third-party risk process and reporting as the program matures.
  • Serve as a key point of contact for security incident detection and response, working alongside our managed detection and response (MDR) provider.
  • Triage, investigate, and coordinate response to alerts 24/7 on call for incidents escalated by the MDR service.
  • Contribute to and help mature incident response playbooks, runbooks, and post-incident reviews.
  • Work directly with the Director of Information Security & Risk Management to shape the strategy, roadmap, and priorities of the security program.
  • Work with internal IT and the IT MSSP to implement, configure, and operate security tools and controls.
  • Contribute to policy development, security awareness training, and compliance-supporting activities as needed.
  • Take on related security responsibilities as the program evolves.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service