Senior Information Security Analyst - Attack Surface Management Lead Mass General BrighamSenior Information Security Analyst - Attack Surface Management LeadSomerville, MassachusettsThis role will help lead the function into a risk-driven, validation-focused capability that identifies meaningful exposure, prioritizes remediation based on exploitability and business impact, and connects findings to detection engineering, threat hunting, threat intelligence, and broader Cyber Defense priorities. The Mass General Brigham Senior Information Security Analyst – Attack Surface Management Function Lead will be responsible for advancing and coordinating the MGB Attack Surface Management capability across vulnerability discovery, penetration testing, attack surface analysis, and attack simulation.
Business Information Security Officer-VP State StreetBusiness Information Security Officer-VPQuincy, MassachusettsThe VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business’s enhanced decision-making framework. The VP is a strong cyber controls analyst who can correlate the firm’s cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth in at least two focus areas.
Business Information Security Officer-Vp State Street CorporationBusiness Information Security Officer-VpQuincy, MA$120,000–$202,500 / yearThe VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business's enhanced decision-making framework. The VP is a strong cyber controls analyst who can correlate the firm's cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth in at least two focus areas.
Information Security Architect State StreetInformation Security ArchitectBoston, MAFull timeThis role emphasizes the implementation of advanced security frameworks, including cryptography, data protection strategies for data at rest, in motion, and in use, and the deployment of technologies such as Data Security Posture Management (DSPM), Cloud Access Security Brokers (CASB), and Security Service Posture Management (SSPM). As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most.
Information System Security Engineer MIT Lincoln LaboratoryInformation System Security EngineerLexington, MA$114,600–$151,900 / yearIntegrate, test, and configure Free and Open Software (FOSS), Commercial-off-the-Shelf (COTS), Government-off-the-Shelf (GOTS), and custom software Develop/integrate cybersecurity designs for systems and networks with multilevel security requirements or requirements for the processing of multiple classification levels or transfer of information through Cross Domain Solutions (CDS). The final salary offered to a selected candidate will depend on various factors, including—but not limited to—the scope and responsibilities of the role, the candidate’s experience, skills and education/training, internal equity considerations and applicable legal requirements.
Manager of Information Security and Compliance iBoss CybersecurityManager of Information Security and ComplianceBoston, MAIn addition to managing internal security policies, this role will be the primary point of contact for client assessments and external audit engagements, ensuring all compliance obligations are met and supporting key security programs, including contingency planning, configuration management, security awareness, client assurance, and change management. The Director of Information Security & Compliance will develop and implement security policies and align organizational practices with industry frameworks such as ISO 27001, ISO 9001, SOC 1/2, Cyber Essentials, and FedRAMP to ensure continuous monitoring of security controls and incident response readiness.
Information Security Lead Alloy Therapeutics IncInformation Security LeadWaltham, MARemote$150,000–$200,000 / yearThis is a rare role that offers breadth of scope: you will be equally responsible for hands-on technical work (configuring IAM controls, participating in system architecture, managing endpoint security and patching, running vulnerability management) and for the governance work that sits alongside it (writing policies, maintaining compliance documentation, and satisfying the increasingly rigorous security requirements of our enterprise partners). Vulnerability & Patch Management: You run a structured vulnerability management program with defined remediation SLAs (including tight timelines for critical-severity findings), integrate CVE and CSIRT advisory feeds into a regular review cadence, and work directly with IT to ensure patch coverage across endpoints and internet-exposed services.
NewInformation Systems Security Officer (ISSO) III GD Information TechnologyInformation Systems Security Officer (ISSO) IIIPeabody, MassachusettsUSA MA Avon, USA MA Boston, USA MA Braintree, USA MA Burlington, USA MA Cambridge, USA MA Fort Devens, USA MA Hanscom AFB, USA MA Norwood, USA MA Peabody, USA MA Quincy, USA MA Taunton, USA MA Waltham, USA MA Westwood Total Rewards at GDIT: To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.
Information System Security Officer The Charles Stark Draper LaboratoryInformation System Security OfficerCambridge, MassachusettsDraper supports many programs to improve work-life balance including workplace flexibility, employee clubs ranging from photography to yoga, health and finance workshops, off site social events and discounts to local museums and cultural activities. • 1-3 years year relevant industry experience is required, • Preferred experience with RMF (NIST SP 800-53, JSIG, DAAG, ICD 503), IR, Vulnerability Management, SCAP, STIG, and Security-Relevant Tools.
NewInformation Systems Security Officer (ISSO) Abacus TechnologyInformation Systems Security Officer (ISSO)Hanscom AFB, MassachusettsEnsure all users have the requisite security clearances, supervisory need-to-know authorization, and are aware of their IA responsibilities (via IA training) before being granted access to Air Force information systems according to AFSSI 8522. Overview: Abacus Technology is seeking an Information Systems Security Officer (ISSO) to support security and information assurance activities for Hanscom AFB.
Chief Information Security Officer Verily Life Sciences LLCChief Information Security OfficerBoston, MADirect experience working with governance, risk, and compliance frameworks, including ISO 27001 and SOC 2. Direct experience with Okta, Crowdstrike, Wiz, Synk, or equivalent tools, and hands-on experience with hyperscaler platforms, Google Cloud Platform, Amazon Web Services, and/or Azure. Uniquely positioned at the intersection of technology, data science, and healthcare, Verily transforms multimodal health data into insights, models, and actions that make healthcare more personalized, predictive, and precise.
Information System Security Engineer Lincoln LaboratoryInformation System Security EngineerLexington, MA$114,600–$151,900 / yearIntegrate, test, and configure Free and Open Software (FOSS), Commercial-off-the-Shelf (COTS), Government-off-the-Shelf (GOTS), and custom software Develop/integrate cybersecurity designs for systems and networks with multilevel security requirements or requirements for the processing of multiple classification levels or transfer of information through Cross Domain Solutions (CDS). Mission - The Security Department's (SD) overall mission is to identify and counter security threats to the MIT Lincoln Laboratory's mission of development of game-changing technology in support of national security, including guarding against compromise by foreign intelligence agencies and insider threats.
Information Security Engineer III Mass General BrighamInformation Security Engineer IIISomerville, MassachusettsThe ideal candidate possesses strong analytical and problem-solving abilities, can rapidly develop an understanding of unfamiliar technologies and business challenges, and is comfortable working across a diverse range of technical and operational domains. • Collaborate with technical teams, business stakeholders, vendors, project leaders, and security professionals to address security concerns and help ensure that security considerations are incorporated into decision-making processes.
Information System Security Officer (ISSO) III Amatriot Group, LLCInformation System Security Officer (ISSO) IIIHanscom AFB, MA$132,000–$140,000 / yearThis role manages the day-to-day security operations of systems supporting Department of Defense (DoD) Special Access Programs (SAPs), including Collateral, Sensitive Compartmented Information (SCI), and SAP environments. The Information System Security Officer (ISSO) III is responsible for maintaining the operational security posture of assigned information systems in close collaboration with the Information System Security Manager (ISSM) and Information Security Officer (ISO).
Senior Information Systems Security Engineer Axient LLCSenior Information Systems Security EngineerBedford, MAAstrion has an exciting opportunity for a Senior Information System Security Engineer (ISSO) located at the Hanscom AFB, MA supporting the Special Programs Division (AFLCMC/HNJ). Minimum of ten years of progressive technical experience related to IA/cyber engineering architecture, requirements determination, development, and implementation.
Information Systems Security Manager Leidos Holdings IncInformation Systems Security ManagerConcord, MA$107,900–$195,050 / yearBachelor's degree in an IT-related subject matter area from an accredited college or university and 12+ years of experience in an IT-related position with at least 10 years being in an operational cyber security-specific role (e.g., information system security manager, information system security officer, cyber security specialist) or have 15+ years of experience in an IT related position with at least 10 of those years in an operational cyber security specific role. Implement and manage the Risk Management Framework (RMF) Continuous Monitoring process by utilizing an automated ticketing system, ensuring accurate tracking, monitoring, and reporting of security controls, vulnerabilities, and remediation efforts within the organization's information systems.
Senior Information Systems Security Engineer AstrionSenior Information Systems Security EngineerBedford / Hanscom AFB, MassachusettsAstrion has an exciting opportunity for a Senior Information System Security Engineer (ISSO) located at the Hanscom AFB, MA supporting the Special Programs Division (AFLCMC/HNJ). Certifications: CISSP and SAP/SAR Experince in: security systems engineering involving hardware and software operating systems and application solutions.
Information System Security Manager I (ISSM I) (TS, w/ SCI Eligibility) - RedTrace Technologies IncInformation System Security Manager I (ISSM I) (TS, w/ SCI Eligibility) -Hanscom AFB, MASECURITY CLEARANCE REQUIREMENT: TS, WITH SCI ELIGIBILITYPOSITION REQUIRES US CITIZENSHIPPosition Title: Information System Security Manager I (ISSM I) Location: Hanscom AFB, Bedford, MA (on-site) Position Description: The ISSM’s primary function serves as a principal advisor on all matters, technical and otherwise, involving the security of information systems under their purview. IAM Level I• SAP experience Desired • Bachelor’s degree in a related area or equivalent experience (4 years)• 10%-25% Travel Security Clearance: • TS with SCI eligibility• Eligibility for access to Special Access Program Information • Willingness to submit to a Counterintelligence polygraph Employee Benefits: Competitive salary for well qualified applicants.
Information System Security Officer MIT Lincoln LaboratoryInformation System Security OfficerLexington, MA$95,700–$126,700 / yearAbility to integrate information security requirements into the acquisition process; using applicable baseline security controls as one of the sources for security requirements; ensuring a robust software quality control process; and establishing multiple sources (e.g., delivery routes, for critical system elements). Mission - The Security Department’s overall mission is to identify and counter security threats to the MIT Lincoln Laboratory’s mission of development of game-changing technology in support of national security, including guarding against compromise by foreign intelligence agencies and insider threats.
Information Systems Security Manager (ISSM) Abacus TechnologyInformation Systems Security Manager (ISSM)Hanscom AFB, Massachusetts$175,800–$195,100 / yearAuthor, review, certify, and/or maintain security management plans and RMF package artifacts including but not limited to: RMF Implementation Plans, System Security Management Plans, Information Support Plans, Program Protection Plans (PPPs), Security Risk Analyses, Security Vulnerability and Countermeasure Analyses, Vulnerability Management Plans, Common Control Packages, Security Concepts of Operations, OPSEC Plans, Authority-to-Connect guest system packages, and other system/network security related documents. Evaluate system sources of changes such as Deficiency Reports (DRs), Problem Reports (PRs), Change Requests/Proposals (CRs/CPs), and AF Form 1067s; provide inputs to the root cause analysis reporting and the formulation of recommended solution from alternatives; determine the security impacts of proposed or actual changes to the system, environment, threats, and vulnerabilities; and if any, document in written reports the changes/revisions to the system’s RMF artifacts.