ARCHIVED
This job listing has been archived and is no longer accepting applications.
MisuJob - AI Job Search Platform MisuJob

Security Engineer

Keystone

Boston Hybrid permanent

Posted: April 13, 2026

Interested in this position?

Create a free account to apply with AI-powered matching

Quick Summary

We are seeking a Senior Security Engineer with a strong background in security architecture and a passion for collaboration, to join our team in Boston, MA.

Job Description

Keystone is a premier economics, technology, and strategy consulting firm built to help companies lead through transformation. As breakthrough innovations reshape industries, redefine competition and change our society, complex and highly competitive ecosystems emerge. Keystone advises technology leaders, Fortune 100 companies, their legal counsel, and governments on business, economic, litigation, and regulatory strategy in relation to these innovations and competitive eco-systems. We operate globally from offices in New York, Boston, San Francisco, Seattle, London, Dubai, and Washington, D.C.

About Keystone

Keystone is a premier economics, technology, and strategy consulting firm built to help companies lead through transformation. As breakthrough innovations reshape industries, redefine competition and change our society, complex and highly competitive ecosystems emerge. Keystone advises technology leaders, Fortune 100 companies, their legal counsel, and governments on business, economic, litigation, and regulatory strategy in relation to these innovations and competitive eco-systems. We operate globally from offices in New York, Boston, San Francisco, Seattle, London, Dubai, and Washington, D.C.

We’re growing quickly and looking for a Security Engineer with governance, risk and compliance (GRC) proficiency who will be responsible for strengthening the organization’s cybersecurity posture through the execution of governance, risk management, and compliance activities. This role will be building and maintaining structured governance by formalizing policies, controls, and accountability across the organization, enabling proactive risk management through continuous assessment, threat modeling, and mitigation strategies, and ensuring compliance efforts can scale effectively alongside company growth, evolving regulatory requirements, and increasing complexity in systems, data handling, and third-party relationships.

About the Security Engineer – GRC Role

Reporting to the Director, IT Security you will work cross-functionally with IT, product, compliance, and leadership team, and in some cases directly with clients or auditor, to ensure our security posture meets both technical and regulatory expectations across commercial and regulated environments. This role focuses on developing, documenting, and refining security standards and procedures; performing risk and control assessments; and ensuring alignment with government regulatory and security frameworks, including ISO, industry standards, and organizational policies. This role is ideal for a technically strong security professional who enjoys building secure systems and translating regulatory and business requirements into practical, scalable security solutions.

Key Responsibilities

Security Engineering & Technical Controls

• Design, implement, and maintain security controls across cloud and SaaS environments (AWS, Azure, GCP)

• Implement and manage IAM solutions (SSO, MFA, RBAC, least privilege)

• Support vulnerability management, secure configuration, and system hardening initiatives

• Support logging, monitoring, and alerting integrations (SIEM, cloud-native tools)

• Assist with incident response planning, tabletop exercises, and post-incident reviews

• Evaluate and implement security tooling to improve visibility, protection, and automation

• Partner with engineering teams to embed security into the SDLC (secure design reviews, threat modeling, security requirements)

Governance, Risk & Compliance (GRC)

• Enforce and maintain cybersecurity governance, risk, and control frameworks aligned with applicable laws and industry standards

• Perform cybersecurity risk assessments, maturity assessments, and Business Impact Analyses (BIA)

• Conduct control readiness and effectiveness assessments

• Maintain risk registers, POA&Ms, and remediation timelines

• Serve as a trusted advisor on control design, risk treatment, and security architecture decisions

Regulatory & Audit Support

• Support compliance initiatives such as FedRAMP Moderate/High, ISO 27001, and similar frameworks

• Develop and maintain compliance documentation, including:

• System Security Plans (SSPs)

• Policies, procedures, and SOPs

• Control implementation statements

• Coordinate evidence collection and technical validation for internal and external audits

• Work directly with auditors, 3PAOs, and internal stakeholders during assessments

• Support continuous monitoring activities (vulnerability scans, control testing, compliance reporting)

Program Execution & Improvement

• Track security control implementation with leadership and IT teams

• Drive automation and tooling improvements to scale compliance and monitoring

• Support third-party risk management, including technical vendor assessments and questionnaires

• Research and apply evolving security standards, regulatory requirements, and threat trends

• Lead process improvements to enhance security efficiency and operational maturity

What You’ll Bring

Required

• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience

• 5–8+ years of experience in security engineering, GRC, or hybrid security/IT roles

• Strong hands-on experience with:

• Cloud platforms (AWS, Azure, GCP)

• IAM, network security, encryption, and secure system design

• Vulnerability management and secure configuration

• Strong working knowledge of security frameworks and compliance standards:

• NIST SP 800-53 (Rev. 5), NIST RMF (800-37), NIST CSF

• FedRAMP Moderate/High (including SSPs, POA&Ms, and audits)

• ISO 27001, CIS

• Experience translating compliance requirements into technical implementations

• Excellent technical writing, documentation, and stakeholder communication skills

• Ability to operate independently, manage multiple initiatives, and influence without authority

Preferred

• Experience with FedRAMP 20x, GovRAMP, CMMC, TX-RAMP, or HIPAA

• Familiarity with GRC platforms (JupiterOne or similar)

• Experience with SIEM, WAF, CSPM, CNAPP, and vulnerability scanning tools

• Background in incident response, threat modeling, or penetration testing

• Scripting or automation experience (Python, Bash, Terraform)

• Cybersecurity certifications such as CISSP, CISA, CRISC, CCSP, Security+

At Keystone we believe diversity matters. At every level of our firm, we seek to advance and promote diversity, foster an inclusive culture, and ensure our colleagues have a deep sense of respect and belonging. If you are interested in growing your career with colleagues from varied backgrounds and cultures, consider Keystone.

In addition to annual salary, we provide an annual discretionary bonus, 401k contribution, and competitive benefits package. Actual Compensation within the range will depend upon the level the individual is hired into based on their skills, experience, and qualifications.

Annual Salary Range
$110,000—$150,000 USD

At Keystone we believe diversity matters. At every level of our firm, we seek to advance and promote diversity, foster an inclusive culture, and ensure our colleagues have a deep sense of respect and belonging. If you are interested in growing your career with colleagues from varied backgrounds and cultures, consider Keystone.

Why Apply Through MisuJob?

AI-Powered Job Matching: MisuJob uses advanced artificial intelligence to analyze your skills, experience, and career goals. Our matching algorithm compares your profile against thousands of job requirements to find positions where you have the highest chance of success. This saves you hours of manual job searching and ensures you only see relevant opportunities.

One-Click Applications: Once you create your profile, applying to jobs is effortless. Your resume and cover letter are automatically tailored to highlight the most relevant experience for each position. You can apply to multiple jobs in minutes, not hours.

Career Intelligence: Beyond job matching, MisuJob provides valuable career insights. See how your skills compare to market demands, identify skill gaps to address, and understand salary benchmarks for your experience level. Make data-driven decisions about your career path.

Frequently Asked Questions

How do I apply for this position?

Click the "Register to Apply" button above to create a free MisuJob account. Once registered, you can apply with one click and track your application status in your dashboard.

Is MisuJob free for job seekers?

Yes, MisuJob is completely free for job seekers. Create your profile, get matched with jobs, and apply without any cost. We help you find your dream job without any hidden fees.

How does AI matching work?

Our AI analyzes your resume, skills, and experience to understand your professional profile. It then compares this against job requirements using natural language processing to calculate a match percentage. Higher matches mean better fit for the role.

Can I apply to jobs in other countries?

Absolutely. MisuJob features jobs from companies worldwide, including remote positions. Filter by location or look for remote opportunities to find jobs that match your preferences.

Ready to Apply?

Join thousands of job seekers using MisuJob's AI to find and apply to their dream jobs automatically.

Register to Apply