Security Assurance Engineer RFQ
- 🇺🇸 United States
- On-site
- Mid level
- 9 hours ago
- $92 / hour
- triage
- AWS
- Salesforce
- AI
- SAST
- DAST
- Penetration Testing
- Jira
- RAG
- Tenable
- GitHub
- CISSP
- NIST
- CCSP
- CSSLP
   Security Assurance Engineer – ContractLocation: Boston, MA
Work Model: Hybrid
Job Type: Contract
Duration: 6–12 months, with possibility of extension
Hours: 37.5 hours/week
Project Duration: Through June 30, 2027, with possibility of extension
Position Overview
Our client, aMassachusetts-based public-sector organization, is seeking an experiencedSecurity Assurance Engineer to support major application modernization initiatives.
The Security Assurance Engineer will provide project-focused security assurance from design through deployment. This includes security requirements, risk analysis, security testing, vulnerability triage, remediation planning, security controls, and release-readiness activities.
The role will work closely with project teams, application owners, architects, developers, vendors, testing teams, and security stakeholders.
Key Responsibilities
- Define and document project security requirements, control objectives, implementation details, and acceptance criteria.
- Review application architecture, data flows, integrations, databases, AWS, Salesforce-based applications, AI-enabled services, identity, logging, infrastructure, and document handling.
- Perform project-specific security risk analysis covering threat scenarios, exploitability, exposure, data sensitivity, business and regulatory impact, existing controls, and release dependencies.
- Document inherent and residual risks and provide recommended treatment options.
- Implement approved project-scoped security controls and technical safeguards when assigned.
- Guide application and business teams on control ownership, configuration, operation, evidence collection, exceptions, and transition to ongoing management.
- CoordinateSAST, DAST, penetration testing, and vulnerability scanning.
- Analyze and triage findings from vulnerability scanners, application security testing tools, code repositories, testing providers, and other approved sources.
- Validate findings, identify false positives and duplicates, analyze root causes and affected components, determine severity and release priority, and identify owners.
- Track security findings and remediation activities using Jira or applicable tracking systems.
- Develop remediation plans with technical actions, owners, priorities, dependencies, target dates, validation steps, compensating controls, and risk decisions.
- Verify remediation through retesting and evidence review.
- Collaborate with engineering teams, application owners, vendors, and testing providers.
- Escalate material findings, blocked remediation, and risks that could affect project milestones or go-live readiness.
- Prepare security review results, testing evidence, remediation plans, control documentation, risk decisions, and release-readiness records.
- Verify that Critical and High findings are remediated, retested, addressed through approved compensating controls, or formally accepted before go-live.
- Present residual risks and recommendations to appropriate risk-acceptance stakeholders.
- Maintain accurate security documentation and evidence throughout the project lifecycle.
AI Security
The role will also support security assessment of AI-enabled solutions, including:
- RAG pipelines and LLM-based solutions
- Prompt injection
- Data leakage
- Retrieval poisoning
- Model behavior manipulation
- Jailbreak attempts
- AI guardrail evaluation
- Adversarial and red-team testing
The engineer may also use approved AI-assisted capabilities for vulnerability testing, secure code review, test-case development, finding analysis, and remediation planning.
Required Qualifications
- 5+ years of professional experience in application security, cloud security, product security, security engineering, or a closely related field.
- Experience defining security requirements and reviewing application architectures, data flows, integrations, and technical controls.
- Experience coordinating SAST, DAST, and penetration testing and validating remediation or retest evidence.
- Experience performing security risk analysis and vulnerability triage.
- Experience developing remediation plans and tracking findings through closure.
- Experience implementing or supporting technical security controls.
- Experience guiding technical or business teams on control ownership, operation, evidence, and exceptions.
- Working familiarity withJira, Salesforce-based applications, Tenable Cloud, Veracode static and dynamic testing, GitHub, and GitHub Copilot or comparable approved tools.
- Experience using AI-assisted capabilities responsibly for security testing, source-code or configuration review, finding analysis, or remediation planning.
- Working knowledge of identity, data protection, logging, deployment, cloud, and infrastructure controls for complex applications.
- Ability to manage concurrent work against milestones, release schedules, acceptance criteria, and project reporting requirements.
- Excellent written and verbal communication skills.
- Ability to work independently, maintain accurate evidence, and escalate risks or blockers promptly.
- Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field. A CISSP credential, or comparable security certification, together with relevant professional experience will be considered equivalent to the bachelor's degree requirement.
Preferred Qualifications
- Experience securing AWS, Salesforce, public-facing digital services, or regulated application environments.
- Experience supporting legacy-platform modernization, cloud re-platforming, or complex application integrations.
- Experience working with AI solutions and infrastructure, including RAG pipelines, LLM models, and voice models.
- Familiarity with security considerations for AI-enabled services, document uploads, constituent data, and regulated workflows.
- Hands-on experience using Jira, Tenable Cloud, Veracode, GitHub, GitHub Copilot, and Salesforce-based applications in an enterprise or public-sector delivery environment.
- Knowledge of NIST security frameworks.
- Experience working in state government, the public sector, financial services, consumer protection, or another regulated environment.
- CISSP, CCSP, CSSLP, or comparable application, cloud, or security engineering certification.
- Experience coordinating security work across internal teams, systems integrators, vendors, and independent testing providers.
Work Schedule & Location
This is ahybrid, Massachusetts-based position in Boston.
- Minimum3 days per week onsite for the first 90 days.
- After the first 90 days, onsite attendance will generally be2–3 days per week, depending on project and team requirements.
- Standard working hours are8:45 AM–5:00 PM, Monday–Friday.
- Occasional before- or after-hours work may be required for vendor meetings, testing, deployments, and emergency system recovery.
- Weekend testing and other activities may be required around major deployments.
Location: Boston, MA
Work Model: Hybrid
Â
LanceSoft is a certified Minority Business Enterprise (MBE) and an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. LanceSoft makes hiring decisions based solely on qualifications, merit, and business needs at the time.
EEO EmployerÂ
Security Assurance Engineer RFQ · LanceSoft Inc