Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
QM
Quincy Mutual Fire Insurance Company
Senior Cybersecurity Engineer
Career Insights for Cyber Security Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Massachusetts data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.
$119,098 / year median in Massachusetts
+2% projected growth
Job Description
Senior Cybersecurity Engineer This position currently follows a hybrid work schedule, with three in-office days. Tuesday and Thursday are Company anchor days, and the third day will be worked out with your manager.
POSITIONSUMMARY
The Cybersecurity Engineer is a senior individual contributor responsible for executing cybersecurity initiatives across the organization. This role ensures that security controls, operational practices, and architectural considerations are effectively embedded across infrastructure, applications, cloud platforms, and data initiatives. The role supports execution of cybersecurity strategy by translating CIO direction, in collaboration with the vCISO, into actionable controls, while supporting secure modernization across Microsoft 365, data platforms, and enterprise systems.PRINCIPAL ACCOUNTABILITIES
Planning and Delivery Security Operations and Risk Management- Own and drive cybersecurity operations across endpoints, servers, and enterprise systems
- Recommend, implement and maintain security baselines, hardening standards, and best practices
- Manage the vulnerability management lifecycle including identification, prioritization, and remediation tracking
- Define and monitor patch management compliance in partnership with infrastructure teams
- Continuously assess and reduce organizational attack surface Security Architecture and Modernization Enablement
- Participate in security reviews for system upgrades and modernization initiatives
- Participate in architecture reviews and solution design discussions
- Define and promote secure design patterns and standards
- Ensure security is embedded across infrastructure, applications, and data platforms Cloud Security and Microsoft Ecosystem
- Provide security oversight for Microsoft 365, SharePoint, Teams, Power BI, and emerging platforms such as Microsoft Fabric
- Assist with design and implementation of identity, access control, and data protection capabilities
- Enforce Zero Trust principles including strong authentication, least privilege, and device posture validation
- Secure Development and Technology Enablement
- Promote secure development lifecycle practices
- Evaluate security considerations in new technologies, platforms, and integrations Identity, Access, and Data Protection
- Promote identity-first security practices across the organization
- Support data classification, data loss prevention, and secure data sharing standards Communication & Culture Enablement Incident Response and Coordination
- Participate in cybersecurity incident response activities.
- Lead cross-functional response efforts across infrastructure, applications, support, and external partners in coordination with senior company leadership
- Ensure timely containment, remediation, and recovery
- Maintain incident response plans, escalation procedures, and playbooks
- Participate in post-incident reviews and drive corrective actions Training and Preparedness
- Partner with cross functional leadership in planning and execution of cybersecurity tabletop exercises to strengthen organizational preparedness and response capabilities
- Simulate scenarios such as ransomware, phishing compromise, and data breaches
- Identify gaps in response readiness and drive remediation efforts
- Ensure protection of sensitive data across business and analytics platforms
- Administer and enhance enterprise security awareness program activities
- Implement training, phishing simulations, and targeted campaigns
- Track training completion and effectiveness metrics
- Support and play a key role in IT-led monthly cybersecurity best practice sessions for employees and IT teams, helping deliver awareness, reinforce secure behaviors, and promote organizational security best practices. Cross Functional Enablement
- Partner with infrastructure, application development, and support teams to embed security practices
- Partner with IT leaders to facilitate alignment between operational execution and policies defined by the vCISO and legal teams Leadership and Advisory
- Provide cybersecurity guidance to IT team on cybersecurity best practices
- Assist with application security, code review practices, and vulnerability remediation
- Support evaluation of third-party vendors from a cybersecurity standpoint
- Review security controls and risks associated with external solutions
- Partner with procurement and leadership to ensure appropriate risk visibility
- Advise on secure collaboration, external sharing, and data governance practices
- Collaborate with IT team, vCISO, and Legal functions to develop and formalize enterprise cybersecurity policies, SOC documentation, and contribute to responses to regulators, auditors, and external stakeholders.
- Maintain and govern a centralized repository for all related artifacts and records. Business Insight and Analytics & Reporting
- Develop and maintain cybersecurity metrics and dashboards
- Report on vulnerabilities, patch compliance, incidents, and training outcomes
- Provide regular updates to senior leadership on risk posture and emerging threats
- Translate technical risks into business impact
JOB REQUIREMENTS
EDUCATION:
- Bachelor's Degree in Engineering, Information Systems, or a related field is required.
EXPERIENCE
- Total IT experience: 6-10 years
- Cybersecurity-focused experience: 4-7 years
- Experience spanning security operations, incident response, and infrastructure or cloud environments
- Prior involvement in cloud adoption or modernization initiatives preferred
- Experience in regulated industries such as insurance or financial services is advantageous
SKILLS:
Technical Skills- Endpoint security and EDR platforms
- Vulnerability management tools and processes
- Patch management and system hardening
- Identity and access management, including modern authentication and access controls
- Cloud security fundamentals, particularly Microsoft 365 and Azure environments
- Data protection technologies including data classification and data loss prevention
- Familiarity with logging, monitoring, and detection concepts Frameworks and Standards
- Experience working with or implementing security frameworks such as: o NIST Cybersecurity Framework o CIS Critical Security Controls o ISO 27001 or similar standards
- Ability to translate framework requirements into practical controls and operational processes Core Competencies
- Collaboration and decision-making capability under pressure
- Ability to balance hands-on execution with strategic project work
- Strong analytical and troubleshooting skills
- Ability to work collaboratively across IT teams
- Solid understanding of security architecture principles
- Strong attention to detail
- Willingness to learn new security technologies and best practicesCommunication and Influence
- Communicate effectively with technical teams and business stakeholders.
- Ability to translate cybersecurity risks into business context Emerging Technology Awareness
- Awareness of security considerations related to emerging technologies including AI, advanced analytics, and cloud-native platforms
- Ability to assess and communicate risks introduced by new technologies