Demo

Security Engineering Lead (Local to MA)- F2F interview

Lorvenk Technologies LLC
Boston, MA Contractor
POSTED ON 7/22/2026
AVAILABLE BEFORE 8/21/2026

Role: Security Engineering Lead

Location: Boston, MA 3 days/week (Hybrid)

Exp: 13

Duration: Long Term

Interview: F2F interview is required

Visa:

Note: This person needs to be strong in AWS / Snowflake

They need to have built security governance to protect against Agentic/Gen AI systems

POSITION SUMMARY: This is a unique opportunity for a strong technologist to be one of founding member of the team building a strategic data and AI platform from scratch for a well-established bank

Security Engineering Manager will lead and execute cybersecurity engineering across our existing on-premises infrastructure, new AWS cloud environment, Snowflake data platform, and emerging AI application ecosystem.

This is not a pure oversight or policy role. The primary need is a senior technical security practitioner who can hands-on design, build, harden, implement, troubleshoot, and continuously improve security controls. The role will manage and mentor a small team of talented security engineers, but the individual must remain deeply hands-on and comfortable acting as the senior technical architect executor for cybersecurity engineering.

The ideal candidate has strong financial services experience, has previously helped secure a new AWS environment from the ground up, understands traditional infrastructure and data center security, and can help the Bank safely adopt cloud, data, and AI technologies.

Key Responsibilities

1. Security Engineering & Architecture

Own the design, implementation, and continuous improvement of security controls across infrastructure, cloud, applications, data platforms, and AI solutions.

Responsibilities include:

Design and implement practical security architectures for on-premises systems, AWS, Snowflake, and internally developed AI applications.

Translate cybersecurity standards and risk requirements into deployable technical controls.

Build secure-by-design patterns for identity, network segmentation, encryption, logging, monitoring, endpoint protection, vulnerability management, and access governance.

Serve as a senior technical security advisor to infrastructure, engineering, data, AI, and vendor teams.

Evaluate new technologies and ensure security requirements are embedded early in design and delivery.

AWS security is a critical part of this role. AWS defines cloud security as a shared responsibility model, where AWS is responsible for security of the cloud and customers are responsible for security in the cloud. This role will own the Bank s side of that responsibility across identity, networking, data protection, monitoring, governance, and workload security.

2. AWS Cloud Security

Lead the security design and implementation for the Bank s new AWS environment.

Responsibilities include:

Secure a new AWS environment from initial design through operationalization.

Implement multi-account security patterns, IAM controls, least privilege access, SCPs, logging, monitoring, encryption, secrets management, vulnerability scanning, and network segmentation.

Design secure VPC, subnet, routing, security group, and NACL patterns.

Implement controls across services such as IAM, Organizations, CloudTrail, CloudWatch, GuardDuty, Security Hub, Config, KMS, Secrets Manager, Macie, Inspector, S3, Lambda, RDS, EC2, ECS/EKS as applicable.

Partner with infrastructure and engineering teams to embed security into CI/CD, IaC, cloud provisioning, and operational support.

Establish AWS security baselines and exception management processes.

AWS specifically highlights data protection, encryption in transit, IAM, infrastructure security, security groups, subnet controls, resilience, and compliance validation as part of managing security responsibilities for Amazon VPC.

3. On-Premises Infrastructure & Data Center Security

Own security engineering for the Bank s existing data center and infrastructure environment.

Responsibilities include:

Maintain and improve controls across servers, endpoints, firewalls, networks, Active Directory, privileged access, remote access, vulnerability management, patching, EDR, SIEM/logging, backup security, and segmentation.

Strengthen identity and access controls across Microsoft/Windows environments.

Support remediation of audit findings and security gaps across existing infrastructure.

Partner with IT operations to ensure cybersecurity controls are practical, sustainable, and operationally reliable.

Help modernize legacy security patterns while reducing operational risk.

4. Snowflake & Data Platform Security

Support the secure implementation and operation of Snowflake and the Bank s broader data platform.

Responsibilities include:

Design and review Snowflake access controls, role hierarchy, authentication, MFA/SSO integration, network policies, data classification, masking, row-level access, and audit logging.

Partner with data engineering and analytics teams to ensure sensitive banking data is protected appropriately.

Support security patterns for data ingestion, transformation, sharing, and reporting.

Ensure appropriate monitoring, alerting, and governance around privileged access, service accounts, and data movement.

Snowflake experience is strongly preferred; direct implementation experience is a major plus.

5. AI Security

Lead security work for internally developed AI applications and AI-enabled business capabilities.

Responsibilities include:

Define and implement security guardrails for AI applications, including RAG, chatbots, AI agents, document intelligence, and internally developed AI tools.

Address AI-specific risks such as prompt injection, data leakage, insecure output handling, excessive agency, model misuse, unsafe integrations, and sensitive information exposure.

Partner with AI/data engineering teams to secure model access, data flows, vector stores, APIs, plugins/tools, and application permissions.

Establish controls for AI application logging, monitoring, testing, human review, access governance, and incident response.

Monitor external AI-enabled cyber threats, including phishing, social engineering, malware generation, deepfakes, and adversarial automation.

AI security is now a distinct discipline. The OWASP Top 10 for LLM Applications identifies risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, supply chain vulnerabilities, and sensitive information disclosure. NIST has also published a Generative AI Profile under its AI Risk Management Framework to help organizations identify and manage risks unique to generative AI.

6. Team Leadership & Mentorship

Manage a small team of approximately two security engineers while remaining hands-on.

Responsibilities include:

Provide technical direction, mentoring, and daily guidance to security engineers.

Help upskill the team in AWS, Snowflake, AI security, automation, and modern security engineering practices.

Assign work, review technical outputs, and ensure timely execution of security initiatives.

Build a culture of ownership, urgency, documentation, and practical risk reduction.

Act as manager, lead and senior individual contributor.

7. Audit, Risk & Vendor Management

Serve as the technical cybersecurity point of contact for internal security audit, regulatory exams, and vendor security matters.

Responsibilities include:

Face off with Security Audit, Risk, Compliance, and regulatory stakeholders.

Provide evidence, explanations, remediation plans, and technical responses for audit findings.

Translate audit and regulatory requirements into specific technical actions.

Support vendor security assessments, third-party reviews, and ongoing vendor oversight.

Review vendor security architecture, access models, SOC reports, control gaps, and remediation plans.

Partner with the Information Security Officer, IT leadership, and business stakeholders to ensure cybersecurity controls meet banking expectations.

Required Qualifications

8 years of hands-on cybersecurity experience, with significant experience in security engineering, cloud security, infrastructure security, or security architecture.

Prior experience in financial services, banking, fintech, payments, lending, insurance, or another regulated financial environment is required.

Proven experience securing and operationalizing an AWS environment, ideally from early-stage setup or greenfield implementation.

Strong hands-on knowledge of AWS security services, IAM, networking, encryption, logging, monitoring, and cloud governance.

Strong understanding of on-premises infrastructure security, including Windows/Active Directory, network security, endpoint security, vulnerability management, privileged access, and SIEM/logging.

Practical experience designing and implementing security controls, not just reviewing policies or writing standards.

AI security experience, especially securing LLM-based applications, RAG systems, AI agents, internal AI tools, or AI-enabled workflows

Demonstrated ability to lead, mentor, and manage a small technical security team.

Experience supporting audits, regulatory exams, security assessments, and evidence collection.

Strong communication skills with the ability to explain technical security matters to IT, audit, risk, vendors, and senior leadership.

Independent, self-directed working style with the ability to own outcomes without heavy supervision.

Strongly Preferred Qualifications

Snowflake security experience, including RBAC, masking policies, row access policies, network policies, SSO, logging, and data governance.

Experience with secure software development, DevSecOps, CI/CD security, SAST/DAST/SCA, secrets scanning, container security, and infrastructure-as-code security.

Experience with AWS Control Tower, Organizations, SCPs, GuardDuty, Security Hub, Config, IAM Identity Center, KMS, Macie, Inspector, CloudTrail, and CloudWatch.

Experience with Microsoft security ecosystem, including Entra ID, Defender, Purview, Intune, Sentinel, or related tools.

Security certifications such as CISSP, CCSP, AWS Certified Security Specialty, CISM, GIAC, or equivalent practical experience.

Desired Technical Skills

AWS security architecture and operations

IAM, least privilege, privileged access management

Network security, firewalls, segmentation, VPN, zero trust concepts

Active Directory and Microsoft security controls

Endpoint detection and response

Vulnerability management and patch governance

SIEM, logging, alerting, and incident response

CloudTrail, GuardDuty, Security Hub, Config, KMS, Macie, Inspector, Crowd Strike

Snowflake access control and data protection

AI/LLM application security

Secure SDLC and DevSecOps

Vendor security reviews

Audit evidence and remediation management

Security automation and scripting

Education

Bachelor s degree in Computer Science, Engineering, Information Systems, or related field required; advanced degree preferred

Hourly Wage Estimation for Security Engineering Lead (Local to MA)- F2F interview in Boston, MA
$88.00 to $105.00
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Engineering Lead (Local to MA)- F2F interview?

Sign up to receive alerts about other jobs on the Security Engineering Lead (Local to MA)- F2F interview career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$123,167 - $152,295
Income Estimation: 
$146,673 - $180,130
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Lorvenk Technologies LLC

  • Lorvenk Technologies LLC Mc Lean, VA
  • Job Title: Cloud Engineer Specialist Location: On-site (McLean, VA) Contract Duration: 12 Months with possible extension Rounds: 2 Rounds Duration: 60 mins... more
  • 1 Day Ago

  • Lorvenk Technologies LLC Acushnet, MA
  • Role: Project Manager (Need Q2 with Banking Domain Experience ) Client :Cambridge Savings Bank Location : Waltham, MA 3 days/week onsite F2F Interview is r... more
  • 2 Days Ago

  • Lorvenk Technologies LLC Columbia, SC
  • The State of South Carolina is looking for a Business Analyst - Project Lead Interview Process: 1 round, Virtual/Online Duration of the Contract: 12 months... more
  • 3 Days Ago

  • Lorvenk Technologies LLC Richmond, VA
  • Title: Data Analyst Location: Richmond or McLean, VA (Hybrid) Duration: Long Term Exp: 7 Employment: W2 Job Description We are seeking a skilled Data Analy... more
  • 10 Days Ago


Not the job you're looking for? Here are some other Security Engineering Lead (Local to MA)- F2F interview jobs in the Boston, MA area that may be a better fit.

  • Securitas Security Services USA, Inc. Devens, MA
  • Location: Devens, MA Schedule: Wednesday-Sunday 12am-8am We are looking for a reliable and motivated Lead Security Officer to help oversee nightly security... more
  • 7 Days Ago

  • Boston Engineering Waltham, MA
  • Boston Engineering is a technology-driven consulting firm that provides innovative engineering solutions to commercial and government clients. Headquartere... more
  • 19 Days Ago

AI Assistant is available now!

Feel free to start your new journey!