Talent.com
Application Security Engineer
Application Security EngineerHarbourVest Partners, LLC • Boston
Application Security Engineer

Application Security Engineer

HarbourVest Partners, LLC • Boston
30+ days ago
Job type
  • Full-time
Job description

Description

Summary

For over forty years, HarbourVest has been home to a committed team of professionals with an entrepreneurial spirit and a desire to deliver impactful solutions to our clients and investing partners. As our global firm grows, we continue to add individuals who seek a collaborative, open-door culture that values diversity and innovative thinking.

In our collegial environment that’s marked by low turnover and high energy, you’ll be inspired to grow and thrive. Here, you will be encouraged to build on your strengths and acquire new skills and experiences.

We are committed to fostering an environment of inclusion that promotes mutual respect among all employees. Understanding and valuing these differences optimizes the potential of both the individual and the firm.

HarbourVest is an equal opportunity employer.

This position will be a hybrid work arrangement. You will receive 18 remote workdays per quarter to use at your discretion, subject to manager approval. For example, you may choose to work in the office 4 days per week and take one remote day weekly (typically 13 weeks per quarter), leaving 5 additional remote days to be used as needed.

As a key member of the Security Engineering team, this person will help lead HarbourVest’s Application Security program. The Application Security Engineer (ASE) will serve in a multi-functional role, advising development teams on secure coding and accepted industry procedures. The ASE is responsible for leading SDLC initiatives that include secure code reviews, architecture assessments, and application scanning methods. They will provide end-to-end leadership for application security, working closely within platform teams to advocate for and enhance a strong program focused on application security. In this role, they will help uphold and continuously improve HarbourVest’s high security standards across infrastructure, applications, and operational processes.

The ideal candidate is someone who is:

  • Dedicated to protecting sensitive financial data, client information, and critical business systems

  • Skilled in navigating regulated financial services settings

  • Able to assess and prioritize security concerns by considering their effect on business and financial outcomes

  • A collaborative partner to engineering, risk, compliance, and audit teams

  • Proactive, diligent, and calm when responding to security incidents

What you will do:

  • Identify risks and areas of exposure in applications, SDLC processes, and architecture

  • Define guardrails, standards, and secure usage patterns for agentic AI–based coding tools, enabling engineering teams to adopt them safely while managing data exposure, code quality, and security risk

  • Perform secure build reviews, threat modeling, and application security testing (SAST, DAST, SCA)

  • Identify, assess, and support remediation of vulnerabilities in web applications and APIs

  • Partner with engineering teams to promote secure coding standards utilizing CI/CD pipelines and DevSecOps practices

  • Support audits, regulatory exams, penetration tests, and security incident response

  • Secure and continuously monitor third-party SaaS applications using SSPM tools, ensuring configurations, access controls, and integrations meet HarbourVest security standards

  • Establish metrics and reporting to track coverage and effectiveness of security processes

  • Enable developers through secure coding guidance, training, and tooling

  • And other responsibilities as required!

What you bring:

  • Solid understanding of application security principles and OWASP Top 10 risks

  • Experience securing web applications, APIs, and microservices in financial environments

  • Hands-on experience with AI-assisted coding tools such as Cursor, GitHub Copilot, and ChatGPT Codex, with an understanding of their security implications in enterprise software development

  • Proficiency reviewing code in at least one common language (Java, Python, C#, or JavaScript)

  • Familiarity with cloud platforms, containers, IaaC, and modern DevSecOps tooling

  • Ability to clearly communicate technical risk to both technical and non-technical collaborators


​Education Preferred:

  • Bachelor’s degree or equivalent experience in Computer Science, Information Security, or a related field

  • Security certifications such as CISSP, CSSLP, OSCP, GWAPT, or similar are a plus

Experience:

  • 3-5 years of experience in application security or secure software development

  • Experience working in controlled sectors such as finance, banking, or fintech

  • Exposure to compliance frameworks (e.g., SOC 2, SOX, PCI DSS, GDPR)

    #LI-Hybrid

Salary Range

$100,000.00 - $160,000.00

This USD base salary range represents only one component of total compensation for this role and is provided in accordance with local requirements. This role is eligible for a discretionary annual bonus, which is determined based on individual and overall firm performance. In addition to salary and bonus, total compensation may include eligibility for long-term reward programs and a comprehensive total rewards package that may include retirement, health, insurance, paid time off, and wellness programs. Our total rewards offerings are influenced by several business factors, and eligibility for certain components will vary by position and geography. Please note the posted ranges do not apply outside the U.S. and should not be converted to other currencies as a proxy for compensation in other countries.

Create a job alert for this search

Application Security Engineer • Boston

Similar jobs

Application Security Lead: Threat Modeling & Secure SDLC

LamworkBoston, MA, United States
Full-time

A technology company in Boston is seeking an experienced Application Security Specialist to identify and mitigate risks in applications and development processes.You will work closely with engineer...Show more

 • Promoted

Workday Application Security & Controls Manager

PwCBoston, MA, United States
Full-time

At PwC, our people in business application consulting specialise in consulting services for a variety of business applications, helping clients optimise operational efficiency.These individuals ana...Show more

 • Promoted

Senior Security Engineer / IR / Blue Team

7AI, Inc.Boston, MA, United States
Full-time

We are seeking a Senior AI Security Engineer to join our team, focusing on defining security workflows and incident response (IR) strategies.Our AI Security Engineers are at the forefront of the Ag...Show more

 • Promoted

Advanced Security Engineer, Enterprise Security

RelativityBoston, Massachusetts, United States
Full-time

As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate security controls that protect Relativity's employee endpoints and the enterprise systems they acc...Show more

 • Promoted

Remote Platform Security Engineer

ZoomBoston, MA, United States
Remote
Full-time

A leading communication platform is seeking a Security Engineer to ensure security design and reviews across products.You will collaborate with engineering teams to implement secure solutions, cond...Show more

 • Promoted

Senior Platform Engineer: AI-Driven Infra & Security

7AI, Inc.Boston, MA, United States
Full-time

A leading technology firm in Boston is seeking a Senior Platform Engineer to design and build scalable infrastructure for their AI-driven security products.You will collaborate with development tea...Show more

 • Promoted

Principal Product Security Cloud Engineer

Johnson & JohnsonDanvers, Massachusetts, MA, United States
Full-time

This job is with Johnson & Johnson, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community.Please do not contact the recruiter directly.At Joh...Show more

 • Promoted

Cloud Security Engineer

Tech CraticBoston, MA, United States
Full-time

Technology has revolutionized how we approach job hunting, and this book streamlines the process into a fast, efficient system that works.Instead of relying on outdated advice,.Technology has revol...Show more

 • Promoted

Senior Director, Application Security

Berkshire Hathaway Specialty InsuranceBoston, MA, United States
Full-time

Senior Director, Application Security.Berkshire Hathaway Specialty Insurance.This role is based in Boston, MA and the Base salary range for this position is.Total compensation will be determined by...Show more

 • Promoted

Cloud Security Engineer

Cornerstone ResearchBoston, Massachusetts, United States
Full-time

HYBRID) ALL US OFFICES - CHI, SF, LA, BOS, NYC, D.The Cloud Security Engineer is responsible for deploying, managing, and securing cloud solutions across AWS, Azure, and Google Cloud platforms.This...Show more

 • Promoted

Application Security Specialist

LamworkBoston, MA, United States
Full-time

APPLICATION SECURITY SPECIALIST RESUME EXAMPLE.Updated: July 26, 2024 - The Application Security Specialist identifies and communicates risks in applications, development processes, and architectur...Show more

 • Promoted

Workday Application Security & Controls Director

PwCBoston, MA, United States
Full-time

Workday Application Security & Controls Director.Workday Application Security & Controls Director.Be among the first 25 applicants.Specialty / Competency: Workday.Industry / Sector: Not Applicable....Show more

 • Promoted

Sr. Application Engineer

The Davis CompaniesReading, MA, United States
Full-time

Lead the design and execution of complex and custom assembly projects from concept through production.Develop advanced system layouts and designs that meet customer requirements and manufacturing c...Show more

 • Promoted

Senior Director, Application Security — Lead DevSecOps

Berkshire Hathaway Specialty InsuranceBoston, MA, United States
Full-time

A leading insurance company based in Boston is seeking a Senior Director, Application Security to shape the security strategy for critical applications.You will lead a team while embedding security...Show more

 • Promoted

Senior Security Engineer - Zero-Trust & Cloud Defense

Henderson ScottBoston, MA, United States
Full-time

A technology services provider is seeking a Senior Security Engineer to enhance security posture in cloud-native and hybrid environments.Responsibilities include platform integration, threat detect...Show more

 • Promoted

Senior Security Engineer - Detection and Response

KlaviyoBoston, MA, MA, United States
Full-time

This job is with Klaviyo, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community.Please do not contact the recruiter directly.At Klaviyo, we v...Show more

 • Promoted

Senior Security Engineer, Cyber Defense Platforms

State StreetBoston, MA, United States
Full-time

This job is with State Street, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community.Please do not contact the recruiter directly.Senior Secu...Show more

 • Promoted

Principal Cyber Engineer

PrattwhitneyCambridge, MA, United States
Full-time

Principal Cyber Engineer page is loaded## Principal Cyber Engineerlocations: US-MA-CAMBRIDGE-BBN06 ~ 10 & 50 Moulton St ~ MOULTON B6time type: Full timeposted on: Posted Todayjob requisition id: 01...Show more