1

Senior Security Engineer Jobs in Vermont (NOW HIRING)

Senior Security Engineer

Burlington, VT ยท On-site

$112K - $154K/yr

Senior Security Engineer Team: Engineering Location: Remote-Friendly About the Role: We're looking for a Senior Security Engineer tolead application security efforts across our product portfolio ...

Senior Security Engineer

Burlington, VT ยท On-site

$120 - $160/hr

Burlington, United States | Posted on 07/13/2026 We're looking for a Senior Security Engineer to lead application security efforts across our product portfolio, spanning web applications, APIs ...

Senior Security Engineer

Burlington, VT ยท On-site

$120 - $150/hr

Develops engineering recommendations and enhancements that improve the security posture and effectiveness of each client's managed platforms, and communicates them to client stakeholders. * Provides ...

next page

Showing results 1-20

Senior Security Engineer information

See Vermont salary details

$78.1K

$145.8K

$198.3K

How much do senior security engineer jobs pay per year?

As of Aug 25, 2026, the average yearly pay for senior security engineer in Vermont is $145,805.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,700.00 and $166,900.00 per year, depending on experience, location, and employer.

What skills and qualifications are needed to be a senior security engineer?

To thrive as a Senior Security Engineer, you need deep expertise in network security, risk assessment, incident response, and a relevant degree or equivalent experience. Familiarity with security tools such as SIEM platforms, firewalls, IDS/IPS, and certifications like CISSP or CEH are typically required. Strong analytical thinking, effective communication, and leadership abilities help you excel in complex security environments. These skills and qualifications are crucial to safeguard organizational assets and maintain robust defense against evolving cyber threats.

How does a senior security engineer collaborate with other departments to enhance organizational security?

Senior Security Engineers frequently work cross-functionally, partnering with IT, software development, and compliance teams to implement security best practices and respond to incidents. They play a key role in conducting security reviews, advising on secure design, and leading incident response efforts. Effective communication and collaboration are essential, as these engineers often translate technical risks into business terms and provide guidance during audits or vulnerability assessments. This collaborative approach helps ensure comprehensive protection across all organizational assets.

What is the difference between Senior Security Engineer vs Security Analyst?

AspectSenior Security EngineerSecurity Analyst
Required CredentialsCertifications like CISSP, CISA, CEH; Bachelor's or Master's in Cybersecurity or related fieldsCertifications like CompTIA Security+, GIAC Security Essentials; Bachelor's in Cybersecurity, Information Technology, or related fields
Work EnvironmentDesigning security systems, implementing security measures, leading security projectsMonitoring security alerts, analyzing threats, conducting security assessments
Employer & Industry UsageUsed in tech companies, finance, healthcare for security infrastructure rolesCommon in various industries for threat detection and incident response

The main difference is that Senior Security Engineers focus on designing and implementing security solutions, while Security Analysts primarily monitor and analyze security threats. Both roles require relevant certifications and work in similar environments, but their responsibilities differ in scope and focus.

What are popular job titles related to Senior Security Engineer jobs in Vermont?

For Senior Security Engineer jobs in Vermont, the most frequently searched job titles are:

Infographic showing various Senior Security Engineer job openings in Vermont as of August 2026, with employment types broken down into 79% Full Time, and 21% Contract. Highlights an 80% In-person, and 20% Remote job distribution, with an average salary of $145,805 per year, or $70.1 per hour.

Senior Security Engineer

Mach7 Technologies

Burlington, VT โ€ข On-site

$112K - $154K/yr

Full-time

Re-posted 13 days ago


Job description


Title: Senior Security Engineer
Team: Engineering
Location: Remote-Friendly
About the Role:
We're looking for a Senior Security Engineer tolead application security efforts across our product portfolio, spanning webapplications, APIs, mobile, embedded software, and shipped productdeliverables. You'll be embedded in the engineering organization,partnering with product and platform teams to bake security into every phaseof the software development lifecycle, not bolt it on at the end.
A critical part of this role is developingand maintaining a deep understanding ofour product attack surface, how components interact, what'sexposed, and where real risk lives. That understanding is what transformssecurity tooling output into prioritized, meaningful action across threatmodeling, vulnerability management, and supply chain risk.
This is a high-impact role for someone who is equallycomfortable reading source code, threat modeling a newmicroservice, and coaching a developer through a secure code review.
What You'll Do
Application Security & Secure SDLC
  • Ownand evolve the AppSec program across the entire SDLC - from design reviewsto post-deployment monitoring - for web, API, mobile, and shipped productdeliverables
  • Buildand maintain a living model of the product attack surface -mapping trust boundaries, data flows, exposed interfaces, and high-valuetargets - and use it to drive prioritization across all securityworkstreams
  • Conductthreat modeling and architecture security reviews for new features,services, and product releases across all delivery channels
  • Performmanual and automated secure code reviews across multiple languages(e.g. Python, Go, TypeScript, C/C++)
  • Integrateand tune SAST, DAST, and SCA tooling within CI/CD pipelines (GitHubActions, Jenkins, or equivalent)
  • Triageand drive remediation of vulnerabilities surfaced through scanning, bugbounty, and pen tests
  • Developand maintain a library of security standards, patterns, andguardrails applicable across product types

Third-Party & Supply Chain Security
  • Ownthe Software Bill of Materials (SBOM) program - define generation,storage, and consumption processes across all product lines
  • Establishand maintain policies for evaluating, onboarding, andcontinuously monitoring third-party dependencies and open-sourcecomponents
  • Triageand prioritize CVEs and license risks surfaced through SCA tooling,driving timely remediation with engineering teams
  • Defineprocesses for responding to upstream supply chain incidents(e.g. compromised packages, malicious dependencies)
  • Collaboratewith procurement and legal to assess security risk of third-party vendorsand integrations
  • Contributeto industry frameworks and internal standards around software supply chainsecurity (SLSA, NIST SSDF, or equivalent)
  • Actas a trusted security advisor embedded within product engineeringsquads
  • Leadsecurity training, lunch-and-learns, and developer educationinitiatives
  • Collaboratewith the Platform team on secrets management, identity, and accesscontrols
  • Workwith the GRC function to translate compliance requirements (SOC 2, ISO27001) into engineering controls

Incident & Vulnerability Management
  • Participatein the security on-call rotation and lead security incident responseinvestigations
  • Driveroot cause analysis and communicate findings clearly to engineeringleadership
  • Buildand maintain metrics and dashboards to track the health of theAppSec program
  • Participateas a member of theCybersecurity council, representing development in theorganization. Report weekly on new threat intelligence as it relatesto product security, and any actions that are being taken to remediate newfindings.
What We're Looking For
Required

โ€ข 5+ years of experience in security engineering, with a strong AppSec focus
โ€ข Hands-on experience with threat modeling frameworks (STRIDE, PASTA, or similar)
โ€ข Proficiency with common AppSec tooling: Semgrep, Snyk, Burp Suite, OWASP ZAP, or equivalents
โ€ข Deep understanding of web application vulnerabilities (OWASP Top 10, API security, auth/authz flaws)
โ€ข Ability to read and reason about code in at least two languages; prior development experience a plus
โ€ข Experience with software supply chain security - SBOM generation and analysis (CycloneDX, SPDX), SCA tooling, and dependency risk management
โ€ข Strong written and verbal communication skills - you can explain risk to both engineers and executives
Preferred
โ€ข Experience with cloud-native environments (AWS, GCP, or Azure) and container/Kubernetes security
โ€ข Familiarity with software supply chain frameworks such as SLSA, NIST SSDF, or OpenSSF Scorecards
โ€ข Contributions to open-source security tooling or security research
โ€ข Relevant certifications: OSCP, CSSLP, GWEB, or similar
We recognize that candidates bring diverse experiences and backgrounds. If you don't meet every requirement, we still encourage you to apply! Many strong candidates don't check every box. We value potential, growth, and impact as much as experience.
Who You Are
โ€ข Experienced security professional with a strong background in application security and secure software development.
โ€ข Skilled at threat modeling, secure code reviews, and identifying real-world risks across complex systems.
โ€ข Knowledgeable in web, API, mobile, and software supply chain security best practices.
โ€ข Comfortable working with developers to embed security throughout the SDLC.
โ€ข Proficient with security testing and vulnerability management tools, including SAST, DAST, and SCA solutions.
โ€ข Strong communicator who can translate technical risks into actionable recommendations.
โ€ข Collaborative, proactive, and driven to improve both product security and engineering security culture.
โ€ข Passionate about continuous learning, emerging threats, and helping teams build secure products at scale.
About Mach7:
Mach7Technologies helps healthcare organizations bring all their medical imagestogether in one place so they can be easily accessed, shared, and used tosupport patient care. Our enterprise imaging solutions, including avendor-neutral archive (VNA), enterprise PACS, the eUnity enterprisediagnostic viewer, and teleradiology workflows, consolidate imaging fromacross the enterprise into a single, accessible source of truth. Built onopen standards, including DICOM and a configurable HL7 engine, and free fromproprietary data lock-in, our technology lets providers store, view, andshare images on their own terms. The result is a simpler, more connectedimaging environment that puts data ownership back where it belongs: with thepeople delivering care. Your data, your infrastructure, your choice.
AI Expectations
โ€ข Integrate AI into daily work - leverage AI tools to enhance efficiency, elevate quality, and support smarter, faster decision-making.
โ€ข Apply critical human judgment to AI output - review, validate, and take full accountability for AI-assisted work, ensuring accuracy and reliability.
โ€ข Continuously improve through AI - proactively identify opportunities to optimize processes, rethink workflows, and challenge existing approaches rather than maintaining the status quo.
โ€ข Use AI responsibly and ethically - safeguard sensitive information, adhere to company guidelines, and actively identify risks such as bias, inaccuracies, or misuse.
CLIMBS Culture Code
At Mach7, our culture is rooted in CLIMBS,a mindset that guides how we show up, collaborate, and grow each day. More than just a set of values, CLIMBS represents the standard we hold ourselves to and the way we approach our work, our teams, and our impact.
C - Customer First
Every decision starts with the customer's perspective. Success = customer outcomes and satisfaction.
L - Learn & Grow
Curiosity keeps us climbing. We embrace continuous learning, share knowledge freely, and invest in each other's development.
I - Innovate for Impact
We value meaningful, outcome-driven innovation over activity. We challenge the status quo and align behind real customer benefit.
M - Minimize Complexity & Move
As complex as needed but no more. Agility beats bureaucracy. We move fast and stay focused on what matters.
B - Build Good Sh*t
(Yes, intentionally memorable.) Extreme ownership, craftsmanship, and pride in high-quality work.
S - Everyone Sells
Not just Sales-Engineering, Product, Support, Finance, IT. We align behind commercial success to enable company success