1

Senior Security Engineer Jobs in Worcester, MA (NOW HIRING)

Senior Security Engineer

Framingham, MA · Hybrid

$117K - $161K/yr

The Senior Security Engineer is HealthDrive's in-house owner of day-to-day security operations and security configuration. This role handles the security work that arrives every day -- reported ...

Senior Product Security Engineer

Framingham, MA · On-site

$117K - $161K/yr

Principal Duties and Responsibilities As a Senior Product Security Engineer, you will work as an integral part of the Product Security team to embed security practices into every aspect of the secure ...

Senior Product Security Engineer

Framingham, MA · On-site

$117K - $161K/yr

Principal Duties and Responsibilities As a Senior Product Security Engineer, you will work as an integral part of the Product Security team to embed security practices into every aspect of the secure ...

Sr. Product Security Engineer

Newton, MA

$125K - $172K/yr

Medtronic Cardiac Ablation Solutions (CAS) is seeking a Senior Product Security Engineer to join our R&D organization and help secure cardiac ablation medical device solutions. This role focuses on ...

Sr. Product Security Engineer

Newton, MA

$125K - $172K/yr

Medtronic Cardiac Ablation Solutions (CAS) is seeking a Senior Product Security Engineer to join our R&D organization and help secure cardiac ablation medical device solutions. This role focuses on ...

next page

Showing results 1-20

Senior Security Engineer information

See Worcester, MA salary details

$73.3K

$136.8K

$186.1K

How much do senior security engineer jobs pay per year?

As of Sep 7, 2026, the average yearly pay for senior security engineer in Worcester, MA is $136,832.00, according to ZipRecruiter salary data. Most workers in this role earn between $114,200.00 and $156,700.00 per year, depending on experience, location, and employer.

What skills and qualifications are needed to be a senior security engineer?

To thrive as a Senior Security Engineer, you need deep expertise in network security, risk assessment, incident response, and a relevant degree or equivalent experience. Familiarity with security tools such as SIEM platforms, firewalls, IDS/IPS, and certifications like CISSP or CEH are typically required. Strong analytical thinking, effective communication, and leadership abilities help you excel in complex security environments. These skills and qualifications are crucial to safeguard organizational assets and maintain robust defense against evolving cyber threats.

How does a senior security engineer collaborate with other departments to enhance organizational security?

Senior Security Engineers frequently work cross-functionally, partnering with IT, software development, and compliance teams to implement security best practices and respond to incidents. They play a key role in conducting security reviews, advising on secure design, and leading incident response efforts. Effective communication and collaboration are essential, as these engineers often translate technical risks into business terms and provide guidance during audits or vulnerability assessments. This collaborative approach helps ensure comprehensive protection across all organizational assets.

What is the difference between Senior Security Engineer vs Security Analyst?

AspectSenior Security EngineerSecurity Analyst
Required CredentialsCertifications like CISSP, CISA, CEH; Bachelor's or Master's in Cybersecurity or related fieldsCertifications like CompTIA Security+, GIAC Security Essentials; Bachelor's in Cybersecurity, Information Technology, or related fields
Work EnvironmentDesigning security systems, implementing security measures, leading security projectsMonitoring security alerts, analyzing threats, conducting security assessments
Employer & Industry UsageUsed in tech companies, finance, healthcare for security infrastructure rolesCommon in various industries for threat detection and incident response

The main difference is that Senior Security Engineers focus on designing and implementing security solutions, while Security Analysts primarily monitor and analyze security threats. Both roles require relevant certifications and work in similar environments, but their responsibilities differ in scope and focus.

What are popular job titles related to Senior Security Engineer jobs in Worcester, MA?

For Senior Security Engineer jobs in Worcester, MA, the most frequently searched job titles are:

What job categories do people searching Senior Security Engineer jobs in Worcester, MA look for?

The top searched job categories for Senior Security Engineer jobs in Worcester, MA are:

What cities near Worcester, MA are hiring for Senior Security Engineer jobs?

Cities near Worcester, MA with the most Senior Security Engineer job openings:

Infographic showing various Senior Security Engineer job openings in Worcester, MA as of August 2026, with employment types broken down into 83% Full Time, 15% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $136,832 per year, or $65.8 per hour.

Senior Security Engineer

Healthdrive Corporation

Framingham, MA • Hybrid

$117K - $161K/yr

Full-time

Re-posted 3 days ago


Job description

Overview

About HealthDrive:

HealthDrive delivers on-site healthcare services to residents of long-term care facilities, offering a comprehensive suite of specialties including primary care, behavioral health, dentistry, optometry, podiatry, and audiology. Our mission is to improve the quality of life for patients through compassionate and consistent care, while supporting our partners with reliable, integrated healthcare solutions tailored to the unique needs of senior populations.

About the Role:

The Senior Security Engineer is HealthDrive's in-house owner of day-to-day security operations and security configuration. This role handles the security work that arrives every day - reported phishing, email and data loss prevention alerts, endpoint detections, and escalations from our managed security providers - and drives each to closure. It also owns the configuration and hardening of our Microsoft cloud estate and holds accountability for ensuring identified vulnerabilities are actually remediated.

HealthDrive uses managed security providers for around-the-clock monitoring and for network security engineering. This role sits above those providers: it directs their work, evaluates their performance, and remains the decision-maker for HealthDrive when a genuine security incident occurs. This is a hands-on engineering role, not a governance or audit role, and not a role that supervises staff.

Work Environment:

Based at HealthDrive's Framingham, MA office (off Route 9, near Routes 90 and 495) on a hybrid schedule. 

Compensation Range:

$85,000 to $115,000 / experience dependent

#INDHDCORPREC

Responsibilities

Day-to-Day Security Operations

  • Triage, investigate and resolve reported phishing and email-borne threats, including user communication and follow-up.
  • Monitor, tune and maintain email security and data loss prevention policy and alerting; investigate and disposition DLP events involving protected health information.
  • Own escalations from HealthDrive's managed detection provider from receipt through containment and closure, including endpoint detection and response alerts.
  • Investigate user-reported security concerns and suspicious activity, and maintain records of findings and actions taken.

Vulnerability Management

  • Own the vulnerability management cycle end to end: scanning, risk-based prioritization, and accountability for remediation reaching completion.
  • Work with Infrastructure and Software Development to schedule and validate remediation, including where patching conflicts with clinical or operational workflows.
  • Report remediation status, aging and exceptions to IT leadership on a defined cadence.

Cloud and Endpoint Security Configuration

  • Own security configuration and hardening of Microsoft Entra ID, including Conditional Access policy design, review and change control.
  • Own Microsoft 365 security configuration and data protection settings across mail, collaboration and file storage.
  • Maintain endpoint security policy and configuration, and verify coverage across the managed device estate.
  • Review and improve identity, access and privilege configuration, including administrative access and multi-factor authentication enforcement.

Managed Provider Oversight

  • Serve as HealthDrive's technical owner of the managed security provider relationships, covering monitoring, response and network security engineering services.
  • Direct provider work, submit and validate detection tuning requests, and reduce recurring false positives.
  • Run periodic service reviews, hold providers to contracted response commitments, and escalate performance shortfalls to IT leadership.
  • Maintain documented escalation paths and ensure HealthDrive retains the knowledge required to change providers without loss of continuity.

Incident Response

  • Recommend and implement containment and recovery actions for affected systems when a provider escalates a confirmed incident.
  • Maintain and exercise incident response procedures, and lead post-incident review and corrective action.
  • Support breach assessment and notification analysis in coordination with Compliance and Legal.

Security Program Support

  • Contribute to security awareness and phishing simulation programs.
  • Support security review of vendors and third parties, and of new applications and integrations, in partnership with Compliance.
  • Maintain security documentation, configuration baselines and operational runbooks.
Qualifications

Must have:

  • Approximately seven or more years of hands-on experience in security engineering or security operations, with demonstrated personal ownership of the work rather than coordination of it.
  • Demonstrated hands-on ownership of email security and data loss prevention. Proofpoint strongly preferred; comparable enterprise platforms considered.
  • Demonstrated hands-on experience configuring and securing Microsoft Entra ID and Microsoft 365, including Conditional Access policy design in a production environment.
  • Demonstrated ownership of a vulnerability management program, including driving remediation to closure across teams that do not report to this role.
  • Practical experience with endpoint detection and response platforms and with security monitoring or SIEM output. SentinelOne, Microsoft Sentinel or Secureworks Taegis are directly relevant.
  • Demonstrated incident response experience with sound judgment on containment decisions.
  • Experience working with or overseeing managed security service providers.
  • Working knowledge of enterprise network and firewall security sufficient to review provider work and partner effectively with Infrastructure. Fortinet experience is relevant.
  • Scripting or automation capability, such as PowerShell or Python.
  • Ability to communicate risk clearly to non-technical stakeholders, including clinical and operational leaders.

Nice to have: 

  • Healthcare provider-side experience and working familiarity with HIPAA and HITECH.
  • Experience with Qualys, Fortinet, SentinelOne, Microsoft Sentinel or Secureworks.
  • Third-party and vendor risk assessment experience.
  • Experience in a small or lean IT organization where breadth and self-direction are required.

Education & Qualifications:

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity or a related field, or equivalent demonstrated professional experience.

Certifications & Licenses:

  • CISSP preferred.
  • In the absence of CISSP, at least one of the following: AZ-500, SC-200, Security+, CySA+, CISM, CCSP or HCISPP

Core Competencies:

  • Communication 
  • Cooperation and Team working 
  • Adaptability 
  • Expertise and Professionalism 
  • Problem Solving / Analysis 
Employment Type: FULL_TIME