Boston, MAremote

Salary
$164,000–$237,000
Posted
Jun 29, 2026
Location
Boston, MA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A security engineering role focused on hardening a cloud-based platform across application, infrastructure, and pipeline layers. Day-to-day work covers IAM configuration, authentication and API authorization patterns, secrets and data-flow security, security monitoring, and embedding scanning tools into CI/CD workflows, alongside periodic assessments and incident response. Suited to an experienced individual contributor with 8+ years in application or infrastructure security, comfortable in a fast-moving environment and collaborating across offices in Boston and Taipei.

Senior level · 8+ years · Remote · Bachelor's required · Full-time

Pay in the description: $164,000–$237,000

Must have (7)
GCP, AWS or AzureIAMOAuthSASTDASTCI/CDNode.js
Nice to have (3)
Next.jsTerraformpenetration testing

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 1,300 people nationally plausibly meet what this posting asks for (information security analysts). range 790–2,000

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
IAM45%CI/CD45%Node.js40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $129,180 (middle half $97,810–$163,500). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The job posting explicitly states this is an IN-OFFICE position in Boston, MA. The caller has overridden this to remote=true with a national candidate pool; the metro has been left blank accordingly.

Node.js/Next.js is listed under Required Qualifications as 'preferably in Node.js/Next.js environments' — the 'preferably' qualifier softens Node.js slightly, but it sits in the required section and is the only named environment, so Node.js is treated as a hard gate. Next.js is listed as a secondary preference within that phrase and is marked preferred.

GCP is listed under Knowledge and Skills (a requirements-style section) with 'or equivalent platforms' — treated as a hard gate on cloud security capability; AWS and Azure are the primary equivalents.

Penetration testing appears both in the responsibilities (as a duty) and under Preferred Qualifications ('is a plus') — the preferred-qualifications framing governs, so it is marked preferred.

Terraform security hardening is explicitly called 'a plus' under Preferred Qualifications.

The alt SOC (15-1252 Software Developers) is noted because the role includes building and maintaining security tooling integrated into CI/CD pipelines, which has a meaningful software-engineering component alongside the dominant security-analyst work.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗