bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCareers Ropesgray Icims ComInformation Security Engineer

Information Security Engineer

Careers Ropesgray Icims Com · New York, NY, US; Boston, MA, US · Hybrid · Active · $117,200–$178,700 / year · iCIMS

Job facts

FieldValue
CompanyCareers Ropesgray Icims Com
TitleInformation Security Engineer
Normalized title-
Department / team-
LocationNew York, NY, United States
Work modelHybrid / Hybrid
Employment typeOTHER
Salary$117,200–$178,700 / year
Statusactive
ATS provideriCIMS
Posted / first seen2026-06-17 / 2026-06-18
Changed / last seen2026-06-18 / 2026-06-21

Related slices

PageWhat it containsOpen
Company jobsActive postings from Careers Ropesgray Icims Com.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through iCIMS.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in New York.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCareers Ropesgray Icims Com
Sourced141ebb6-6649-4048-9b72-746795b5c35c
ATS provideriCIMS

Description

About Ropes & Gray Ropes & Gray is a preeminent global law firm. The firm has been ranked in the top three on The American Lawyer's prestigious A-List for eight consecutive years and #1 on Law.com's UK A-List twice in the past three years - rankings that honor the "best of the best" law firms. The firm has approximately 2,500 lawyers and professionals serving clients in major centers of business, finance, technology, and government in Boston, Chicago, Dublin, Hong Kong, London, Los Angeles, Milan, New York, Paris, San Francisco, Seoul, Shanghai, Silicon Valley, Singapore, Tokyo and Washington, D.C.The firm has consistently been recognized for its leading practices in many areas, including asset management, private equity, M&A, finance, real estate, tax, antitrust, life sciences, health care, intellectual property, litigation & enforcement, privacy & cybersecurity, and business restructuring. Ropes & Gray is an equal opportunity employer. Overview Under the direction of the Senior Manager of Information Security Engineering and Architecture, the Information Security Engineer implements, manages, and maintains the firm's information security infrastructure, empowers the firm's secure adoption of AI technologies, and responds to and investigates information security incidents to closure or escalation. The Information Security Engineer is a highly experienced, hands-on technologist with a professional foundation in network engineering, systems engineering, software development, cloud infrastructure engineering, or a related IT discipline, serving as the technical lead and subject matter expert for the implementation, administration, and maintenance for assigned information security technologies deployed by the firm. This role spans the full breadth of the firm’s technology landscape, including on-premises systems, cloud-native and hybrid architectures across IaaS, SaaS, and PaaS platforms, generative AI and agentic systems, and enterprise application environments, all consistent with industry best practices, applicable standards, and regulatory requirements. The scope of this position is firm wide and requires a thorough understanding of all IT systems the firm uses and how those systems are secured — encompassing on-premises infrastructure, multi-cloud platforms (IaaS), AI and machine learning systems, enterprise applications, and the network infrastructure that connects them. The Information Security Engineer advises the Information Security Team on emerging vulnerabilities and newly introduced risks to firm systems — including risks introduced by the adoption of generative AI, agentic AI architectures, and the continued expansion of cloud services — and takes a proactive approach in continually assessing the security of firm systems throughout their lifecycle, providing recommendations for enhancing security and adapting to new threats and vulnerabilities. Responsibilities ESSENTIAL FUNCTIONS: Excellent customer service skills and sense of urgency when resolving issues Strong knowledge of information security principles and practices Hands-on experience supporting hardware, software, and security architecture Serve as the subject matter expert (SME) for information security platforms, when assigned as the primary engineer; on-going threat analysis and research Play a significant role in responding to and containing information security related incidents Conduct regular technical risk assessments of firm systems and infrastructure Oversee and directly participate in the installation, configuration, and management of information security technologies Utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to continuously identify and remediate misconfigurations, compliance drift, and over-privileged access across IaaS, PaaS, and SaaS environments, including container orchestration platforms, serverless architectures, and CI/CD pipeline integrations Assess and mitigate security risks introduced by generative AI adoption — including prompt injection attacks, context manipulation, agentic workflow abuse, and Model Context Protocol (MCP) server vulnerabilities — and assist in the development and enforcement of organizational AI usage policies. Maintain current working knowledge of generative AI concepts and architecture — including large language models (LLMs), prompt engineering, context engineering, AI skills and function-calling, agentic AI frameworks, and Model Context Protocol (MCP) servers — in order to effectively evaluate, design security controls for, and advise stakeholders on AI-integrated systems and workflows Maintain expertise in the OWASP Top 10, OWASP Top-10 GenAI, CWE/CVE frameworks, and emerging application-layer attack techniques; API security testing, and web application firewall (WAF) policy management Network security experience — including next-generation firewalls (NGFW), intrusion detection and prevention systems (IDS/IPS), network segmentation and microsegmentation, network traffic analysis (NTA), DNS security, IPSec VPN, and secure access service edge (SASE) architectures — to protect firm technology infrastructure Assist in the development and knowledge transfer to Information Security team members, Information Services groups, and business support teams Promote a culture of information security across all business units Performs ticketed work-related duties Flexibility to work escalated issues and/or apply production changes off-hours where needed Participate in On-Call rotation for after-hours/weekend support Periodic travel may be required Qualifications EDUCATION, EXPERIENCE AND SKILLS REQUIRED: Self-directed and driven, with a proven ability to prioritize and execute independently in fast-paced environments. Bachelor of Science in Computer Science, Information Technology, Cybersecurity, or a related technical discipline; equivalent hands-on technical experience demonstrating the same depth of competency will be considered in lieu of a degree Minimum 3 years of experience in dedicated information security roles, with a demonstrated track record of engineering, deploying, and operating enterprise-scale security controls and leading response to sophisticated incidents 5 or more years of prior hands-on IT experience in a foundational technical discipline, such as network engineering, systems administration, software or application development, cloud infrastructure engineering, or DevOps/platform engineering Working knowledge of generative AI technologies and their associated security considerations, including LLM architecture, prompt engineering and context engineering concepts, AI skills and function-calling, agentic AI frameworks, and Model Context Protocol (MCP) server security; demonstrated ability to identify and mitigate AI-introduced risks is highly desirable Strong working knowledge of information security software and services, including EDR/XDR, zero trust network access (ZTNA), web security/proxy, application control, security service edge (SSE), DNS security, identity and access management (IAM/PAM), DLP, CASB, and SIEM platforms Strong working knowledge of Crowdstrike Next-Gen SIEM is desirable Strong knowledge of cloud security principles and architecture across all major delivery models: IaaS (AWS, Azure, GCP), SaaS (M365, NetDocs, iManage, Workday, etc.), and PaaS (container and Kubernetes security, serverless function hardening, and CI/CD pipeline security); M365 Defender and Microsoft Purview expertise is highly desirable; hands-on experience with CSPM and CNAPP tooling preferred Strong working knowledge of TCP/IP and network architecture Desired: Hands-on experience with network security technologies including next-generation firewalls (NGFW), IDS/IPS, network access control (NAC), network traffic analysis (NTA), microsegmentation, and SASE/SD-WAN architectures Desired: Hands-on application security experience including operation of SAST, DAST, and SCA tooling, API security testing and assessment, web application firewall (WAF) administration, secure SDLC program participation, and familiarity with DevSecOps practices Professional security certifications are desired but not required: CISSP, CCSP, CEH, OSCP, AWS Security Specialty, or GIAC certifications (GCIH, GPEN, GWEB, GWAPT, GCFE); active pursuit of relevant credentials is encouraged and supported by the firm Strong written and oral communication skills Organized, responsive and thorough problem solver Ability to manage multiple concurrent activities and effectively prioritize time and effort, in a high-pressure environment Ability to adapt quickly to changing priorities Maintains strict confidentiality regarding sensitive firm information, personnel matters, and internal affairs, and exercises sound discretion at all times. A committed team player who fosters strong working relationships, embraces the diverse expertise of colleagues, and contributes to a culture of trust, inclusion, and shared purpose. Compensation and Total Rewards Package Ropes & Gray is proud to offer a comprehensive Total Rewards package to our business support team members. The firm also offers comprehensive health and well-being benefits, personal and professional development, career growth opportunities and a collegial and supportive culture. The anticipated pay range for this role is listed below and represents our good faith and reasonable estimate of the starting salary range at the time of posting. In addition, this role is eligible for a discretionary bonus based on performance. The actual offered rate for this position will be determined based on job-related, non-discriminatory factors, including qualifications and experience, geographic location, education, external market data and consideration of internal equity. Boston: $117,200 - $178,700 New York: $127,900 - $195,000 Working Conditions Flexibility to work escalated issues off-hours and apply production changes where needed. Periodic travel may be required. The list of duties and responsibilities is not intended to be all-inclusive and may be expanded to include other duties or responsibilities that management may deem necessary from time to time.

Full job record

Job ID9729326b085cc0e713960060fd2543a2a481cb2f
Org IDfd42b313-88b6-40ee-b5b0-22ff104b8b5e
Source IDd141ebb6-6649-4048-9b72-746795b5c35c
Board IDd141ebb6-6649-4048-9b72-746795b5c35c
Providericims
Provider Job Key9200
TitleInformation Security Engineer
Normalized Title
Statusactive
Activeyes
Location TextNew York, NY, US; Boston, MA, US
Department
Team
Employment TypeOTHER
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionNY
CityNew York
Salary RawAbout Ropes & Gray Ropes & Gray is a preeminent global law firm. The firm has been ranked in the top three on The American Lawyer's prestigious A-List for eight consecutive years and #1 on Law.com's UK A-List twice in the past three years - rankings that honor the "best of the best" law firms. The firm has approximately 2,500 lawyers and professionals serving clients in major centers of business, finance, technology, and government in Boston, Chicago, Dublin, Hong Kong, London, Los Angeles, Milan, New York, Paris, San Francisco, Seoul, Shanghai, Silicon Valley, Singapore, Tokyo and Washington, D.C.The firm has consistently been recognized for its leading practices in many areas, including asset management, private equity, M&A, finance, real estate, tax, antitrust, life sciences, health care, intellectual property, litigation & enforcement, privacy & cybersecurity, and business restructuring. Ropes & Gray is an equal opportunity employer. Overview Under the direction of the Senior Manager of Information Security Engineering and Architecture, the Information Security Engineer implements, manages, and maintains the firm's information security infrastructure, empowers the firm's secure adoption of AI technologies, and responds to and investigates information security incidents to closure or escalation. The Information Security Engineer is a highly experienced, hands-on technologist with a professional foundation in network engineering, systems engineering, software development, cloud infrastructure engineering, or a related IT discipline, serving as the technical lead and subject matter expert for the implementation, administration, and maintenance for assigned information security technologies deployed by the firm. This role spans the full breadth of the firm’s technology landscape, including on-premises systems, cloud-native and hybrid architectures across IaaS, SaaS, and PaaS platforms, generative AI and agentic systems, and enterprise application environments, all consistent with industry best practices, applicable standards, and regulatory requirements. The scope of this position is firm wide and requires a thorough understanding of all IT systems the firm uses and how those systems are secured — encompassing on-premises infrastructure, multi-cloud platforms (IaaS), AI and machine learning systems, enterprise applications, and the network infrastructure that connects them. The Information Security Engineer advises the Information Security Team on emerging vulnerabilities and newly introduced risks to firm systems — including risks introduced by the adoption of generative AI, agentic AI architectures, and the continued expansion of cloud services — and takes a proactive approach in continually assessing the security of firm systems throughout their lifecycle, providing recommendations for enhancing security and adapting to new threats and vulnerabilities. Responsibilities ESSENTIAL FUNCTIONS: Excellent customer service skills and sense of urgency when resolving issues Strong knowledge of information security principles and practices Hands-on experience supporting hardware, software, and security architecture Serve as the subject matter expert (SME) for information security platforms, when assigned as the primary engineer; on-going threat analysis and research Play a significant role in responding to and containing information security related incidents Conduct regular technical risk assessments of firm systems and infrastructure Oversee and directly participate in the installation, configuration, and management of information security technologies Utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to continuously identify and remediate misconfigurations, compliance drift, and over-privileged access across IaaS, PaaS, and SaaS environments, including container orchestration platforms, serverless architectures, and CI/CD pipeline integrations Assess and mitigate security risks introduced by generative AI adoption — including prompt injection attacks, context manipulation, agentic workflow abuse, and Model Context Protocol (MCP) server vulnerabilities — and assist in the development and enforcement of organizational AI usage policies. Maintain current working knowledge of generative AI concepts and architecture — including large language models (LLMs), prompt engineering, context engineering, AI skills and function-calling, agentic AI frameworks, and Model Context Protocol (MCP) servers — in order to effectively evaluate, design security controls for, and advise stakeholders on AI-integrated systems and workflows Maintain expertise in the OWASP Top 10, OWASP Top-10 GenAI, CWE/CVE frameworks, and emerging application-layer attack techniques; API security testing, and web application firewall (WAF) policy management Network security experience — including next-generation firewalls (NGFW), intrusion detection and prevention systems (IDS/IPS), network segmentation and microsegmentation, network traffic analysis (NTA), DNS security, IPSec VPN, and secure access service edge (SASE) architectures — to protect firm technology infrastructure Assist in the development and knowledge transfer to Information Security team members, Information Services groups, and business support teams Promote a culture of information security across all business units Performs ticketed work-related duties Flexibility to work escalated issues and/or apply production changes off-hours where needed Participate in On-Call rotation for after-hours/weekend support Periodic travel may be required Qualifications EDUCATION, EXPERIENCE AND SKILLS REQUIRED: Self-directed and driven, with a proven ability to prioritize and execute independently in fast-paced environments. Bachelor of Science in Computer Science, Information Technology, Cybersecurity, or a related technical discipline; equivalent hands-on technical experience demonstrating the same depth of competency will be considered in lieu of a degree Minimum 3 years of experience in dedicated information security roles, with a demonstrated track record of engineering, deploying, and operating enterprise-scale security controls and leading response to sophisticated incidents 5 or more years of prior hands-on IT experience in a foundational technical discipline, such as network engineering, systems administration, software or application development, cloud infrastructure engineering, or DevOps/platform engineering Working knowledge of generative AI technologies and their associated security considerations, including LLM architecture, prompt engineering and context engineering concepts, AI skills and function-calling, agentic AI frameworks, and Model Context Protocol (MCP) server security; demonstrated ability to identify and mitigate AI-introduced risks is highly desirable Strong working knowledge of information security software and services, including EDR/XDR, zero trust network access (ZTNA), web security/proxy, application control, security service edge (SSE), DNS security, identity and access management (IAM/PAM), DLP, CASB, and SIEM platforms Strong working knowledge of Crowdstrike Next-Gen SIEM is desirable Strong knowledge of cloud security principles and architecture across all major delivery models: IaaS (AWS, Azure, GCP), SaaS (M365, NetDocs, iManage, Workday, etc.), and PaaS (container and Kubernetes security, serverless function hardening, and CI/CD pipeline security); M365 Defender and Microsoft Purview expertise is highly desirable; hands-on experience with CSPM and CNAPP tooling preferred Strong working knowledge of TCP/IP and network architecture Desired: Hands-on experience with network security technologies including next-generation firewalls (NGFW), IDS/IPS, network access control (NAC), network traffic analysis (NTA), microsegmentation, and SASE/SD-WAN architectures Desired: Hands-on application security experience including operation of SAST, DAST, and SCA tooling, API security testing and assessment, web application firewall (WAF) administration, secure SDLC program participation, and familiarity with DevSecOps practices Professional security certifications are desired but not required: CISSP, CCSP, CEH, OSCP, AWS Security Specialty, or GIAC certifications (GCIH, GPEN, GWEB, GWAPT, GCFE); active pursuit of relevant credentials is encouraged and supported by the firm Strong written and oral communication skills Organized, responsive and thorough problem solver Ability to manage multiple concurrent activities and effectively prioritize time and effort, in a high-pressure environment Ability to adapt quickly to changing priorities Maintains strict confidentiality regarding sensitive firm information, personnel matters, and internal affairs, and exercises sound discretion at all times. A committed team player who fosters strong working relationships, embraces the diverse expertise of colleagues, and contributes to a culture of trust, inclusion, and shared purpose. Compensation and Total Rewards Package Ropes & Gray is proud to offer a comprehensive Total Rewards package to our business support team members. The firm also offers comprehensive health and well-being benefits, personal and professional development, career growth opportunities and a collegial and supportive culture. The anticipated pay range for this role is listed below and represents our good faith and reasonable estimate of the starting salary range at the time of posting. In addition, this role is eligible for a discretionary bonus based on performance. The actual offered rate for this position will be determined based on job-related, non-discriminatory factors, including qualifications and experience, geographic location, education, external market data and consideration of internal equity. Boston: $117,200 - $178,700 New York: $127,900 - $195,000 Working Conditions Flexibility to work escalated issues off-hours and apply production changes where needed. Periodic travel may be required. The list of duties and responsibilities is not intended to be all-inclusive and may be expanded to include other duties or responsibilities that management may deem necessary from time to time.
Salary Min117,200
Salary Max178,700
Salary CurrencyUSD
Salary Periodyear
Source URLhttps://careers-ropesgray.icims.com/jobs/9200/information-security-engineer/job
Apply URLhttps://careers-ropesgray.icims.com/jobs/9200/information-security-engineer/job
First Seen At2026-06-18 08:42:17Z
Last Seen At2026-06-21 08:46:52Z
Last Checked At2026-06-21 08:46:52Z
Last Changed At2026-06-18 08:42:17Z
Inactive At
Source Posted At2026-06-17 04:00:00Z
Source Updated At2026-06-17 16:53:11Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=icims/board=careers-ropesgray.icims.com/date=2026-06-21/2026-06-21T08-46-50-590Z-b5f9cc7a549c5890d6ab8a8bf5cf174b21f84e2d378da93a42def72804110c3f.json
Event Fields
{
  "content_hash": "3bf8dd56e6e72de03f0beb7b83e1dfebd3257443364feef68ee1ceb44857c9a2",
  "source_hash": "35d60bc8949716fd54321825ac778194fb911395a5b75829c1662c5e79e26c1f",
  "last_changed_at": "2026-06-18T08:42:17.830Z",
  "active_status": "active"
}
Parsed Structured
{
  "dedupe": null,
  "language": "en",
  "location": {
    "raw": "New York, NY, US",
    "city": "New York",
    "region": "NY",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": 178700,
  "salary_min": 117200,
  "inferred_at": "2026-06-21T08:46:52.356Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "New York, NY, US",
      "city": "New York",
      "region": "NY",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": "year",
  "workplace_type": "hybrid",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "json_ld": {
    "url": "https://careers-ropesgray.icims.com/jobs/9200/information-security-engineer/job",
    "@type": "JobPosting",
    "title": "Information Security Engineer",
    "@context": "http://schema.org",
    "datePosted": "2026-06-17T04:00:00.000Z",
    "description": "<h2>About Ropes & Gray</h2>\n<p>Ropes & Gray is a preeminent global law firm. The firm has been ranked in the top three on <i>The American Lawyer's</i> prestigious A-List for eight consecutive years and #1 on <i>Law.com's</i> UK A-List twice in the past three years - rankings that honor the \"best of the best\" law firms. The firm has approximately 2,500 lawyers and professionals serving clients in major centers of business, finance, technology, and government in Boston, Chicago, Dublin, Hong Kong, London, Los Angeles, Milan, New York, Paris, San Francisco, Seoul, Shanghai, Silicon Valley, Singapore, Tokyo and Washington, D.C.The firm has consistently been recognized for its leading practices in many areas, including asset management, private equity, M&A, finance, real estate, tax, antitrust, life sciences, health care, intellectual property, litigation & enforcement, privacy & cybersecurity, and business restructuring. Ropes & Gray is an equal opportunity employer.</p>\n<h2>Overview</h2>\n<p>Under the direction of the Senior Manager of Information Security Engineering and Architecture, the Information Security Engineer implements, manages, and maintains the firm's information security infrastructure, empowers the firm's secure adoption of AI technologies, and responds to and investigates information security incidents to closure or escalation. The Information Security Engineer is a highly experienced, hands-on technologist with a professional foundation in network engineering, systems engineering, software development, cloud infrastructure engineering, or a related IT discipline, serving as the technical lead and subject matter expert for the implementation, administration, and maintenance for assigned information security technologies deployed by the firm. This role spans the full breadth of the firm’s technology landscape, including on-premises systems, cloud-native and hybrid architectures across IaaS, SaaS, and PaaS platforms, generative AI and agentic systems, and enterprise application environments, all consistent with industry best practices, applicable standards, and regulatory requirements.</p>\n<p> </p>\n<p>The scope of this position is firm wide and requires a thorough understanding of all IT systems the firm uses and how those systems are secured — encompassing on-premises infrastructure, multi-cloud platforms (IaaS), AI and machine learning systems, enterprise applications, and the network infrastructure that connects them.</p>\n<p> </p>\n<p>The Information Security Engineer advises the Information Security Team on emerging vulnerabilities and newly introduced risks to firm systems — including risks introduced by the adoption of generative AI, agentic AI architectures, and the continued expansion of cloud services — and takes a proactive approach in continually assessing the security of firm systems throughout their lifecycle, providing recommendations for enhancing security and adapting to new threats and vulnerabilities.</p>\n<h2>Responsibilities</h2>\n<p><strong>ESSENTIAL FUNCTIONS:</strong></p>\n<ul>\n <li>Excellent customer service skills and sense of urgency when resolving issues</li>\n <li>Strong knowledge of information security principles and practices</li>\n <li>Hands-on experience supporting hardware, software, and security architecture</li>\n <li>Serve as the subject matter expert (SME) for information security platforms, when assigned as the primary engineer; on-going threat analysis and research</li>\n <li>Play a significant role in responding to and containing information security related incidents</li>\n <li>Conduct regular technical risk assessments of firm systems and infrastructure</li>\n <li>Oversee and directly participate in the installation, configuration, and management of information security technologies</li>\n <li>Utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to continuously identify and remediate misconfigurations, compliance drift, and over-privileged access across IaaS, PaaS, and SaaS environments, including container orchestration platforms, serverless architectures, and CI/CD pipeline integrations</li>\n <li>Assess and mitigate security risks introduced by generative AI adoption — including prompt injection attacks, context manipulation, agentic workflow abuse, and Model Context Protocol (MCP) server vulnerabilities — and assist in the development and enforcement of organizational AI usage policies.</li>\n <li>Maintain current working knowledge of generative AI concepts and architecture — including large language models (LLMs), prompt engineering, context engineering, AI skills and function-calling, agentic AI frameworks, and Model Context Protocol (MCP) servers — in order to effectively evaluate, design security controls for, and advise stakeholders on AI-integrated systems and workflows</li>\n <li>Maintain expertise in the OWASP Top 10, OWASP Top-10 GenAI, CWE/CVE frameworks, and emerging application-layer attack techniques; API security testing, and web application firewall (WAF) policy management</li>\n <li>Network security experience — including next-generation firewalls (NGFW), intrusion detection and prevention systems (IDS/IPS), network segmentation and microsegmentation, network traffic analysis (NTA), DNS security, IPSec VPN, and secure access service edge (SASE) architectures — to protect firm technology infrastructure</li>\n <li>Assist in the development and knowledge transfer to Information Security team members, Information Services groups, and business support teams</li>\n <li>Promote a culture of information security across all business units</li>\n <li>Performs ticketed work-related duties</li>\n <li>Flexibility to work escalated issues and/or apply production changes off-hours where needed</li>\n <li>Participate in On-Call rotation for after-hours/weekend support</li>\n <li>Periodic travel may be required</li>\n</ul>\n<h2>Qualifications</h2>\n<p><strong>EDUCATION, EXPERIENCE AND SKILLS REQUIRED:</strong></p>\n<ul>\n <li>Self-directed and driven, with a proven ability to prioritize and execute independently in fast-paced environments. </li>\n <li>Bachelor of Science in Computer Science, Information Technology, Cybersecurity, or a related technical discipline; equivalent hands-on technical experience demonstrating the same depth of competency will be considered in lieu of a degree</li>\n <li>Minimum 3 years of experience in dedicated information security roles, with a demonstrated track record of engineering, deploying, and operating enterprise-scale security controls and leading response to sophisticated incidents</li>\n <li>5 or more years of prior hands-on IT experience in a foundational technical discipline, such as network engineering, systems administration, software or application development, cloud infrastructure engineering, or DevOps/platform engineering</li>\n <li>Working knowledge of generative AI technologies and their associated security considerations, including LLM architecture, prompt engineering and context engineering concepts, AI skills and function-calling, agentic AI frameworks, and Model Context Protocol (MCP) server security; demonstrated ability to identify and mitigate AI-introduced risks is highly desirable</li>\n <li>Strong working knowledge of information security software and services, including EDR/XDR, zero trust network access (ZTNA), web security/proxy, application control, security service edge (SSE), DNS security, identity and access management (IAM/PAM), DLP, CASB, and SIEM platforms</li>\n <li>Strong working knowledge of Crowdstrike Next-Gen SIEM is desirable</li>\n <li>Strong knowledge of cloud security principles and architecture across all major delivery models: IaaS (AWS, Azure, GCP), SaaS (M365, NetDocs, iManage, Workday, etc.), and PaaS (container and Kubernetes security, serverless function hardening, and CI/CD pipeline security); M365 Defender and Microsoft Purview expertise is highly desirable; hands-on experience with CSPM and CNAPP tooling preferred</li>\n <li>Strong working knowledge of TCP/IP and network architecture</li>\n <li>Desired: Hands-on experience with network security technologies including next-generation firewalls (NGFW), IDS/IPS, network access control (NAC), network traffic analysis (NTA), microsegmentation, and SASE/SD-WAN architectures</li>\n <li>Desired: Hands-on application security experience including operation of SAST, DAST, and SCA tooling, API security testing and assessment, web application firewall (WAF) administration, secure SDLC program participation, and familiarity with DevSecOps practices</li>\n <li>Professional security certifications are desired but not required: CISSP, CCSP, CEH, OSCP, AWS Security Specialty, or GIAC certifications (GCIH, GPEN, GWEB, GWAPT, GCFE); active pursuit of relevant credentials is encouraged and supported by the firm</li>\n <li>Strong written and oral communication skills</li>\n <li>Organized, responsive and thorough problem solver</li>\n <li>Ability to manage multiple concurrent activities and effectively prioritize time and effort, in a high-pressure environment</li>\n <li>Ability to adapt quickly to changing priorities</li>\n <li>Maintains strict confidentiality regarding sensitive firm information, personnel matters, and internal affairs, and exercises sound discretion at all times.</li>\n <li>A committed team player who fosters strong working relationships, embraces the diverse expertise of colleagues, and contributes to a culture of trust, inclusion, and shared purpose.</li>\n</ul>\n<h2>Compensation and Total Rewards Package</h2>\n<p>Ropes & Gray is proud to offer a comprehensive Total Rewards package to our business support team members. The firm also offers comprehensive health and well-being benefits, personal and professional development, career growth opportunities and a collegial and supportive culture. The anticipated pay range for this role is listed below and represents our good faith and reasonable estimate of the starting salary range at the time of posting. In addition, this role is eligible for a discretionary bonus based on performance. The actual offered rate for this position will be determined based on job-related, non-discriminatory factors, including qualifications and experience, geographic location, education, external market data and consideration of internal equity.</p>\n<ul>\n <li>Boston: $117,200 - $178,700</li>\n <li>New York: $127,900 - $195,000</li>\n</ul>\n<p> </p>\n<h2>Working Conditions</h2>\n<p>Flexibility to work escalated issues off-hours and apply production changes where needed.</p>\n<p> </p>\n<p>Periodic travel may be required.</p>\n<p> </p>\n<p>The list of duties and responsibilities is not intended to be all-inclusive and may be expanded to include other duties or responsibilities that management may deem necessary from time to time.<em> </em></p>",
    "directApply": true,
    "jobLocation": [
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "10036",
          "addressRegion": "NY",
          "streetAddress": "1211 Avenue of the Americas",
          "addressCountry": "US",
          "addressLocality": "New York",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      },
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "UNAVAILABLE",
          "addressRegion": "MA",
          "streetAddress": "UNAVAILABLE",
          "addressCountry": "US",
          "addressLocality": "Boston",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      }
    ],
    "validThrough": "2027-06-17T04:00:00.000Z",
    "employmentType": "OTHER",
    "hiringOrganization": {
      "name": "Ropes & Gray",
      "@type": "Organization",
      "sameAs": "www.ropesgray.com"
    }
  },
  "detail_meta": {
    "url": "https://careers-ropesgray.icims.com/jobs/9200/information-security-engineer/job?in_iframe=1",
    "http_status": 200,
    "content_type": "text/html;charset=UTF-8",
    "response_bytes": 53612,
    "compact_response_bytes": 12176,
    "original_response_bytes": 53612
  },
  "sitemap_job": {
    "id": "9200",
    "url": "https://careers-ropesgray.icims.com/jobs/9200/information-security-engineer/job",
    "slug": "information-security-engineer",
    "lastmod": "2026-06-17T12:53:11-04:00"
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/9729326b085cc0e713960060fd2543a2a481cb2f?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/fd42b313-88b6-40ee-b5b0-22ff104b8b5eJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/d141ebb6-6649-4048-9b72-746795b5c35cJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/9729326b085cc0e713960060fd2543a2a481cb2f/eventsJSON