Motion Recruitment
Security Assurance Engineer / AWS / QA / IAM
Motion Recruitment is hiring a Security Assurance Engineer / AWS / QA / IAM in Boston, MA, United States. Posted October 8, 2026.
Job at a glance
- Company
- Motion Recruitment
- Location
- Boston, MA, United States
- Pay
- $82 – $92
- Workplace
- On-site
- Sector
- Engineering & Technology
- Posted
- October 8, 2026
- First scanned
- October 9, 2026
- Apply by
- December 12, 2026
About the job
We are looking for a Security Assurance Engineer to join a large-scale public-sector technology modernization initiative in Boston, MA. This is a contract opportunity with a hybrid schedule, requiring 3 days onsite per week for the first 90 days and 2 days onsite thereafter. The role will focus on application security, cloud security, vulnerability management, security testing, and release readiness across AWS, Salesforce, GitHub, Jira, Tenable, Veracode, and AI-enabled applications.
This is a great opportunity for a security engineer who wants to be involved throughout the full project lifecycle rather than coming in after the fact to review vulnerabilities. You’ll work directly with application, cloud, development, architecture, testing, and project teams to build security into two major modernization initiatives from design through deployment. The environment includes public-facing applications, cloud integrations, Salesforce, AI/LLM solutions, RAG pipelines, and sensitive data, giving you exposure to a wide range of modern security challenges. The ideal person will be hands-on, comfortable working independently, and able to communicate technical risk clearly to both technical and non-technical stakeholders.
Contract Duration: 6–12 Months, with the project currently running through June 2027 and potential for extension
Required Skills & Experience
· 5+ years of experience in application security, cloud security, product security, security engineering, or a related field
· Experience defining security requirements and reviewing application architectures, data flows, integrations, and technical controls
· Experience with SAST, DAST, penetration testing, vulnerability scanning, vulnerability triage, and remediation
· Strong experience with risk analysis, remediation planning, and tracking security findings through closure
· Hands-on experience with Jira and GitHub
· Experience with cloud and application security, preferably AWS
· Experience working with SaaS applications, APIs, identity, data protection, logging, and deployment controls
· Ability to coordinate security initiatives across engineering, development, architecture, vendors, testing teams, and project leadership
· Strong communication and documentation skills
· Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field, or equivalent experience
Desired Skills & Experience
· Experience with Workday, Salesforce, or other large enterprise SaaS platforms
· Experience with Tenable Cloud and/or Veracode
· Experience with GitHub Copilot or other approved AI-assisted security tools
· Experience securing AI/LLM applications, RAG pipelines, or voice/AI models
· Knowledge of prompt injection, data leakage, retrieval poisoning, jailbreaks, and AI guardrails
· Experience with AWS security and cloud-native applications
· Knowledge of NIST security frameworks
· Experience in public-sector, financial services, consumer protection, or another regulated environment
· CISSP, CCSP, CSSLP, or comparable security certification
· Experience with legacy application modernization, cloud migrations, and complex integrations
What You Will Be Doing
Tech Breakdown
· 25% Application & Cloud Security
· 20% Vulnerability Management & Security Testing
· 15% AI/LLM Security & Adversarial Testing
· 15% Risk Analysis & Security Controls
· 15% Remediation & Release Readiness
· 10% Security Documentation & Reporting
Daily Responsibilities
· 35% Hands-On Security Engineering — vulnerability triage, security testing, architecture reviews, control implementation, remediation validation, and AI security testing
· 25% Risk & Release Readiness — assessing findings, developing remediation plans, validating closure, and supporting go-live decisions
· 25% Team Collaboration — partnering with developers, architects, project teams, vendors, testing teams, and security stakeholders
· 15% Documentation & Reporting — maintaining security evidence, risk decisions, remediation status, and project reporting