Information Security Engineer
Core
SecOps engineer securing internal SaaS ecosystem, third-party integrations, APIs, and automation workflows while leading incident response.
Role type
Senior IC Information Security Engineer (SaaS & Integration Security)
Builds
Secure design patterns, threat models, security review processes, and automated checks for integrations and scripts.
Domain
Cybersecurity, SaaS, Cloud Security, Identity & Access Management
Required skills
SaaS security, application security, cloud security, threat modeling, incident response, DLP, vendor risk assessment, OAuth/SAML/OIDC, secrets management, script security (Python/JS/shell), least privilege, defense in depth
Preferred skills
Experience with Apple systems, Google Workspace, Slack, Mimecast, Code42, Okta, CrowdStrike, Cloudflare WARP, Tenable Nessus, Jamf Pro, OWASP, MITRE ATT&CK, NIST, CIS Controls
Technologies
Apple systems, Google Workspace, Slack, Mimecast, Code42, Okta, CrowdStrike, Cloudflare WARP, Tenable Nessus, Jamf Pro, Python, JavaScript, shell
Responsibilities
Conduct security reviews for new SaaS applications and integrations; facilitate risk-based threat modeling for APIs and automation; lead L2 incident response for SaaS and identity events; assess vendor and third-party security posture; detect and reduce shadow IT; review scripts for secrets handling and injection risks.
Seniority
Senior, hands-on IC
