Job Description
Responsibilities
Security Architecture & Strategy
- Architect and secure multi-tenant SaaS infrastructure, ensuring robust tenant isolation, data residency controls, and per-customer security boundaries
- Lead the design and implementation of preventative security controls leveraging automation and AI-driven capabilities to reduce risk and improve detection and response
- Establish and evolve DevSecOps and Infrastructure-as-Code (IaC) security standards, integrating security controls into CI/CD pipelines
SaaS & Customer Data Protection
- Design and enforce security controls for SaaS-specific concerns including multi-tenancy, data segregation, API security, and identity federation (SSO, SAML, OIDC, OAuth 2.0)
- Define data security and privacy controls to meet SaaS compliance requirements (SOC 2, ISO 27001, GDPR, CCPA) and support customer trust and audit readiness
- Establish security architecture for customer-facing APIs and integrations, including third-party SaaS connectors, webhooks, and marketplace integrations
Application Security & Emerging Threats
- Identify and establish controls to mitigate cybersecurity risks
- Apply frameworks such as OWASP Top 10
- Expand security capabilities into next-generation domains such as AI/ML security, container security, and advanced threat detection and response
Container & Runtime Security
- Define and implement security architecture for containerized SaaS workloads (Kubernetes/EKS/GKE/AKS), including cluster hardening, workload isolation, image supply chain security, and runtime protection
- Regularly audit and optimize internal DevOps processes to improve risk visibility and remediation across cloud, container, and SaaS environments
- Lead evolution of cloud detection and response capabilities, integrating cloud telemetry, and advanced security analytics
Security Operations & Engineering
- Architect and deliver automation frameworks and security services to improve scalability and operational efficiency across the security program
- Maintain and monitor security operation infrastructure (task tracking system, IDS/IPS, SIEM, SAST, agentic MCP Servers used in security automation, etc) to ensure information security processes are protected from outage and security breach
- Conduct and guide threat modeling and attack surface management for complex cloud-native and SaaS systems
- Lead the implementation of vulnerability management and patch cadence processes aligned with SaaS release cycles
- Influence security and engineering practices across multiple teams, driving adoption of secure-by-design principles
Technical Leadership
- Provide technical mentorship to engineers and guide security-oriented thinking across product and infrastructure teams
- Train and mentor junior security staff
- Own security outcomes of key cloud and SaaS initiatives, ensuring successful delivery and measurable risk reduction
- Collaborate with Product, Compliance, and Customer Success to address enterprise customer security requirements and questionnaires
- Conduct security team presentation during company meetings and new hire training
Core Requirements
- Bachelor’s or Master’s degree in Computer Science, Computer Engineering, Information Security, or related field (or equivalent experience)
- 5-6 years of relevant professional experience
- Proven experience designing and securing large-scale cloud architectures in SaaS or cloud-native product environments (AWS, Azure, GCP)
- Deep expertise in cloud security architecture including IAM, network segmentation, encryption, secrets management, and secure design patterns, with hands-on experience designing and operating enterprise IAM solutions (e.g., Okta, Azure AD/Entra ID, Ping Identity, AWS IAM Identity Center) covering authentication, authorization, role-based access control (RBAC), and privileged access management (PAM)
- Strong programming and automation skills with the ability to design and scale security engineering solutions, such as Ansible and Terraform, including hands-on DevOps experience automating SaaS infrastructure provisioning, configuration management, and operational workflows
- Extensive experience implementing DevSecOps practices and securing Infrastructure-as-Code (IaC) workflows
- Proven DevOps experience operating production SaaS environments, including building and maintaining CI/CD pipelines, configuration management with Ansible (or equivalent automation tools such as Chef), and Infrastructure-as-Code provisioning with Terraform
- Experience with container technologies (Kubernetes, Docker, GKE) and related security tooling
- Experience leading implementation and adoption of SIEM, SAST, DAST, IDS/IPS
- Strong background in security prevention, detection, and response strategy for SaaS environments
- Excellent communication skills with the ability to translate security risks for technical and non-technical stakeholders
SaaS & Compliance Experience
- Hands-on experience securing multi-tenant SaaS architectures and understanding of SaaS-specific attack surfaces
- Familiarity with SaaS compliance frameworks: SOC 2 Type II, ISO 27001, ISO 27701, GDPR, CCPA, NIST CSF, or similar
- Experience with identity federation standards (SAML, OAuth 2.0, OIDC, SCIM) and enterprise SSO integration security, including identity lifecycle management, MFA enforcement, conditional access policies, and just-in-time (JIT) access provisioning for SaaS workforce and customer identities
- Understanding of SaaS operational security practices: secret rotation, least-privilege access, customer data handling policies
Application Security & AI
- Deep understanding of OWASP Top 10 vulnerabilities
- Experience performing penetration testing application and network
- Experience securing LLM integrations
Additional
- Experience designing highly scalable, resilient, and secure architectures across application, network, and data layers
- Relevant certifications preferred (e.g., ISC2 CISSP, AWS/GCP security specialty)
- Experience working across multi-OS and distributed environments
Are you interested in this position?
Apply by clicking on the āApply Nowā button below!
#GraphicDesignJobsOnline
#WebDesignRemoteJobs
#FreelanceGraphicDesigner
#WorkFromHomeDesignJobs
#OnlineWebDesignWork
#RemoteDesignOpportunities
#HireGraphicDesigners
#DigitalDesignCareers
# Dynamicbrand guru