Information Security Engineer

September 18, 2026
Application ends: December 17, 2026
Apply Now

Job Description

Responsibilities

Security Architecture & Strategy

  • Architect and secure multi-tenant SaaS infrastructure, ensuring robust tenant isolation, data residency controls, and per-customer security boundaries
  • Lead the design and implementation of preventative security controls leveraging automation and AI-driven capabilities to reduce risk and improve detection and response
  • Establish and evolve DevSecOps and Infrastructure-as-Code (IaC) security standards, integrating security controls into CI/CD pipelines

SaaS & Customer Data Protection

  • Design and enforce security controls for SaaS-specific concerns including multi-tenancy, data segregation, API security, and identity federation (SSO, SAML, OIDC, OAuth 2.0)
  • Define data security and privacy controls to meet SaaS compliance requirements (SOC 2, ISO 27001, GDPR, CCPA) and support customer trust and audit readiness
  • Establish security architecture for customer-facing APIs and integrations, including third-party SaaS connectors, webhooks, and marketplace integrations

Application Security & Emerging Threats

  • Identify and establish controls to mitigate cybersecurity risks
  • Apply frameworks such as OWASP Top 10
  • Expand security capabilities into next-generation domains such as AI/ML security, container security, and advanced threat detection and response

Container & Runtime Security

  • Define and implement security architecture for containerized SaaS workloads (Kubernetes/EKS/GKE/AKS), including cluster hardening, workload isolation, image supply chain security, and runtime protection
  • Regularly audit and optimize internal DevOps processes to improve risk visibility and remediation across cloud, container, and SaaS environments
  • Lead evolution of cloud detection and response capabilities, integrating cloud telemetry, and advanced security analytics

Security Operations & Engineering

  • Architect and deliver automation frameworks and security services to improve scalability and operational efficiency across the security program
  • Maintain and monitor security operation infrastructure (task tracking system, IDS/IPS, SIEM, SAST, agentic MCP Servers used in security automation, etc) to ensure information security processes are protected from outage and security breach
  • Conduct and guide threat modeling and attack surface management for complex cloud-native and SaaS systems
  • Lead the implementation of vulnerability management and patch cadence processes aligned with SaaS release cycles
  • Influence security and engineering practices across multiple teams, driving adoption of secure-by-design principles

Technical Leadership

  • Provide technical mentorship to engineers and guide security-oriented thinking across product and infrastructure teams
  • Train and mentor junior security staff
  • Own security outcomes of key cloud and SaaS initiatives, ensuring successful delivery and measurable risk reduction
  • Collaborate with Product, Compliance, and Customer Success to address enterprise customer security requirements and questionnaires
  • Conduct security team presentation during company meetings and new hire training

Core Requirements

  • Bachelor’s or Master’s degree in Computer Science, Computer Engineering, Information Security, or related field (or equivalent experience)
  • 5-6 years of relevant professional experience
  • Proven experience designing and securing large-scale cloud architectures in SaaS or cloud-native product environments (AWS, Azure, GCP)
  • Deep expertise in cloud security architecture including IAM, network segmentation, encryption, secrets management, and secure design patterns, with hands-on experience designing and operating enterprise IAM solutions (e.g., Okta, Azure AD/Entra ID, Ping Identity, AWS IAM Identity Center) covering authentication, authorization, role-based access control (RBAC), and privileged access management (PAM)
  • Strong programming and automation skills with the ability to design and scale security engineering solutions, such as Ansible and Terraform, including hands-on DevOps experience automating SaaS infrastructure provisioning, configuration management, and operational workflows
  • Extensive experience implementing DevSecOps practices and securing Infrastructure-as-Code (IaC) workflows
  • Proven DevOps experience operating production SaaS environments, including building and maintaining CI/CD pipelines, configuration management with Ansible (or equivalent automation tools such as Chef), and Infrastructure-as-Code provisioning with Terraform
  • Experience with container technologies (Kubernetes, Docker, GKE) and related security tooling
  • Experience leading implementation and adoption of SIEM, SAST, DAST, IDS/IPS
  • Strong background in security prevention, detection, and response strategy for SaaS environments
  • Excellent communication skills with the ability to translate security risks for technical and non-technical stakeholders

SaaS & Compliance Experience

  • Hands-on experience securing multi-tenant SaaS architectures and understanding of SaaS-specific attack surfaces
  • Familiarity with SaaS compliance frameworks: SOC 2 Type II, ISO 27001, ISO 27701, GDPR, CCPA, NIST CSF, or similar
  • Experience with identity federation standards (SAML, OAuth 2.0, OIDC, SCIM) and enterprise SSO integration security, including identity lifecycle management, MFA enforcement, conditional access policies, and just-in-time (JIT) access provisioning for SaaS workforce and customer identities
  • Understanding of SaaS operational security practices: secret rotation, least-privilege access, customer data handling policies

Application Security & AI

  • Deep understanding of OWASP Top 10 vulnerabilities
  • Experience performing penetration testing application and network
  • Experience securing LLM integrations

Additional

  • Experience designing highly scalable, resilient, and secure architectures across application, network, and data layers
  • Relevant certifications preferred (e.g., ISC2 CISSP, AWS/GCP security specialty)
  • Experience working across multi-OS and distributed environments

Are you interested in this position?
Apply by clicking on the ā€œApply Nowā€ button below!
#GraphicDesignJobsOnline
#WebDesignRemoteJobs
#FreelanceGraphicDesigner
#WorkFromHomeDesignJobs
#OnlineWebDesignWork
#RemoteDesignOpportunities
#HireGraphicDesigners
#DigitalDesignCareers
# Dynamicbrand guru