Jobiglo

No results.

Information Security Engineer

moonpay · Bengaluru

New
Onsite Mid 🇬🇧 English
Python JavaScript OAuth SAML OIDC SSO MFA Threat modeling Incident response DLP Apple systems Google Workspace Slack Mimecast Code42 Okta Crowdstrike Cloudflare WARP Tenable Nessus Jamf Pro

Job description

About the role

We are looking for an Information Security Engineer, SaaS & Integration Security, to join our Information Security team. You will secure our internal SaaS ecosystem, third‑party integrations, APIs, and automation workflows, own the security review process for new SaaS applications, build threat‑modeling and secure‑design practices, and contribute to incident response for SaaS and identity‑related events.

Key responsibilities

  • Set and maintain security standards for SaaS apps, integrations, APIs, plugins, and automation platforms.
  • Assess new applications and integrations, reviewing architecture, data flows, OAuth scopes, tokens, service accounts and webhooks for excessive permissions or unauthorized access.
  • Facilitate risk‑based threat modeling, identify trust boundaries, and provide secure design alternatives.
  • Review Python, JavaScript, shell and low‑code automations for secrets handling, injection risks and excessive permissions.
  • Conduct vendor and third‑party security assessments, evaluate SOC 2 reports, pen‑test summaries and sub‑processor risk.
  • Act as L2 Incident Responder, monitor SaaS environments for suspicious activity, lead incidents through identification to recovery, and improve detections and playbooks.

Required profile

  • 3+ years experience in SaaS security, application security, cloud security or a related defensive role.
  • Proven experience conducting technical security reviews, threat modeling and vendor risk assessments.
  • Strong understanding of least‑privilege, defense‑in‑depth and identity concepts such as OAuth, SAML, OIDC, SSO and MFA.
  • Hands‑on experience with incident response and data‑loss‑prevention (DLP) in a fast‑paced environment.

Required skills

  • Python, JavaScript, Shell scripting.
  • OAuth, SAML, OIDC, SSO, MFA.
  • Threat modeling, security standards, vendor risk assessment.
  • Incident response, L2 SOC operations, DLP.
  • Tools: Apple systems, Google Workspace, Slack, Mimecast, Code42, Okta, Crowdstrike, Cloudflare WARP, Tenable Nessus, Jamf Pro.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec moonpay.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:lever

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 12 hours ago

Expires 1 month from now

5 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

moonpay

Bengaluru