Skip to content

Open nowPosted 39 days ago

Security Engineer III - SAAS

ibgllc180 open roles

Where
Mumbai, Maharashtra, India
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer III - SAASibgllc · Mumbai, Maharashtra, India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on ibgllc's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 39 days ago

The posting

Role Overview The Security Engineer III – SaaS Security leads structured threat modeling across the firm's SaaS applications, cloud-native platforms, APIs, and third-party SaaS integrations to identify design level risk before it reaches production. This is a hands on, technical contributor role for someone who thinks like an adversary, understands modern multi-tenant SaaS and cloud architecture deeply, and can turn complex technical exposure into clear, prioritized, business-relevant risk. You will partner closely with product and platform engineering to drive secure-by-design outcomes across high-risk systems such as trading platforms, client portals, and the APIs and integrations that connect them. Key Responsibilities End to End Threat Modeling (core focus)

Lead threat modeling across the full deployment gamut of SaaS, cloud native, on premise, hybrid, and third-party systems, including applications, infrastructure, microservices, monoliths, APIs, network architecture, and data flows, using methodologies such as STRIDE, PASTA, or attack trees, supported by data flow diagrams (DFDs). Map attack surface, trust boundaries, and abuse cases across cloud, data center, network, and endpoint layers, drawing on threat knowledge bases (MITRE ATT&CK including Enterprise, Cloud/SaaS, ICS, and Containers matrices, CAPEC, OWASP Top 10 and API Security Top 10).

Model environment specific risk across the ecosystem, including:

SaaS and multi-tenant: tenant isolation, data segregation, token and secrets management, and API authorization (e.g., BOLA/IDOR, broken function level authorization). Identity and access: authentication and federation flows (OAuth 2.0 / OIDC, SAML/SSO, SCIM provisioning, Kerberos/Active Directory, LDAP), privileged access, and lateral movement paths. Cloud native (AWS, Azure, GCP): IAM and over permissioned roles, exposed storage, containers/Kubernetes, serverless, and infrastructure as code, within the relevant shared responsibility model. On premise and hybrid: data center and network segmentation, east west traffic, legacy and end of life systems, physical and virtualized infrastructure, on premise to cloud connectivity, and the trust boundaries between them. Translate technical findings into documented, prioritized business risk exposure with clear risk ratings, irrespective of where a system is hosted or how it is deployed.

Secure by Design and Engineering Partnership

Embed threat modeling into the SDLC and architecture lifecycle, and shift security left into design and architecture reviews for new builds, migrations, and modernization of existing on-premises estates. Partner with product, platform, and infrastructure engineering to recommend mitigations, secure design patterns, and reference architectures across cloud and on-premises environments. Build and maintain reusable threat model libraries, templates, and security patterns to scale coverage across diverse deployment models. Support adoption of threat modeling tooling and threat modeling as code and validate that recommended controls are implemented.

Integration, Supply Chain, and Ecosystem Risk

Threat model integrations across the ecosystem, including third party SaaS, on premise and vendor systems, data flows, authentication, API exposure, webhook and OAuth scope risk, and supply chain and system to system paths (SaaS to SaaS, cloud to on premise, and B2B connectivity). Evaluate vendor and partner architectures where they intersect the firm's threat models and trust boundaries.

Risk Communication & Governance

Produce high-quality threat models and recommendations and tailor communication for both technical and non-technical audiences. Brief leadership with concise, decision ready risk insights, and escalate high risk design flaws with context and recommended actions. Align threat models with enterprise frameworks (NIST CSF, ISO 27001, CSA Cloud Controls Matrix) and applicable financial services obligations (e.g., DORA, NYDFS 500, RBI guidance). Track and report key risk indicators such as threat model coverage across the estate and finding closure rates.

Required Qualifications

Typically, 5 to 8 years in cybersecurity (or equivalent demonstrated depth) with a focus on threat modeling, application/product security, or security architecture across cloud, SaaS, and on-premise environments. Demonstrated, hands on threat modeling of modern and traditional systems using a structured methodology (e.g., STRIDE, PASTA) with DFDs. Strong understanding of both cloud native and on-premise architectures: multi tenancy, APIs, microservices, network and infrastructure design, and identity/authentication flows (OAuth/OIDC, SAML/SSO, Active Directory/Kerberos). Working knowledge of AWS, Azure, or GCP and their shared responsibility models, plus familiarity with data centers, networks, and hybrid infrastructure security. Familiarity with OWASP (Top 10 and API Security Top 10) and MITRE ATT&CK / CAPEC. Ability to translate technical risk into clear business terms, with strong written and verbal communication. Bachelor's degree in a related field or equivalent practical experience.

Preferred Qualifications

Experience in financial services or another regulated industry (e.g., DORA, NYDFS 500, RBI guidelines). Hands-on with threat-modeling tooling / threat-modeling-as-code (e.g., IriusRisk, OWASP Threat Dragon, Microsoft Threat Modeling Tool, ThreatModeler). Experience with DevSecOps, secure SDLC, infrastructure-as-code (Terraform), containers/Kubernetes, or secure code review. Exposure to AI/ML or LLM application threat modeling and other emerging technology risks. Certifications such as CSSLP, CCSP, CISSP, or a cloud-security specialty (e.g., AWS Certified Security – Specialty, Azure Security Engineer).

Core Competencies

Adversarial and systems thinking. Deep technical understanding of cloud, SaaS, and on-premise architecture across the ecosystem. Secure by design, shift left mindset. Clear communication across technical and business audiences. Strong collaboration with engineering, platform, and infrastructure teams. Ownership and accountability for deliverables.

Company Benefits & Perks: • Competitive salary package.• Performance based annual bonus (cash and stocks).• Group Medical & Life Insurance.• Modern offices with free amenities & fully stocked cafeterias.• Monthly food card & company paid snacks.• Hardship/shift allowance with company provided pickup & drop facility• Attractive employee referral bonus.• Frequent company sponsored team building events and outings. Depending upon the shifts.  **The benefits package is subject to change at the management's discretion.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against ibgllc's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on ibgllc's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    ibgllc's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.