Information Security Engineer
You will secure internal SaaS applications third-party integrations APIs and automation workflows. You will conduct security reviews threat modeling and vendor assessments, improve secrets management and secure design practices, test integrations, and lead SaaS-related incidents through containment recovery and lessons learned.
Responsibilities
- Set security standards for SaaS applications integrations APIs plugins and automation platforms
- Assess application architectures data flows trust boundaries permissions and third-party access
- Facilitate risk-based threat modeling and provide secure design alternatives
- Review automation scripts for secrets handling injection risks unsafe processing and excessive permissions
- Build automated checks for exposed secrets insecure configurations and permission risks
- Conduct vendor and third-party security assessments
- Monitor SaaS environments for suspicious activity unauthorized integrations and data leakage
- Lead security incidents through identification containment eradication recovery and lessons learned
- Improve detections dashboards playbooks and incident-response processes
Requirements
- 3+ years of experience in SaaS security application security cloud security or a related defensive security role
- Experience conducting technical security reviews and risk-based threat modeling
- Experience assessing third-party integrations APIs and vendor risk
- Experience validating security findings and driving remediation
- Strong understanding of least privilege defense in depth and trust boundaries
- Understanding of OAuth SAML OIDC SSO and MFA
- Familiarity with excessive permissions cross-tenant exposure insecure data flows injection credential exposure and supply-chain compromise
- Working knowledge of OWASP MITRE ATT&CK NIST or CIS Controls
- Ability to review Python JavaScript or shell scripts for security weaknesses
- Understanding of secrets management short-lived credentials and secure API design
- Experience securing Okta Google Workspace and Google Cloud Platform
- Experience assessing security controls in SaaS tools including Linear Slack Notion Intercom Jira and Confluence
- Ability to build or use automated security checks
- Excellent analytical and problem-solving abilities
- Ability to work effectively under pressure and handle multiple incidents simultaneously
- Strong communication and interpersonal skills
- Practical incident-response experience
- Experience with vulnerability management and vendor security assessments
- Bachelor's degree in Computer Science Information Security or a related field or equivalent experience
Benefits
- Equity package
- Pay-for-performance equity bonus
- Moonshot award with a $250,000 equity grant for selected employees twice a year
- Employer pension contributions from day one
- Employee referral program paying 10K in USDC
- Flexible time off
- Birthday leave
- Enhanced parental leave
- Hybrid working schedule with fully remote work or work from the nearest Moonbase
- Public transport commuter benefits
- Private healthcare benefits
- Wellhub wellness membership
- Unlimited enterprise access to AI tools
- Lunch credit on office days
- Home office setup allowance
- Remote working allowance for fully remote employees
- Monthly product budget and zero-fee crypto transactions
- Regular remote company offsites
- Ireland Cycle to Work scheme
- UK EV Salary Sacrifice