Information Security Engineer

You will secure internal SaaS applications third-party integrations APIs and automation workflows. You will conduct security reviews threat modeling and vendor assessments, improve secrets management and secure design practices, test integrations, and lead SaaS-related incidents through containment recovery and lessons learned.

Responsibilities

  • Set security standards for SaaS applications integrations APIs plugins and automation platforms
  • Assess application architectures data flows trust boundaries permissions and third-party access
  • Facilitate risk-based threat modeling and provide secure design alternatives
  • Review automation scripts for secrets handling injection risks unsafe processing and excessive permissions
  • Build automated checks for exposed secrets insecure configurations and permission risks
  • Conduct vendor and third-party security assessments
  • Monitor SaaS environments for suspicious activity unauthorized integrations and data leakage
  • Lead security incidents through identification containment eradication recovery and lessons learned
  • Improve detections dashboards playbooks and incident-response processes

Requirements

  • 3+ years of experience in SaaS security application security cloud security or a related defensive security role
  • Experience conducting technical security reviews and risk-based threat modeling
  • Experience assessing third-party integrations APIs and vendor risk
  • Experience validating security findings and driving remediation
  • Strong understanding of least privilege defense in depth and trust boundaries
  • Understanding of OAuth SAML OIDC SSO and MFA
  • Familiarity with excessive permissions cross-tenant exposure insecure data flows injection credential exposure and supply-chain compromise
  • Working knowledge of OWASP MITRE ATT&CK NIST or CIS Controls
  • Ability to review Python JavaScript or shell scripts for security weaknesses
  • Understanding of secrets management short-lived credentials and secure API design
  • Experience securing Okta Google Workspace and Google Cloud Platform
  • Experience assessing security controls in SaaS tools including Linear Slack Notion Intercom Jira and Confluence
  • Ability to build or use automated security checks
  • Excellent analytical and problem-solving abilities
  • Ability to work effectively under pressure and handle multiple incidents simultaneously
  • Strong communication and interpersonal skills
  • Practical incident-response experience
  • Experience with vulnerability management and vendor security assessments
  • Bachelor's degree in Computer Science Information Security or a related field or equivalent experience

Benefits

  • Equity package
  • Pay-for-performance equity bonus
  • Moonshot award with a $250,000 equity grant for selected employees twice a year
  • Employer pension contributions from day one
  • Employee referral program paying 10K in USDC
  • Flexible time off
  • Birthday leave
  • Enhanced parental leave
  • Hybrid working schedule with fully remote work or work from the nearest Moonbase
  • Public transport commuter benefits
  • Private healthcare benefits
  • Wellhub wellness membership
  • Unlimited enterprise access to AI tools
  • Lunch credit on office days
  • Home office setup allowance
  • Remote working allowance for fully remote employees
  • Monthly product budget and zero-fee crypto transactions
  • Regular remote company offsites
  • Ireland Cycle to Work scheme
  • UK EV Salary Sacrifice

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available