Назад
4 дня назад

TSS Information Security Engineer (SaaS & Integrations)

Тип работы
fulltime
Грейд
middle
Страна
India
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

TL;DR
TSS Information Security Engineer (SaaS & Integrations): Owning security reviews and approvals for SaaS applications, integrations, APIs, plugins, automation platforms, and AI integrations with an accent on threat modeling, permissions analysis, and defensive security. Focus on identifying trust boundaries and abuse cases, reviewing automation code for secrets and injection risks, and responding to SaaS and identity incidents.
TSS Information Security Engineer, SaaS & Integrations

Full-time / Company: MoonPay

MoonPay builds the operating system for value movement — enabling crypto, stablecoins, tokenized assets and payments for 30M+ customers and 500+ partners. The company is regulated across multiple jurisdictions and uses AI broadly to drive efficiency and impact.

Applicants must be located in Bengaluru, India.

Responsibilities:

- Own the security review and approval process for new SaaS apps, integrations, APIs, plugins, and automation platforms.
- Define and maintain security standards, approved patterns, and threat models for integrations, non-human identities, and automation workflows.
- Assess OAuth scopes, tokens, webhooks, service accounts, marketplace apps, and AI integrations for excessive permissions and exposure.
- Conduct threat modeling, identify trust boundaries and abuse cases, and ensure risk owners and mitigations are assigned.
- Review scripts and automations (Python, JavaScript, shell, low-code) for secrets handling, injection risks, and unsafe processing; promote centralized secrets management.
- Act as L2 Incident Responder for SaaS/identity incidents: monitor, investigate, contain, and translate learnings into detections and playbooks.

Requirements:

- 3+ years in SaaS security, application/cloud security, or a related defensive security role.
- Experience conducting technical security reviews and risk-based threat modeling for integrations and APIs.
- Strong expertise in DLP and hands-on incident response experience.
- Comfortable working across technical tooling, process development, and cross-functional collaboration.

Stack:

Apple systems, Google Workspace, Slack, Mimecast, Code42, Okta, Crowdstrike, Cloudflare WARP, Tenable Nessus, Jamf Pro

📩

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -