CrawlJobs Logo

SaaS Security Engineer (SSPM)

United States, Phoenix Contract work · Job Posted June 17, 2026
Apply Position
Job Link Share

Job Description

The Opportunity: We are seeking a SaaS Security Posture Management (SSPM) Engineer to support enterprise SaaS security initiatives by designing, implementing, and managing security posture management capabilities across a rapidly growing SaaS ecosystem. This role will be responsible for strengthening SaaS security governance, automating security controls, and continuously monitoring SaaS platforms to identify and remediate security risks. The ideal candidate has a strong background in SaaS security, cloud security, automation, and identity governance, with hands-on experience implementing SSPM solutions and integrating security controls across enterprise platforms. This individual will work closely with security, cloud, governance, and engineering teams to enhance visibility, reduce risk, and support the secure adoption of cloud and AI-enabled technologies.

Job Responsibility

  • Lead the implementation, configuration, and administration of SaaS Security Posture Management (SSPM) platforms across enterprise environments
  • Continuously assess SaaS applications for security risks, configuration weaknesses, identity governance issues, excessive permissions, and data exposure concerns
  • Monitor and remediate SaaS configuration drift and security posture deviations across business-critical applications
  • Identify and evaluate risks associated with third-party integrations, connected applications, and SaaS ecosystems
  • Establish SaaS security baselines, governance controls, and remediation processes to improve overall security posture
  • Support SaaS onboarding, certification, and security review activities to ensure compliance with enterprise security requirements
  • Develop and maintain integrations between SSPM platforms, Identity and Access Management (IAM) solutions, SIEM platforms, governance tools, and ticketing systems
  • Build automation workflows using APIs, scripting, and Infrastructure-as-Code methodologies to improve operational efficiency and security visibility
  • Create dashboards, reports, and metrics to provide stakeholders with actionable insights into SaaS security posture and compliance status
  • Assess cloud-connected SaaS environments across AWS, Microsoft Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI)
  • Review identity federation, API connectivity, logging, monitoring, and data protection controls associated with SaaS platforms
  • Partner with cloud security, security operations, governance, and risk management teams to ensure consistent security standards and controls
  • Document findings, risk assessments, remediation recommendations, and security exceptions
  • Contribute to the development of SaaS security standards, governance frameworks, and secure-by-design practices
  • Support emerging technology initiatives, including AI and Generative AI-enabled SaaS platforms, through security assessments and risk evaluations

Requirements

  • 5+ years of experience in Security Engineering, Cloud Security, SaaS Security, or related cybersecurity disciplines
  • Hands-on experience implementing and managing one or more SaaS Security Posture Management (SSPM) solutions, including: AppOmni, Obsidian, Palo Alto SaaS Security solutions, Adaptive Shield, Wing Security, Valence, or similar SSPM technologies
  • Strong understanding of: SaaS Security Architecture, Identity & Access Management (IAM), Data Protection & Privacy Controls, API Security, Security Monitoring & Detection, SaaS Governance & Risk Management
  • Experience securing and assessing SaaS environments integrated with AWS, Azure, GCP, and/or OCI
  • Proficiency with: Python, PowerShell, REST APIs, Terraform, GitHub, Security Automation Frameworks
  • Experience integrating security tools and building automated workflows across enterprise environments
  • Strong analytical, troubleshooting, documentation, and communication skills
  • Ability to work effectively with technical and business stakeholders in complex enterprise environments

Nice to have

  • Experience implementing CASB solutions and SaaS governance programs
  • Knowledge of SaaS application onboarding, certification, and vendor risk management processes
  • Familiarity with AI and Generative AI security risks within SaaS platforms
  • Experience with cloud-native security controls and enterprise cloud security frameworks
  • Understanding of compliance frameworks and security standards such as NIST, ISO 27001, CIS Controls, and CSA Cloud Controls Matrix
  • Experience supporting large-scale SaaS environments with complex integration ecosystems

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

SaaS Security Engineer (SSPM)

8 matching positions

Information Security Engineer

We are seeking a Information Security Engineer to serve as a technical leader in...
Location
Location
Salary
Salary:
Not provided
deel.com Logo
Deel
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years of experience in cybersecurity
  • Handson experience with security tools like EDR, SWG, CASB, ZTNA, SSPM and DLP
  • Experience managing technical vulnerability of OS and applications for endpoints using tools like CrowdStrike Spotlight, InsightVM, Tenable, Qualys.
  • Familiarity with cybersecurity frameworks and best practices, such as MITRE, NIST, CIS, ISO27001, SOC and others.
  • Experience in collaborating with internal stakeholders to rollout enterprise security solutions.
  • Understanding and having the ability to utilize Cloud platforms such as AWS, GCP, Azure to host security tooling.
  • Excellent English in both verbal and written.
Job Responsibility
Job Responsibility
  • Act as the Subject Matter Expert (SME) for Endpoint Detection and Response (EDR) tools/process including optimizing configurations/policies, developing custom threat detection rules, and proactively improving Deel’s overall security posture for remote endpoints (Mac and Windows) and cloud assets (Eg, VMs).
  • Configure, manage, and tune the full suite of security policies within SWG, CASB and ZTNA. Assist our remote colleague with seamless experience through troubleshooting end user issues as needed.
  • Continuously improve SaaS security posture with SSPM tools and processes around it. Collaborate with diverse application owners, understand security control and resolve configuration drifts for our wide range of SaaS applications from baseline.
  • Develop a rigorous review, approval, policy enforcement and auditing for browser extensions, third party OAuth applications for SaaS applications such as Google Workspace, GitHub, Jira etc to meet security and privacy standards.
  • Design, implement, and audit security policies related to enterprise browsers (Eg, Island, Chrome Enterprise etc) including controlling access to sensitive web apps, and data loss prevention (DLP) configuration, ZTNA, secure web browsing experience but not limited to.
  • implement and manage DLP policies across Endpoint, Network, SaaS Applications and Cloud assets, directly supporting the 'Crawl-Walk-Run' program phases. Ensure DLP policies meet diverse data sovereignty, privacy (GDPR, CCPA, etc.), and national regulatory requirements.
  • Run vulnerability management programs for endpoints and servers and ensure they are patched according to the policy in collaboration with stakeholders.
What we offer
What we offer
  • Stock grant opportunities dependent on your role, employment status and location
  • Additional perks and benefits based on your employment status and country
  • The flexibility of remote work, including optional WeWork access
  • Fulltime
Read More
Arrow Right

Senior Corporate Security Engineer

At Crusoe, the Corporate Security Engineer is essential for safeguarding our emp...
Location
Location
United States , San Francisco; Sunnyvale
Salary
Salary:
130000.00 - 170000.00 USD / Year
crusoe.ai Logo
Crusoe
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 6-8+ years of hands-on experience in a Corporate Security, Enterprise Security, or similar role
  • Proven experience designing, implementing, and managing security technologies at scale, including: MDM solutions (e.g., Intune, Kandji, Jamf, etc.), IAM solutions (e.g., Okta, Azure AD, IGA applications, etc. including SSO, MFA, PAM concepts), Endpoint security tools (EDR/XDR), Email threat protection solutions, DLP and/or SSPM solutions
  • Strong understanding of modern security principles, including Zero Trust architecture, "secure by design," and defense-in-depth
  • Experience with securing SaaS applications and enforcing security policies
  • Demonstrated experience in security incident response, including triage, investigation, and remediation
  • Familiarity with scripting languages (e.g., Python, PowerShell) for automation and integration
  • Excellent problem-solving, analytical, and critical-thinking skills
  • Strong communication and collaboration skills, with the ability to work effectively across different teams
  • Embody the Company values
Job Responsibility
Job Responsibility
  • MDM Administration & Endpoint Security: Implementing, administering, and optimizing Mobile Device Management (MDM) solutions and enforcing security policies across diverse endpoints (laptops, mobile devices)
  • Hardware & Software Security Standards: Establishing and maintaining hardware/software security standards and ensuring the strong security posture of corporate devices
  • Identity & Access Management (IAM): Designing, implementing, and managing core Identity & Access Management (IAM) technologies, including SSO, MFA, PAM, and identity lifecycle solutions, contributing to our Zero Trust architecture
  • Data Protection & Email Security: Implementing, configuring, and tuning Data Loss Prevention (DLP), SaaS Security Posture Management (SSPM), and email security solutions to protect against various threats
  • Secure Architecture & Technology Evaluation: Designing secure corporate environments using "secure by design" principles and evaluating the security posture of new technologies, vendors, and applications
  • Security Operations & Incident Response: Actively participating in corporate security operations, including monitoring security alerts, detecting, triaging, investigating, and responding effectively to security incidents
  • Security Consulting & Best Practices: Consulting with and advising IT, Engineering, and other teams on secure architecture, IAM best practices, and secure configurations
What we offer
What we offer
  • Restricted Stock Units in a fast growing, well-funded technology company
  • Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
  • Employer contributions to HSA accounts
  • Paid Parental Leave
  • Paid life insurance, short-term and long-term disability
  • Teladoc
  • 401(k) with a 100% match up to 4% of salary
  • Generous paid time off and holiday schedule
  • Cell phone reimbursement
  • Tuition reimbursement
  • Fulltime
Read More
Arrow Right

Senior/Staff Enterprise Security Engineer

We're looking for a very experienced and highly motivated Senior or Staff Enterp...
Location
Location
United States , San Francisco; New York
Salary
Salary:
214200.00 - 252000.00 USD / Year
abridge.com Logo
Abridge
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5 to 7+ years of progressive experience in an Enterprise/Corporate Security Engineering role
  • Proven hands-on experience developing security automation solutions with Python or similar high-level languages
  • Expert-level knowledge of IAM concepts, protocols (SAML, OAuth), and hands-on experience with at least IAM in Google Workspace
  • Strong experience deploying and managing modern Endpoint Protection (EDR) and MDM solutions in a large corporate environment
  • Deep understanding of networking and security protocols (TCP/IP, DNS, TLS/SSL, VPN, Firewalls) and how to secure hybrid environments
  • Demonstrated ability to lead complex projects, mentor junior staff, and communicate security risks and solutions effectively to both technical and non-technical stakeholders
Job Responsibility
Job Responsibility
  • Architect and implement enterprise-wide Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions
  • Own the implementation and maintenance of authentication standards, including Single Sign-On (SSO), phishing resistant Multi-Factor Authentication (MFA), and identity federation protocols (SAML, OIDC, OAuth2)
  • Design and enforce security policies for critical SaaS applications using tools like SSPM (SaaS Security Posture Management)
  • Develop and automate the full identity lifecycle (joiner, mover, leaver) process
  • Lead the development of the security automation roadmap for Enterprise Security
  • Design and build custom automation scripts and integrations using languages like Python to connect security tools (SIEM, EDR, IAM, Ticketing)
  • Utilize Infrastructure as Code (IaC) tools (e.g., Terraform) to manage the secure configuration of enterprise tools and enforce security policies at scale
  • Engineer, deploy, and manage our Endpoint Detection and Response (EDR) and Mobile Device Management (MDM) platforms
  • Design, configure, and maintain enterprise network security controls, including next-generation firewalls, secure web gateways, VPNs, and micro-segmentation strategies
  • Own and optimize the email security stack, DMARC/DKIM/SPF enforcement, and anti-phishing controls
What we offer
What we offer
  • Generous Time Off: 14 paid holidays, flexible PTO for salaried employees, and accrued time off for hourly employees
  • Comprehensive Health Plans: Medical, Dental, and Vision coverage for all full-time employees and their families
  • Generous HSA Contribution: If you choose a High Deductible Health Plan, Abridge makes monthly contributions to your HSA
  • Paid Parental Leave: Generous paid parental leave for all full-time employees
  • Family Forming Benefits: Resources and financial support to help you build your family
  • 401(k) Matching: Contribution matching to help invest in your future
  • Personal Device Allowance: Tax free funds for personal device usage
  • Pre-tax Benefits: Access to Flexible Spending Accounts (FSA) and Commuter Benefits
  • Lifestyle Wallet: Monthly contributions for fitness, professional development, coworking, and more
  • Mental Health Support: Dedicated access to therapy and coaching to help you reach your goals
  • Fulltime
Read More
Arrow Right

Cloud Security Senior Cyber Security Analyst

For this activity, we are looking for a Senior Cloud & On-Premises Infrastructur...
Location
Location
India , Bengaluru
Salary
Salary:
Not provided
https://www.soprasteria.com Logo
Sopra Steria
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 4+ years of experience designing and delivering complex cloud and on-premises infrastructures
  • Strong knowledge of security tools such as SSPM, DSPM, or CNAPP
  • Ability to write clear and structured technical documentation
  • Strong knowledge of SaaS environments (Google Workspace, ServiceNow, Workday, Salesforce)
  • Proven experience onboarding solutions in hybrid environments (cloud and on-premises)
  • Knowledge of security frameworks such as NIST, CIS, MITRE ATT&CK, and MITRE D3FEND
  • Knowledge of the CrowdStrike Falcon® Shield solution (formerly Adaptive Shield)
  • Strong expertise in cloud architecture (networking, compute, identity, storage, governance)
  • Cloud Certifications - Google, AWS / Azure
  • Engineering Graduate - preferably B.E. /B.Tech in IT or Computer Engineering
Job Responsibility
Job Responsibility
  • Configure the SSPM solution (SaaS)
  • Create a simple SSPM training material
  • Onboarding 4 SaaS applications = Google Workspace, ServiceNow, Workday, Salesforce on the SSPM
  • Define the SaaS hardening baseline
  • Configure the SSPM alerts
  • Produce a detailed SSPM training manual aligned with the customer environment
  • Collaborate with the customer SaaS team to integrate SaaS applications into the SSPM tool, ensuring security rules are correctly implemented
  • Collaborate with the customer SaaS team to configure alerts within the SSPM solution
  • Fulltime
Read More
Arrow Right

SecOps Engineer

The SecOps Engineer manages and leads the resolution of high or critical severit...
Location
Location
United States , Milwaukee; Boston; Paramus
Salary
Salary:
135000.00 - 150000.00 USD / Year
veolianorthamerica.com Logo
Veolia
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s or Master’s Degree in Computer Science, Engineering, Information Security or extensive professional experience considered in place of a Bachelor’s degree
  • Min of 5 years of professional experience in SOC operations and/or incident response
  • Understanding of technologies and solutions utilized in cybersecurity and networks (SIEM, SOAR, Firewalls, IAM, IDS/IPS, End Point Protection, Threat Management/Intelligence)
  • Expertise in Cloud security such as AWS, GuardDuty, CloudTrail, Lambda, GCP, GCP Cloud Audit, Cloud Security Command Center, Log Explorer, GKE Logs, Kubernetes
  • Understanding of API security: REST, SOAP, OAuth, API Keys/Tokens, API Gateway
  • SaaS: SSPM, CASB
  • Familiarity with security frameworks, standards, and guidelines
  • Knowledge of current hacking techniques, vulnerability disclosures, data breach incidents, and security analysis techniques
  • Ability to work with complex problems where analysis of situations or data requires an in-depth evaluation of variable factors
  • Excellent troubleshooting and problem-solving skills
Job Responsibility
Job Responsibility
  • Work closely with and advise on security best practices for Cloud, Infrastructure, Developers and Data Analysts to ensure security is implemented by design
  • Design and implement technical security controls
  • Conduct security review/audit of Cloud, SaaS, Network, AI environments to identify and mitigate potential security risks
  • Develop and implement security automation workflows using scripting languages and/or automation tooling such as Torq, Tines, etc
  • Provide seniority and oversight for a SOC shift as needed
  • Conduct complex investigations and providing advice to other Security Analysts
  • Manage and lead High or Critical severity incident resolution
  • Develop customized scripts or procedures to automate the repetitive tasks and improve the efficiency of incident response activities
  • Provide expert advice on remediation and recovery efforts and develop threat remediation strategies
  • Perform proactive analysis of the attack surface and advising on potential threats and attack vectors
What we offer
What we offer
  • Paid time off policies
  • health, dental, vision, life insurance
  • savings accounts
  • tuition reimbursement
  • paid volunteering
  • employer sponsored 401(k) plan
  • Sick leave – 56 hours
  • Observed Holidays – 11 days
  • Vacation – Flexible Time Off
  • Eligible for up to 10% Annual Performance Bonus
  • Fulltime
Read More
Arrow Right

Head of cyber threat exposure and attack surface management

Lead the enterprise-wide Continuous Threat Exposure Management (CTEM) strategy, ...
Location
Location
United Kingdom , Knutsford
Salary
Salary:
Not provided
barclays.co.uk Logo
Barclays
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Experience in cybersecurity with direct exposure to vulnerability management, red teaming, or threat exposure reduction
  • Proven track record leading programs integrating CSPM, SSPM, ASM, BAS, or exposure correlation technologies
  • Strong understanding of attack paths, adversary emulation, and continuous validation concepts
Job Responsibility
Job Responsibility
  • Own and drive the global CTEM strategy, establishing a continuous, threat-driven exposure management lifecycle aligned with NIST, MITRE, and CISA Secure-by-Design principles
  • Lead and develop a high-performing CTEM team, fostering collaboration, technical excellence, and an outcome-driven culture
  • Integrate and oversee key exposure management technologies, including Cloud Security Posture Management (CSPM), SaaS Security Posture Management (SSPM), Attack Surface Management (ASM), Breach & Attack Simulation (BAS), and other exposure correlation platforms
  • Correlate assets, identity, vulnerability, and configuration to identify high-impact, exploitable attack paths and inform prioritized remediation strategies
  • Collaborate with Application Security, Vulnerability Management, Red Team, and Security Operations to synchronize discovery, validation, and remediation of exposures across the enterprise
  • Align CTEM outputs with real-world adversary behaviors, leveraging Red Team and Threat Intelligence input to validate attack paths and focus on exploitable conditions
  • Drive automation and AI-enabled analytics to continuously map, assess, and measure reductions in the organization’s attack surface
  • Translate technical findings into business risk language, enabling senior leadership and risk committees to make data-driven investment decisions
  • Define and lead CTEM governance and operating models, ensuring exposure assessments, validation, and remediation tracking are embedded in operational processes
  • Establish clear KRIs and maturity metrics that demonstrate continuous improvement in visibility, validation, and response effectiveness
What we offer
What we offer
  • Competitive holiday allowance
  • Life assurance
  • Private medical care
  • Pension contribution
  • Fulltime
Read More
Arrow Right
New

IT Training Lead

The IT Training Lead will drive technology learning and user adoption across the...
Location
Location
United States , Delray Beach
Salary
Salary:
Not provided
https://www.roberthalf.com Logo
Robert Half
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Experience in IT training, instructional design, technical enablement, or learning and development
  • Strong knowledge of Microsoft 365
  • Excellent communication, facilitation, and content development skills
  • Ability to translate technical concepts into practical, user-friendly training.
Job Responsibility
Job Responsibility
  • Design, develop, and deliver IT training programs in instructor-led, virtual, and self-paced formats
  • Take lead in the Microsoft Copilot and AI training strategy, including onboarding, advanced use cases, responsible AI usage, and ongoing enablement
  • Partner with IT leadership to support new technology rollouts, system upgrades, and digital transformation initiatives
  • Create and maintain training content, including videos, guides, tutorials, and job aids
  • Identify skill gaps and develop targeted learning solutions to improve adoption and productivity
  • Gather feedback and measure training effectiveness to continuously improve programs.
Read More
Arrow Right
New

K Kitchen Representative

The position includes, but is not limited to, the following essential job duties...
Location
Location
United States , New Albany
Salary
Salary:
Not provided
https://www.circlek.com Logo
Circle K
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Excellent communication skills
  • Team player who can work well with others or independently
  • Acts with integrity
  • keeps commitments
  • Contagious positive attitude
  • Focuses on achieving results while having fun
  • Frequently bend, twist at waist, kneel, squat, stand, and walk
  • Occasionally climb and descend ladders
  • Tolerate extreme cold and hot temperatures and work in and around fryers, ovens, grills, coolers, freezers, sharp objects, and loud noises
  • Reach, grasp, and manipulate objects with hands for entire shift, including reaching for objects overhead
Job Responsibility
Job Responsibility
  • Provides excellent guest service in a fast and friendly manner
  • Maintains a clean restaurant environment by cleaning and performing general housekeeping duties
  • Prepares and serves food items in accordance with all Brand, Company, and health department regulations
  • Ensures product quality, food safety, and operational standards are met
  • Keeps accurate cash, sales, and inventory control records
  • Follows all government laws and safety codes
  • Completes reports on all incidents following our 5-minute rule policy
  • Lives our Company values: One Team, Do the Right Thing, Takes Ownership, Play to Win
What we offer
What we offer
  • Medical, Dental, Vision, Term Life and AD&D plans
  • Flexible spending and health savings accounts (FT)
  • Vacation paid time off
  • Company holidays paid at time and a half
  • Matching 401(k)
  • Tuition Reimbursement
  • Stock Purchase Plan
  • Employee Discount Program
  • Discount Meal Benefit
  • Wellness Plan
Read More
Arrow Right