We are seeking a skilled and proactive Cybersecurity Specialist to lead the security strategy and implementation for our enterprise SaaS application. This role will be responsible for safeguarding our platform, users, and data against current and emerging threats. You will work closely with engineering, DevOps, compliance, and product teams to ensure our application is secure by design and compliant with relevant security standards and regulations.
Key Responsibilities:
· Programming & Automation:
· Develop and maintain security automation scripts, tools, and integrations in languages such as Python, Go, JavaScript, or Bash.
· Create CI/CD security gates using tools like GitHub Actions, GitLab CI, Jenkins, or CircleCI.
· Build custom security testing scripts or utilities to supplement commercial tools.
· Automate compliance evidence gathering, scanning, and reporting.
- DevSecOps Integration:
- Champion security automation and CI/CD pipeline integration for static/dynamic scanning, secrets detection, etc.
- Educate developers on secure coding practices and provide guidance during architecture/design discussions.
- Application Security:
- Lead threat modeling, secure code reviews, and security testing throughout the SDLC.
- Implement and maintain security controls across the SaaS stack (frontend, backend, APIs, and data layer).
- Conduct regular vulnerability assessments and coordinate remediation with development teams.
- Cloud & Infrastructure Security:
- Collaborate with DevOps to ensure secure cloud infrastructure (e.g., IBM Cloud, AWS, GCP).
- Define and enforce security policies for IAM, network segmentation, encryption, and logging.
- Security Monitoring & Incident Response:
- Investigate and respond to security incidents, breaches, and anomalies in real-time.
- Compliance & Governance:
- Ensure the application meets relevant security and privacy standards (e.g., SOC 2, ISO 27001, GDPR, HIPAA).
- Support audits and customer security reviews with documentation and evidence collection.
- 3–5+ years of experience in cybersecurity, with a focus on application and cloud security.
- Strong understanding of web application security principles (e.g., OWASP Top 10, API security).
- Experience securing modern cloud-native SaaS architectures.
- Hands-on experience with tools like SAST/DAST scanners, WAFs, SIEMs, vulnerability management platforms.
- Familiarity with secure development practices and CI/CD security (DevSecOps).
- Knowledge of regulatory and compliance frameworks (SOC 2, ISO 27001, GDPR, etc.).
- Strong scripting or automation skills (e.g., Python, Bash, Terraform, etc.)
- Security certifications such as CISSP, CEH, OSCP, CSSLP, or CCSP.
- Experience working in Agile/Scrum environments.
- Background in penetration testing or red/blue team activities.