We are hiring an experienced and technically hands-on Information Security Analyst with expertise in securing SaaS (Software as a Service) Cloud Platforms to play a pivotal role in safeguarding our SaaS offerings hosted on cloud infrastructure. Your responsibilities will include implementing security measures, conducting hands-on technical assessments.
Job responsibilities will include:
• Implement and maintain security measures to safeguard our SaaS Cloud Platform on popular cloud providers such as AWS, Azure, or Google Cloud.
• Conduct regular security assessments and audits to identify vulnerabilities and ensure compliance with industry standards.
• Perform hands-on penetration testing, vulnerability assessments, and security reviews of the SaaS Cloud Platform.
• Develop and implement incident response plans specific to the SaaS Cloud Platform environment.
• Utilize security tools and technologies to detect and respond to security incidents in real-time.
• Implement and manage security automation tools to enhance the efficiency of security processes.
• Security Policy Development:
• Contribute to the development and maintenance of security policies, standards, and procedures specific to a SaaS Cloud environment.
• Ensure alignment with regulatory requirements and industry best practices.
Key skills and qualifications required:
• Must have Bachelor's or Master's degree in Cybersecurity, Information Security, or a related field.
• Must have proven experience (5+ years) as an Information Security Analyst, with a focus on securing SaaS Cloud Platforms.
• Technical proficiency in conducting penetration testing, vulnerability assessments, and security reviews.
• In-depth knowledge of cloud security principles and best practices on platforms such as AWS, Azure, or Google Cloud.
• Experience with security automation tools and scripting languages.
• Familiarity with regulatory requirements relevant to SaaS and cloud environments.
Technical Skills required:
• Cloud Security: AWS, Azure, Google Cloud
• Penetration Testing Tools (e.g., Metasploit, Burp Suite)
• Security Automation (e.g., Ansible, Terraform)
• Intrusion Detection and Prevention Systems (IDPS)
• Security Information and Event Management (SIEM) tools
• Secure Coding Practices
• Network Security Protocols and Technologies
• Application Security Principles
• Incident Response Platforms