Information Security Engineer- Software as a Service

RESOURCEFUL ENVIRONMENTAL SERVICES, INC.
Chicago, IL, United States
about 1 month ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$112,710.0 - $183,140.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) Microsoft Windows Artificial Intelligence Amazon Web Services Data Analysis Apple Mac Systems Asana Microsoft Azure Cisco IOS Software as a Service Cloud Computing Security Cyber Security
+19 more
Computer Programming Linux Disaster Recovery Identity and Access Management Intrusion Detection and Prevention Information Systems Security Architecture Professional PCI Data Security Standards Power BI Virtualization Technology Software Vulnerability Management Cloud Platform System Okta Microsoft Power Automate Prompt Engineering Generative AI Cyber Threat Analysis Information Technology Devsecops Workday

Job description

Serve on a team of Cybersecurity Engineers responsible for supporting the organization’s vulnerability and threat management programs (e.g., vulnerability management, threat intelligence, application security testing, and attack surface management). This role focuses on Software as a Service (SaaS) vulnerability management, under the direction of the Vulnerability and Threat Program Manager and collaborates with IT, Cybersecurity, and Technical Stakeholder teams to maximize the security of applications and data. The ideal candidate will have a strong technical background in cybersecurity, hands-on experience with vulnerability management tools, collaborative approach to problem-solving, and ability to communicate clearly and concisely. Job Responsibilities:

  • Conduct continuous identification and assessment of SaaS exposures, to include misconfigurations, permission sprawl, insecure integrations, and identity centric risks across enterprise SaaS platforms.
  • Analyze security findings and provider advisories to identify and prioritize corrective action(s) based on exposure, exploitability, and business criticality.
  • Document and track SaaS security risks, remediation actions, and posture trends using automated risk registers, POA&Ms, and exception requests. Generate and brief technical and executive level reports aligned to applicable regulatory and audit requirements.
  • Develop, implement, and sustain security configuration baselines and hardening standards, mapped to organizationally mandated frameworks ( CIS, NIST CSF, etc.).
  • Partner with SaaS application owners and identity, GRC, and enterprise teams to coordinate remediation of customer controlled SaaS risks.
  • Plan and execute SaaS security posture assessments to measure connected application compliance and alignment across the SaaS portfolio.
  • Participate in cross-functional risk and threat modeling activities and provide actionable recommendations for reduction or transference of risk.
  • Develop, implement, and update vulnerability management policies, standards, and TTPs supporting SaaS vulnerability and exposure management processes.
  • Utilize autonomous skills to leverage organizational Artificial Intelligence (AI) tools to effectively and efficiently assess exposure and risk at scale.
  • Liaison with applications teams, business stakeholders, and vendor representatives to review security posture, remediation ownership, compensating controls, and contractual and regulatory compliance.
  • Support and mature proactive cybersecurity strategies to include CTEM, SaaS Attack Surface Management, Identity Threat Detection and Response (ITDR), and zero trust access models.
  • Maintain up-to-date knowledge of emerging threats, vulnerabilities, and cybersecurity best practices.
  • Assist with cybersecurity tool evaluation and implementation, and operation.
  • Participate in organizational and third-party training and workshops to enhance professional knowledge and team performance., * Manage SaaS platforms - specifically Workday, Monday.com, and Epic and Other SaaS platforms
  • These platforms can’t be scanned directly, so a major focus is making sure they’re securely configured through other means
  • Build and maintain vendor relationships - including making the case to vendors on why they need to prioritize this work, since they don’t currently have visibility/access into these systems
  • Support a shift toward continuous threat exposure management (CTEM) - identifying what’s most exposed and where the real risk sits, rather than treating everything as equal priority
  • Discovery work is a big piece of this: building out a repository/inventory of these platforms and figuring out the right order to tackle them
  • Partner with stakeholders to help shift security culture across the org

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).
  • Professional certification as Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP+), GIAC Security Leadership Certification (GSLC), or equivalent.
  • Minimum 5 years of experience in cybersecurity, with at least 3 years focused on vulnerability management, compliance validation, or threat analysis.
  • Experience with multiple operating systems to include Windows, MacOS, Linux, Cisco iOS, etc.
  • Hands-on experience with SSPM, CASB, IAM, or equivalent SaaS vulnerability management tools (e.g., Wiz, Microsoft Defender, Netskope, Entra ID, Okta).
  • Familiarity with prompt engineering and leveraging of AI tools to automate manual processes and supplement data analysis.
  • A strong understanding of networking, infrastructure, application, and information concepts and associated security principles.
  • Experience in risk assessment and mitigation processes, practices, and strategies.
  • Strong analytical, documentation, and communication skills.
  • Ability to lead cybersecurity engineering projects and effectively communicate with business partners.
  • Excellent interpersonal and communications skills, with the ability to work collaboratively in a team environment.
  • Ability to work under pressure and effectively handle multiple responsibilities in a fast-paced and critical heath care environment., * Experience with business efficiency/intelligence tools (e.g., Power BI, Power Automate, Generative AI).
  • Experience with industry cybersecurity frameworks (e.g., CIS, NIST, PCI DSS).
  • Experience with Business Efficiency, Business Intelligence, or Generative AI products.
  • Exposure to incident response and disaster recovery procedures.
  • Exposure to virtualization and cloud platform security (e.g., Azure, AWS).
  • Familiarity with DevSecOps practices and secure software development methodologies

Resource Consultings Services Inc, Minimum qualifications: Bachelor’s degree or equivalent practical experience. 2 years of programming experience in Java. 2 years of experience in coding and system design with …

  • 12 days ago

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all