> Markdown version of [/jobs/ext/2281065-senior-staff-saas-security-architect](https://www.wearedevelopers.com/jobs/ext/2281065-senior-staff-saas-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Staff SaaS Security Architect - **Company:** State Street - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $202,500.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Cyber Security, Identity and Access Management, Information Security Management, OAuth, OpenID, Openid Connect, Security Assertion Markup Language (SAML), Scripting, Cloud Platform System, Information Technology, Api Design - **Published:** August 28, 2026 - **Apply:** https://www.jofdav.com/jobs/59420087-senior-staff-saas-security-architect ## About the Role * Hands-on experience with SSPM, CASB, SaaS security, or SaaS threat protection platforms such as Obsidian Security. * Strong understanding of SaaS-to-SaaS, identity-to-SaaS, and agent-to-SaaS threats, including account takeover, OAuth abuse, privilege escalation, data exposure, and unauthorized application access. * Experience onboarding enterprise SaaS applications and implementing security controls through APIs, automation, and governance frameworks. * Strong knowledge of OAuth, OpenID Connect (OIDC), SAML/SSO, API permission models, and modern SaaS security architectures. * Strong analytical, problem-solving, automation, and scripting skills., * Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. * 8+ years of experience in information security with a focus on SaaS security, cloud security, identity security, or platform security. * 5+ years of hands-on experience with SSPM, CASB, SaaS threat protection, or related security technologies. * Experience working in financial services or other highly regulated industries preferred. * Relevant cloud or information security certifications (e.g., CISSP, CCSP, AWS/Azure Security) preferred. Additional Requirements * Experience securing enterprise SaaS ecosystems and managing application risk at scale. * Experience working with modern SaaS platforms, APIs, automation frameworks, and cloud-native security technologies. * Knowledge of emerging AI and agentic technologies and their impact on SaaS security is a plus. Work Requirement * Hybrid work model in accordance with company policy. * Ability to collaborate effectively with global teams across multiple time zones. * Standard business hours with flexibility to support critical incidents and deployments when required. ## Description * Lead the deployment, integration, and operationalization of SaaS Security Posture Management (SSPM), SaaS threat protection, and governance capabilities across enterprise SaaS platforms. * Partner with application owners, platform teams, and security stakeholders to onboard SaaS applications, implement security controls, and drive remediation of identified risks. * Design and maintain SaaS security integrations, API-based telemetry collection, and automation workflows to provide continuous visibility into SaaS security posture and threats. * Develop and maintain SaaS security standards, architecture documentation, operational procedures, and implementation guidelines. * Track and report key SaaS security metrics, including application coverage, posture findings, threat exposure, and remediation progress. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)