BrightEdge
Website:
brightedge.com
Job details:
About BrightEdge
BrightEdge is a leading enterprise SEO and content performance platform that helps companies understand how their digital content drives real business results. Founded in 2007, we’re trusted by thousands of organizations across more than 80 countries, including brands like Microsoft and Visa. Our platform combines powerful data and AI-driven insights allowing our customers to plan, optimize, and measure campaigns based on real-time content performance.
About the Role
We are looking for an experienced and driven Security Engineer to join our Information Security team. In this role, you will plan, design, develop, test, and manage security tools and controls that protect and provide visibility across our cloud-based SaaS environments. You will be a key technical contributor ensuring our platform remains resilient, compliant, and trusted by customers worldwide.
This role is highly technical and requires a strong command of security principles applied to production SaaS environments. You will help evolve our cloud security posture using proactive, preventive-focused models that address modern threats — including those driven by AI-enabled attack techniques — while directly supporting our mission to deliver a secure, reliable SaaS product.
Security Architecture & Strategy
- Architect and secure multi-tenant SaaS infrastructure, ensuring robust tenant isolation, data residency controls, and per-customer security boundaries
- Lead the design and implementation of preventative security controls leveraging automation and AI-driven capabilities to reduce risk and improve detection and response
- Establish and evolve DevSecOps and Infrastructure-as-Code (IaC) security standards, integrating security controls into CI/CD pipelines
SaaS & Customer Data Protection
- Design and enforce security controls for SaaS-specific concerns including multi-tenancy, data segregation, API security, and identity federation (SSO, SAML, OIDC, OAuth 2.0)
- Define data security and privacy controls to meet SaaS compliance requirements (SOC 2, ISO 27001, GDPR, CCPA) and support customer trust and audit readiness
- Establish security architecture for customer-facing APIs and integrations, including third-party SaaS connectors, webhooks, and marketplace integrations
Application Security & Emerging Threats
- Identify and establish controls to mitigate cybersecurity risks
- Apply frameworks such as OWASP Top 10
- Expand security capabilities into next-generation domains such as AI/ML security, container security, and advanced threat detection and response
Container & Runtime Security
- Define and implement security architecture for containerized SaaS workloads (Kubernetes/EKS/GKE/AKS), including cluster hardening, workload isolation, image supply chain security, and runtime protection
- Regularly audit and optimize internal DevOps processes to improve risk visibility and remediation across cloud, container, and SaaS environments
- Lead evolution of cloud detection and response capabilities, integrating cloud telemetry, and advanced security analytics
Security Operations & Engineering
- Architect and deliver automation frameworks and security services to improve scalability and operational efficiency across the security program
- Maintain and monitor security operation infrastructure (task tracking system, IDS/IPS, SIEM, SAST, agentic MCP Servers used in security automation, etc) to ensure information security processes are protected from outage and security breach
- Conduct and guide threat modeling and attack surface management for complex cloud-native and SaaS systems
- Lead the implementation of vulnerability management and patch cadence processes aligned with SaaS release cycles
- Influence security and engineering practices across multiple teams, driving adoption of secure-by-design principles
Technical Leadership
- Provide technical mentorship to engineers and guide security-oriented thinking across product and infrastructure teams
- Train and mentor junior security staff
- Own security outcomes of key cloud and SaaS initiatives, ensuring successful delivery and measurable risk reduction
- Collaborate with Product, Compliance, and Customer Success to address enterprise customer security requirements and questionnaires
- Conduct security team presentation during company meetings and new hire training
Core Requirements
- Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Security, or related field (or equivalent experience)
- 5-6 years of relevant professional experience
- Proven experience designing and securing large-scale cloud architectures in SaaS or cloud-native product environments (AWS, Azure, GCP)
- Deep expertise in cloud security architecture including IAM, network segmentation, encryption, secrets management, and secure design patterns, with hands-on experience designing and operating enterprise IAM solutions (e.g., Okta, Azure AD/Entra ID, Ping Identity, AWS IAM Identity Center) covering authentication, authorization, role-based access control (RBAC), and privileged access management (PAM)
- Strong programming and automation skills with the ability to design and scale security engineering solutions, such as Ansible and Terraform, including hands-on DevOps experience automating SaaS infrastructure provisioning, configuration management, and operational workflows
- Extensive experience implementing DevSecOps practices and securing Infrastructure-as-Code (IaC) workflows
- Proven DevOps experience operating production SaaS environments, including building and maintaining CI/CD pipelines, configuration management with Ansible (or equivalent automation tools such as Chef), and Infrastructure-as-Code provisioning with Terraform
- Experience with container technologies (Kubernetes, Docker, GKE) and related security tooling
- Experience leading implementation and adoption of SIEM, SAST, DAST, IDS/IPS
- Strong background in security prevention, detection, and response strategy for SaaS environments
- Excellent communication skills with the ability to translate security risks for technical and non-technical stakeholders
SaaS & Compliance Experience
- Hands-on experience securing multi-tenant SaaS architectures and understanding of SaaS-specific attack surfaces
- Familiarity with SaaS compliance frameworks: SOC 2 Type II, ISO 27001, ISO 27701, GDPR, CCPA, NIST CSF, or similar
- Experience with identity federation standards (SAML, OAuth 2.0, OIDC, SCIM) and enterprise SSO integration security, including identity lifecycle management, MFA enforcement, conditional access policies, and just-in-time (JIT) access provisioning for SaaS workforce and customer identities
- Understanding of SaaS operational security practices: secret rotation, least-privilege access, customer data handling policies
Application Security & AI
- Deep understanding of OWASP Top 10 vulnerabilities
- Experience performing penetration testing – application and network
- Experience securing LLM integrations
Additional
- Experience designing highly scalable, resilient, and secure architectures across application, network, and data layers
- Relevant certifications preferred (e.g., ISC2 CISSP, AWS/GCP security specialty)
- Experience working across multi-OS and distributed environments
**This is a Remote based position in India**
Click on Apply to know more.