Lead incident investigations across SaaS platforms including Okta, Google Workspace, Slack, Box as well as Cloud Computing & Infrastructure platforms such as GCP and AWS.
Design and implement automated security workflows in Okta (e.g., contextual access, dynamic MFA, threat response automation).
Design, implement and deploy SIEM tooling and develop detection rules/playbooks.
Maintain and execute User Access Reviews (UARs), vulnerability scans & remediations, and threat response.
Perform red teaming exercises and annual penetration testing campaigns.
Configure, test, and optimize endpoint, browser, and SaaS security controls.
Collaborate with DevOps and Engineering to ensure secrets and API keys are securely managed.
Monitor and triage alerts from EDR, DLP, and code scanning systems.
Participate in security awareness programs and phishing simulations.
Assist with compliance audits and security documentation including Business Continuity, DR/backup policies.
Requirements
Deep understanding of authentication protocols (SAML, OIDC, OAuth, Kerberos).
Experience with SIEM platforms and detection engineering (rule creation, log correlation).
Strong automation experience with Okta Workflows, scripting (Python/Bash), and APIs.
Familiarity with endpoint protection, browser session security, and DLP tools.
Ability to perform and lead internal red team assessments and penetration testing.
Deep understanding of CI/CD pipelines and secure development knowledge (secrets management, hardcoded credential detection etc..).
Strong documentation and cross-team collaboration skills.
Benefits
Unlimited Vacation
Paid Sick Days & Holidays
100% Employee Covered Medical, Dental, Vision Plan Base Plan
Life Insurance
401k
Flexible Spending Accounts
Commuter Benefits & More
Catered Lunches & Well-stocked Kitchens
Yoga & Wellness Activities
Happy Hours
Company Events
Dog Friendly
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.