{"id":1694717,"url":"https://alion.io/job/interactive-brokers-security-engineer-iii-saas","title":"Security Engineer III - SAAS","company":{"id":58627,"name":"Interactive Brokers","domain":"interactivebrokers.com","url":"https://alion.io/company/interactive-brokers","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Dayforce","truth_index":{"grade":"B","score":75,"open_postings":50,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-04T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Mumbai, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":14000,"max_usd":35000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":414},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"GCP","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Kubernetes","optional":false},{"name":"LDAP","optional":false},{"name":"NIST CSF","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Platform Engineering","optional":false},{"name":"STRIDE","optional":false},{"name":"Threat Modeling","optional":false},{"name":"LLM","optional":true},{"name":"Shift-Left","optional":true},{"name":"Shift-Left Security","optional":true},{"name":"Terraform","optional":true}],"status":"live","first_seen_at":"2026-08-25T00:30:00Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-04T23:48:48Z","board_verified":true,"closed_at":null,"days_open":40,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":40},"description":"Role Overview\nThe Security Engineer III – SaaS Security leads structured threat modeling across the firm's SaaS applications, cloud-native platforms, APIs, and third-party SaaS integrations to identify design level risk before it reaches production. This is a hands on, technical contributor role for someone who thinks like an adversary, understands modern multi-tenant SaaS and cloud architecture deeply, and can turn complex technical exposure into clear, prioritized, business-relevant risk. You will partner closely with product and platform engineering to drive secure-by-design outcomes across high-risk systems such as trading platforms, client portals, and the APIs and integrations that connect them.\nKey Responsibilities\nEnd to End Threat Modeling (core focus)\nLead threat modeling across the full deployment gamut of SaaS, cloud native, on premise, hybrid, and third-party systems, including applications, infrastructure, microservices, monoliths, APIs, network architecture, and data flows, using methodologies such as STRIDE, PASTA, or attack trees, supported by data flow diagrams (DFDs).\nMap attack surface, trust boundaries, and abuse cases across cloud, data center, network, and endpoint layers, drawing on threat knowledge bases (MITRE ATT&CK including Enterprise, Cloud/SaaS, ICS, and Containers matrices, CAPEC, OWASP Top 10 and API Security Top 10).\nModel environment specific risk across the ecosystem, including:\nSaaS and multi-tenant: tenant isolation, data segregation, token and secrets management, and API authorization (e.g., BOLA/IDOR, broken function level authorization).\nIdentity and access: authentication and federation flows (OAuth 2.0 / OIDC, SAML/SSO, SCIM provisioning, Kerberos/Active Directory, LDAP), privileged access, and lateral movement paths.\nCloud native (AWS, Azure, GCP): IAM and over permissioned roles, exposed storage, containers/Kubernetes, serverless, and infrastructure as code, within the relevant shared responsibility model.\nOn premise and hybrid: data center and network segmentation, east west traffic, legacy and end of life systems, physical and virtualized infrastructure, on premise to cloud connectivity, and the trust boundaries between them.\nTranslate technical findings into documented, prioritized business risk exposure with clear risk ratings, irrespective of where a system is hosted or how it is deployed.\nSecure by Design and Engineering Partnership\nEmbed threat modeling into the SDLC and architecture lifecycle, and shift security left into design and architecture reviews for new builds, migrations, and modernization of existing on-premises estates.\nPartner with product, platform, and infrastructure engineering to recommend mitigations, secure design patterns, and reference architectures across cloud and on-premises environments.\nBuild and maintain reusable threat model libraries, templates, and security patterns to scale coverage across diverse deployment models.\nSupport adoption of threat modeling tooling and threat modeling as code and validate that recommended controls are implemented.\nIntegration, Supply Chain, and Ecosystem Risk\nThreat model integrations across the ecosystem, including third party SaaS, on premise and vendor systems, data flows, authentication, API exposure, webhook and OAuth scope risk, and supply chain and system to system paths (SaaS to SaaS, cloud to on premise, and B2B connectivity).\nEvaluate vendor and partner architectures where they intersect the firm's threat models and trust boundaries.\nRisk Communication & Governance\nProduce high-quality threat models and recommendations and tailor communication for both technical and non-technical audiences.\nBrief leadership with concise, decision ready risk insights, and escalate high risk design flaws with context and recommended actions.\nAlign threat models with enterprise frameworks (NIST CSF, ISO 27001, CSA Cloud Controls Matrix) and applicable financial services obligations (e.g., DORA, NYDFS 500, RBI guidance).\nTrack and report key risk indicators such as threat model coverage across the estate and finding closure rates.\nRequired Qualifications\nTypically, 5 to 8 years in cybersecurity (or equivalent demonstrated depth) with a focus on threat modeling, application/product security, or security architecture across cloud, SaaS, and on-premise environments.\nDemonstrated, hands on threat modeling of modern and traditional systems using a structured methodology (e.g., STRIDE, PASTA) with DFDs.\nStrong understanding of both cloud native and on-premise architectures: multi tenancy, APIs, microservices, network and infrastructure design, and identity/authentication flows (OAuth/OIDC, SAML/SSO, Active Directory/Kerberos).\nWorking knowledge of AWS, Azure, or GCP and their shared responsibility models, plus familiarity with data centers, networks, and hybrid infrastructure security.\nFamiliarity with OWASP (Top 10 and API Security Top 10) and MITRE ATT&CK / CAPEC.\nAbility to translate technical risk into clear business terms, with strong written and verbal communication.\nBachelor's degree in a related field or equivalent practical experience.\nPreferred Qualifications\nExperience in financial services or another regulated industry (e.g., DORA, NYDFS 500, RBI guidelines).\nHands-on with threat-modeling tooling / threat-modeling-as-code (e.g., IriusRisk, OWASP Threat Dragon, Microsoft Threat Modeling Tool, ThreatModeler).\nExperience with DevSecOps, secure SDLC, infrastructure-as-code (Terraform), containers/Kubernetes, or secure code review.\nExposure to AI/ML or LLM application threat modeling and other emerging technology risks.\nCertifications such as CSSLP, CCSP, CISSP, or a cloud-security specialty (e.g., AWS Certified Security – Specialty, Azure Security Engineer).\nCore Competencies\nAdversarial and systems thinking.\nDeep technical understanding of cloud, SaaS, and on-premise architecture across the ecosystem.\nSecure by design, shift left mindset.\nClear communication across technical and business audiences.\nStrong collaboration with engineering, platform, and infrastructure teams.\nOwnership and accountability for deliverables.\nCompany Benefits & Perks:\n• Competitive salary package.• Performance based annual bonus (cash and stocks).• Group Medical & Life Insurance.• Modern offices with free amenities & fully stocked cafeterias.• Monthly food card & company paid snacks.• Hardship/shift allowance with company provided pickup & drop facility*• Attractive employee referral bonus.• Frequent company sponsored team building events and outings.* Depending upon the shifts.\n **The benefits package is subject to change at the management's discretion.","description_format":"text","description_chars":6656,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":["Cafeteria","Life insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Software","Financial Services"],"lifecycle":[{"event":"open","at":"2026-10-02T11:57:18Z"}],"visa":[],"liveness":{"score":16,"band":"cold","label":"Long shot","p_open":1,"p_active":0.435,"p_room":0.36,"age_days":40,"expected_fill_days":25,"reasons":["conf:0","stale_co","velocity","win:tail","crowd:brand"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/interactive-brokers-security-engineer-iii-saas","json_url":"https://alion.io/job/interactive-brokers-security-engineer-iii-saas.json","meta":{"generated_at":"2026-10-05T00:10:53Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":89,"day_limit":5000,"remaining_today":4911,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}