We can only consider candidates for this position who are able to accommodate a hybrid work schedule and are close to our Atlanta, GA office.Responsibilities:The Application / SaaS Security Engineer is responsible for strengthening the security of internally developed applications and enterprise SaaS platforms across the organization and its product and service lines. This role partners with development, product, platform, and business application teams to assess risk, define security requirements, improve configurations, and support remediation.
An ideal candidate combines hands on application security knowledge with practical SaaS security experience and a collaborative, problem solving approach.
- Design, enhance, test, and implement application and SaaS security controls across enterprise platforms and internally developed solutions.
- Partner with development, product, platform, and SaaS administration teams to integrate security requirements into the software development and application change lifecycles.
- Perform threat modeling and security architecture reviews for applications, APIs, integrations, authentication flows, and sensitive data paths.
- Conduct scheduled and on demand vulnerability assessments using tools such as Rapid7 and Arnica, and coordinate risk based remediation with technical owners.
- Review SaaS security configurations, roles, permissions, integrations, logging, and data protection controls, with emphasis on Salesforce and other critical platforms.
- Support application security testing, including static analysis, dynamic analysis, software composition analysis, secrets detection, and penetration testing.
- Investigate application and SaaS security incidents and recommend corrective actions to reduce the likelihood of recurrence.
- Develop security standards, reusable control patterns, and automated evidence collection for application and SaaS environments.
- Perform special projects as assigned, while effectively managing time with competing priorities.
Knowledge, Skills & Abilities:- Working knowledge of secure software development practices, the OWASP Top 10, threat modeling, API security, and common authentication and authorization patterns
- Hands on experience with vulnerability management or application security testing tools, including Rapid7, Arnica, or comparable platforms
- Experience assessing and securing enterprise SaaS platforms, including identity, permissions, integrations, logging, and sensitive data protection
- Working knowledge of cloud service platforms and CI/CD or DevOps environments, including Azure, GitHub, or comparable technologies
- Strong communication and collaborative skills, with demonstrated ability to work directly with development and application owner teams
Education & Experience:- 7 to 12 years of experience in application security, product security, SaaS security, cybersecurity, or information technology
- BS degree in Cybersecurity, Computer Science, Software Engineering, or equivalent education and experience
- Experience securing Salesforce, including profiles, permission sets, connected applications, APIs, integrations, and event monitoring
- Hands on experience with static analysis, dynamic analysis, software composition analysis, secrets scanning, and penetration testing tools
- Experience with SaaS security posture management, cloud access security broker technologies, or CrowdStrike Falcon Shield
- Experience with scripting and automation using PowerShell, Python, APIs, or Infrastructure as Code, and integrating security requirements into JIRA or engineering workflows
- Supporting certifications such as CSSLP, CISSP, GIAC, Salesforce, or cloud security certifications
Compensation: The Base Salary range for this position is between $130,000-$140,000.
This information reflects a base salary range that AssetMark reasonably expects to pay for the position based on a number of factors which may include job-related knowledge, skills, education, experience, and actual work location. This position will also be eligible for additional variable incentive compensation and competitive benefits.
Candidates must be legally authorized to work in the US to be considered. We are unable to provide visa sponsorship for this position.
#LI-hybrid