Invesco
by Invesco
Job Summary:
Job Description:
You will be Responsible for:
- Continuously monitor SaaS applications for misconfigurations, risky user behavior, or other deviations against application security baselines.
- Review and remediate SaaS security findings based on industry benchmarks prioritizing vulnerabilities using risk‑based strategies and contextual intelligence.
- Conduct periodic SaaS posture audits and prepare reports for leadership.
- Support SaaS onboarding projects with security configuration reviews.
- Collaborate with IAM, AppSec, SecOps, and Engineering teams to drive secure SaaS adoption.
- Track and report SaaS security KPIs and risk scores.
- Monitor DLP alerts and investigate incidents across storage and applications used by Invesco.
- Conduct risk reviews and operationalize data vulnerability management processes across the organization.
- Prepare dashboards and compliance reports.
- Provide user awareness on secure data practices.
- Lead DLP‑related identified vulnerabilities and remediation plans.
- Provide internal remediation support through the design, implementation and integration of network infrastructure and information security controls.
The Experience You Bring:
- 8+ years of Information Security or relevant experience.
- Solid understanding of SaaS security and controls frameworks.
- Experience with SSPM tools.
- Strong knowledge of OAuth apps, API tokens, SSO, SCIM provisioning, and RBAC models.
- Familiarity with large SaaS platforms.
- Good knowledge of standards: CIS Benchmarks, CSA CMM, SOC2, ISO 27001.
- Ability to analyze alerts, risks, and configurations including usage of automation to scale.
- Hands-on experience with enterprise DLP platforms.
- Strong understanding of data classification, labeling, and protection frameworks.
- Building mature vulnerability management processes for new vulnerability domains.
- Maintain strict confidentiality of all security issues including legal investigations, Compliance, and HR data requests
- Preferred certification: AWS Cloud Practitioner/CCSP – Certified Cloud Security Professional (ISC²)/ CISSP