Job Description
Senior Security Engineer
INDIA BASED, REMOTE
At Prescient Security, we are on a mission to simplify security and compliance.
Our core values are:
- Bring Order to Chaos
- Be Accountable & See it Through
- 1000% With You
- Support & Collaborate
- Think Outside the Box
We're looking for a senior, hands-on Senior Security Engineer to own the operational side of our security program from vulnerability management and pen testing through to securing our core SaaS platforms (Microsoft 365, Salesforce) and the integrations connecting them. This role is a step up from a traditional security engineer: you'll not only triage and remediate, but youll also set the standards, own the roadmap, and drive cross-functional teams to close gaps.
What you'll own
Vulnerability management & penetration testing
- Schedule and coordinate penetration tests (internal and third-party vendors) and recurring DAST scans; manage scope, timing, and access.
- Review and triage DAST, SAST, and SCA findings; distinguish real issues from noise.
- Monitor AWS Security Hub findings; perform initial triage, prioritize, and track to remediation under the same SLA framework.
- Track all findings through-to remediation in a single system of record; report on status, aging, and trends.
- Define, monitor, and enforce remediation SLAs by severity; escalate breaches to owners and leadership.
- Own triage of false positives across all scan sources and maintain suppression/exception records with justification and approvals.
Identity, access & network reviews
- Conduct periodic user access and permission reviews across core systems (infrastructure, M365/Entra ID, Salesforce); identify and drive removal of excess or stale access.
- Perform firewall and network rule reviews; flag overly permissive, unused, or risky rules for cleanup.
- Own the quarterly access review cadence for admin roles, guest users, and high-privilege profiles, including sign-off with system owners.
SaaS & platform security (M365, Salesforce, integrations)
- Own the ongoing security posture of Microsoft 365 and Salesforce: Secure Score / Health Check tracking, conditional access, MFA enforcement (including phishing-resistant MFA for admins), and privileged role management (e.g., PIM).
- Maintain hardened baselines for mail flow, anti-phishing, SPF/DKIM/DMARC, external sharing (SharePoint/OneDrive/Teams), and Salesforce profiles/permission sets/OWD.
- Build and maintain an inventory of integrations touching core platforms auth method, owner, data classification, and secrets location and drive migration of secrets into a managed vault (e.g., Key Vault, Secrets Manager).
- Review and tighten OAuth scopes, connected apps, and service account privileges on a recurring basis.
- Stand up monitoring/alerting for high-risk SaaS events (impossible travel, mass download, anomalous OAuth grants, privilege escalation) and define the triage/escalation process.
Hardening & program leadership
- Lead security hardening projects end-to-end (baselines, configuration standards, control improvements) across infrastructure and SaaS platforms.
- Build and maintain a prioritized security roadmap; present findings, metrics, and roadmap progress to leadership.
- Maintain clear documentation, runbooks (including incident response), and reporting on the state of findings and remediation.
- Act as a technical escalation point and mentor for more junior security/IT staff working on scanning and remediation.
What we're looking for
- 58 years in a security engineer, security administrator, or similarly hands-on security role, with demonstrated ownership of a security program area (not just execution of assigned tickets).
- Working knowledge of DAST, SAST, and SCA tooling and how to interpret their output.
- Experience triaging vulnerability findings, distinguishing false positives, and driving remediation to closure across both infrastructure and SaaS environments.
- Hands-on experience securing Microsoft 365/Entra ID and/or Salesforce (conditional access, identity hardening, permission models) or an equivalent enterprise SaaS platform.
- Experience with integration/secrets security: identifying credential sprawl, migrating to managed vaults, and reviewing OAuth scopes.
- Basic threat modeling skills (e.g., STRIDE, data-flow diagrams) and secure-coding knowledge.
- Comfortable building and presenting a risk-prioritized roadmap to non-technical leadership.
- Hands on experience working with a SOC or NOC
Nice to have
- Relevant certifications (e.g., Security+, AWS Security Specialty, CISSP, CISM, OSCP) — helpful, not required.
- Pentesting background.
- AWS certifications.
- Experience with Salesforce Shield / Event Monitoring, Microsoft Defender for Cloud Apps, or Microsoft Sentinel.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.