Security Engineer III - SAAS

Interactive Brokers Group
Mumbai
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 5-8 yearsEducation: bachelorsSkills: ["Adversarial thinking","Systems thinking","Secure-by-design mindset","Clear communication","Collaboration"]

Lead structured threat modeling for SaaS and cloud-native platforms, APIs, and third-party integrations to identify design-level risks before production. Own end-to-end threat modeling using STRIDE/PASTA and DFDs across multi-tenant, identity, cloud, and hybrid environments. Partner with product and engineering to embed secure-by-design practices, recommend mitigations, and communicate prioritized risks aligned with frameworks such as NIST CSF, ISO 27001, and CSA CCM.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Interactive Brokers Group
Interactive Brokers Group
2 weeks ago

Security Engineer III - SAAS

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 days agoStatus: Live

Job Summary

Lead structured threat modeling for SaaS and cloud-native platforms, APIs, and third-party integrations to identify design-level risks before production. Own end-to-end threat modeling using STRIDE/PASTA and DFDs across multi-tenant, identity, cloud, and hybrid environments. Partner with product and engineering to embed secure-by-design practices, recommend mitigations, and communicate prioritized risks aligned with frameworks such as NIST CSF, ISO 27001, and CSA CCM.
Location: Mumbai
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Lead end-to-end threat modeling across SaaS, cloud-native, on-premise, hybrid, and third-party systems, including applications, infrastructure, microservices/monoliths, APIs, network architecture, and data flows.
  • •Map attack surfaces, trust boundaries, and abuse cases across cloud/data center/network/endpoint layers using threat knowledge bases such as MITRE ATT&CK and OWASP, and model environment-specific risks.
  • •Embed threat modeling into the SDLC and architecture lifecycle to shift security left for new builds, migrations, and modernization efforts; build reusable threat model libraries and templates.
  • •Partner with product, platform, and infrastructure engineering to recommend mitigations, secure design patterns, and reference architectures, and validate controls are implemented.
  • •Produce high-quality threat models and communicate prioritized risk insights to technical and non-technical audiences; brief leadership and track threat model coverage and finding closure rates.

Pay and Benefits

Perks:Annual BonusEquityHealth InsuranceLife InsuranceMeal AllowanceShift AllowanceCommuter Benefits

Key Requirements

  • •Typically 5 to 8 years in cybersecurity with a focus on threat modeling, application/product security, or security architecture across cloud, SaaS, and on-premise environments.
  • •Hands-on threat modeling of modern and traditional systems using structured methodologies such as STRIDE or PASTA with data flow diagrams (DFDs).
  • •Strong understanding of cloud-native and on-premise architectures, including multi-tenancy, APIs/microservices, network/infrastructure design, and identity/auth flows (OAuth/OIDC, SAML/SSO, Active Directory/Kerberos).
  • •Working knowledge of AWS, Azure, or GCP and shared responsibility models, plus familiarity with data centers, networks, and hybrid infrastructure security.
  • •Familiarity with OWASP (Top 10 and API Security Top 10) and MITRE ATT&CK / CAPEC, with ability to translate technical risk into clear business terms; bachelor’s degree (or equivalent).
Experience:5-8 yearsSaaSCloudCybersecurityFinancial servicesRegulated industries
Education:Bachelor's
Skills:Adversarial thinkingSystems thinkingSecure-by-design mindsetClear communicationCollaboration
Certifications:CSSLPCCSPCISSPAWS Certified Security - SpecialtyAzure Security Engineer
Tech Stack:STRIDEPASTAAttack treesData flow diagrams (DFDs)MITRE ATT&CKCAPECOWASP Top 10OWASP API Security Top 10API authorizationBOLAIDOROAuth 2.0OIDCSAMLSSOSCIMKerberosActive DirectoryLDAPAWS

Company Brief

Interactive Brokers Group
Operates an electronic trading platform providing brokerage services for individuals and institutions across global markets, offering equities, options, futures, forex, bonds, and related clearing and custody services with advanced trading technology and low-cost executions.
Industry: Trading Platforms
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Greenwich, United States
Founded: 1977
WebsiteLinkedIn