Senior SaaS Security Engineer
Arlington, Arlington County, Virginia, 22201, USA
Listed on 2025-12-16
-
IT/Tech
Cybersecurity
Senior SaaS Security Engineer
Job Description
OverviewCoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the world’s real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives.
We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers. We’ve continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors.
We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers, our employees, and investors. By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate.
We’re hiring a Senior SaaS Security Engineer to help us evolve our corporate environment to enable our mission and help build a strong practice in SaaS Application Security.
This position is located in Richmond or Arlington, VA, and is in office Monday through Thursday and work from home on Friday.
Responsibilities Program & Strategy- Build the enterprise SaaS Security program: charter, operating model, RACI, roadmap, control framework mapping to ISO 27001, and KPIs.
- Stand up a single source of truth for SaaS inventory (shadow IT included), integrating procurement, SSO/IDP, network/DNS/forward proxy, CASB/SSE, SSPM, and expense data.
- Define SaaS risk tiering and baseline control requirements by data classification and business criticality.
- Implement and operationalize SSPM and extend existing capabilities in CASB/SSE: continuous posture assessment, misconfiguration detection, and auto-remediation pipelines.
- Engineer governed OAuth/consent patterns across IDP and key platforms (e.g., Salesforce, Microsoft 365/Entra , Workday, Atlassian, and Others):
- Enterprise app catalogs, pre-approved scopes, just-in-time reviews, least privilege scopes, refresh token hygiene, IP/session restrictions, device trust signals, token revocation patterns.
- Define and enforce SSO/MFA mandates, SCIM provisioning, tenant segmentation, conditional access, DLP for SaaS, and API logging/telemetry standards.
- Establish secure configuration baselines and policy-as-code (e.g., Terraform/OPA/CLI automations) for major SaaS platforms.
- Integrate SaaS signals (SSPM/CASB, platform event logs like Salesforce Event Monitoring, M365, Okta/Entra) into SIEM/SOAR with detection content for OAuth abuse, anomalous consent, data exfiltration, Admin drift, and risky API usage.
- Author and exercise SaaS IR playbooks: token theft response, consent rollback, key rotation, scope reduction, app quarantine, containment & comms, forensics & lessons learned.
- Codify SaaS security standards and exception management with GRC; embed control checks into procurement/vendor risk and IT change processes.
- Align to SOX ITGC, privacy (e.g., GDPR/CCPA), regulatory audits, and customer assurance (SOC 2/ISO) evidence.
- Drive business adoption: curated enterprise app catalog, secure patterns, training for Admins and app owners, and migration plans for risky patterns.
- Publish dashboards and metrics for leadership (coverage, high-risk apps, misconfig posture, incident MTTR, consent trends).
- Bachelor’s Degree required from an accredited, not for profit university or college.
- A track record of commitment to prior employers
- 8+ years in security with 3+ years specializing in SaaS security across large enterprises (5k+ employees).
- Deep expertise in OAuth 2.0/OIDC, SAML, SCIM, JWT/PKCE, token hygiene/rotation, consent governance, and least-privilege scopes.
- Hands-on with one or more major SaaS ecosystems at scale:
Salesforce (Connected Apps, Shield, Event Monitoring), Microsoft…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).