Anaplan
Security Engineer III
San Francisco, CaliforniaFrom $220kmidAdded yesterday
About this role
Anaplan seeks a Security Engineer III to design and operate enterprise security infrastructure across SaaS, endpoints, networks, and email. This role combines hands-on engineering with security operations to detect, investigate, and respond to threats while driving continuous improvement of detection and automation capabilities.
What you'll do
- Lead SaaS Security Posture Management program rollout, identify misconfigurations, and drive remediation across applications
- Own endpoint vulnerability management lifecycle including scanning, prioritization, patch tracking, and risk assessment
- Design and maintain corporate network security including firewalls, segmentation, DNS controls, and wireless security
- Administer and optimize email security controls including anti-phishing, anti-spam, and DMARC/SPF/DKIM enforcement
- Manage DNS and web security gateways to filter malicious domains and enforce acceptable use policies
- Administer enterprise security platforms, manage configurations, tune alerting, and coordinate vendor relationships
What they're looking for
- SaaS Security Posture Management (SSPM) tools and methodologies
- Vulnerability scanning platforms (Qualys, Tenable, Rapid7)
- Enterprise email security platforms (Proofpoint, Mimecast, Defender for Office 365)
- Email authentication protocols (SPF, DKIM, DMARC)
- DNS security and protective DNS filtering
- Network security including firewalls and segmentation
- Vulnerability prioritization frameworks (CVSS, EPSS, CISA KEV)
- Security incident investigation and response
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Anaplan
- Website
- anaplan.com
Likely interview questions
- Describe your experience implementing or managing a SaaS Security Posture Management program at scale—what challenges did you encounter and how did you address them?
- Walk us through your approach to triaging and prioritizing vulnerabilities using frameworks like CVSS and EPSS, and how you've driven remediation timelines with infrastructure teams.