Interactive Brokers

Security Engineer III - SAAS

Interactive Brokers  •  Mumbai, IN (Hybrid)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About the Company

Interactive Brokers Group, Inc. (NASDAQ: IBKR), a member of the S&P 500, is a global financial services company headquartered in Greenwich, Connecticut, with offices in over 15 countries. Through its affiliates, Interactive Brokers provides automated trade execution and custody of securities, commodities, foreign exchange, and prediction markets on over 170 markets in numerous countries and currencies.

For more than four decades, Interactive Brokers has focused on technology, automation, and innovation to provide clients worldwide with a sophisticated, unified platform to manage their investment portfolios. We serve individual investors, hedge funds, proprietary trading groups, financial advisors, and introducing brokers.

Our culture is driven by problem-solving, efficiency, and continuous improvement. We look for individuals who are intellectually curious, collaborative, and motivated to contribute to technology that helps simplify and enhance access to global financial markets. Interactive Brokers has consistently been recognized as a top broker by respected industry sources including Barron’s, Investopedia, Stockbrokers.com, and others.

The Security Engineer III – SaaS Security leads structured threat modeling across the firm's SaaS applications, cloud-native platforms, APIs, and third-party SaaS integrations to identify design level risk before it reaches production. This is a hands on, technical contributor role for someone who thinks like an adversary, understands modern multi-tenant SaaS and cloud architecture deeply, and can turn complex technical exposure into clear, prioritized, business-relevant risk. You will partner closely with product and platform engineering to drive secure-by-design outcomes across high-risk systems such as trading platforms, client portals, and the APIs and integrations that connect them.
Key Responsibilities
End to End Threat Modeling (core focus)
• Lead threat modeling across the full deployment gamut of SaaS, cloud native, on premise, hybrid, and third-party systems, including applications, infrastructure, microservices, monoliths, APIs, network architecture, and data flows, using methodologies such as STRIDE, PASTA, or attack trees, supported by data flow diagrams (DFDs).
• Map attack surface, trust boundaries, and abuse cases across cloud, data center, network, and endpoint layers, drawing on threat knowledge bases (MITRE ATT&CK including Enterprise, Cloud/SaaS, ICS, and Containers matrices, CAPEC, OWASP Top 10 and API Security Top 10).
Model environment specific risk across the ecosystem, including:
• SaaS and multi-tenant: tenant isolation, data segregation, token and secrets management, and API authorization (e.g., BOLA/IDOR, broken function level authorization).
• Identity and access: authentication and federation flows (OAuth 2.0 / OIDC, SAML/SSO, SCIM provisioning, Kerberos/Active Directory, LDAP), privileged access, and lateral movement paths.
• Cloud native (AWS, Azure, GCP): IAM and over permissioned roles, exposed storage, containers/Kubernetes, serverless, and infrastructure as code, within the relevant shared responsibility model.
• On premise and hybrid: data center and network segmentation, east west traffic, legacy and end of life systems, physical and virtualized infrastructure, on premise to cloud connectivity, and the trust boundaries between them.
• Translate technical findings into documented, prioritized business risk exposure with clear risk ratings, irrespective of where a system is hosted or how it is deployed.
Secure by Design and Engineering Partnership
• Embed threat modeling into the SDLC and architecture lifecycle, and shift security left into design and architecture reviews for new builds, migrations, and modernization of existing on-premises estates.
• Partner with product, platform, and infrastructure engineering to recommend mitigations, secure design patterns, and reference architectures across cloud and on-premises environments.
• Build and maintain reusable threat model libraries, templates, and security patterns to scale coverage across diverse deployment models.
• Support adoption of threat modeling tooling and threat modeling as code and validate that recommended controls are implemented.
Integration, Supply Chain, and Ecosystem Risk
• Threat model integrations across the ecosystem, including third party SaaS, on premise and vendor systems, data flows, authentication, API exposure, webhook and OAuth scope risk, and supply chain and system to system paths (SaaS to SaaS, cloud to on premise, and B2B connectivity).
• Evaluate vendor and partner architectures where they intersect the firm's threat models and trust boundaries.
Risk Communication & Governance
• Produce high-quality threat models and recommendations and tailor communication for both technical and non-technical audiences.
• Brief leadership with concise, decision ready risk insights, and escalate high risk design flaws with context and recommended actions.
• Align threat models with enterprise frameworks (NIST CSF, ISO 27001, CSA Cloud Controls Matrix) and applicable financial services obligations (e.g., DORA, NYDFS 500, RBI guidance).
• Track and report key risk indicators such as threat model coverage across the estate and finding closure rates.
Required Qualifications
• Typically, 5 to 8 years in cybersecurity (or equivalent demonstrated depth) with a focus on threat modeling, application/product security, or security architecture across cloud, SaaS, and on-premise environments.
• Demonstrated, hands on threat modeling of modern and traditional systems using a structured methodology (e.g., STRIDE, PASTA) with DFDs.
• Strong understanding of both cloud native and on-premise architectures: multi tenancy, APIs, microservices, network and infrastructure design, and identity/authentication flows (OAuth/OIDC, SAML/SSO, Active Directory/Kerberos).
• Working knowledge of AWS, Azure, or GCP and their shared responsibility models, plus familiarity with data centers, networks, and hybrid infrastructure security.
• Familiarity with OWASP (Top 10 and API Security Top 10) and MITRE ATT&CK / CAPEC.
• Ability to translate technical risk into clear business terms, with strong written and verbal communication.
• Bachelor's degree in a related field or equivalent practical experience.
Preferred Qualifications
• Experience in financial services or another regulated industry (e.g., DORA, NYDFS 500, RBI guidelines).
• Hands-on with threat-modeling tooling / threat-modeling-as-code (e.g., IriusRisk, OWASP Threat Dragon, Microsoft Threat Modeling Tool, ThreatModeler).
• Experience with DevSecOps, secure SDLC, infrastructure-as-code (Terraform), containers/Kubernetes, or secure code review.
• Exposure to AI/ML or LLM application threat modeling and other emerging technology risks.
• Certifications such as CSSLP, CCSP, CISSP, or a cloud-security specialty (e.g., AWS Certified Security – Specialty, Azure Security Engineer).
Core Competencies
• Adversarial and systems thinking.
• Deep technical understanding of cloud, SaaS, and on-premise architecture across the ecosystem.
• Secure by design, shift left mindset.
• Clear communication across technical and business audiences.
• Strong collaboration with engineering, platform, and infrastructure teams.
• Ownership and accountability for deliverables.
Company Benefits & Perks:
• Competitive salary package.
• Performance based annual bonus (cash and stocks).
• Group Medical & Life Insurance.
• Modern offices with free amenities & fully stocked cafeterias.
• Monthly food card & company paid snacks.
• Hardship/shift allowance with company provided pickup & drop facility*
• Attractive employee referral bonus.
• Frequent company sponsored team building events and outings.

* Depending upon the shifts.
**The benefits package is subject to change at the management's discretion.
Interactive Brokers

About Interactive Brokers

Rated #1 Active Traders and #1 International Trading in 2025 by StockBrokers.com.

Interactive Brokers Group (Nasdaq: IBKR) and its affiliates provide automated trade execution and custody of securities, commodities, foreign exchange, and forecast contracts around the clock on over 160 markets in numerous countries and currencies from a single unified platform to clients worldwide. We serve individual investors, hedge funds, proprietary trading groups, financial advisors and introducing brokers. Our four decades of focus on technology and automation have enabled us to equip our clients with a uniquely sophisticated platform to manage their investment portfolios. We strive to provide our clients with advantageous execution prices and trading, risk and portfolio management tools, research facilities and investment products, all at low or no cost, positioning them to achieve superior returns on investments. Interactive Brokers has consistently earned recognition as a top broker, garnering multiple awards and accolades from respected industry sources such as Barron's, Investopedia, Stockbrokers.com, and many others.

Interactive Brokers Group’s consolidated equity capital exceeds $17 billion.

Throughout its history, the company’s mission has remained unchanged: Create technology to provide liquidity on better terms. Compete on price, speed, size, diversity of global products and advanced trading tools.

Interactive Brokers LLC is a member of NYSE, FINRA, SIPC. For more information, visit: ibkr.com.

Industry
Finance & Insurance
Company Size
1,001-5,000 employees
Headquarters
Greenwich, Connecticut
Year Founded
Unknown
Social Media