At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market. Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, behave like leaders regardless of title, are committed to achieving ambitious goals, and love celebrating our wins. Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!
Responsibilities
- Lead the implementation and management of the SaaS Security Posture Management (SSPM) program, addressing misconfigurations in SaaS applications. Prioritize findings, create actionable remediation plans, and collaborate with application owners and IT to resolve issues.
- Oversee the endpoint vulnerability management lifecycle, from scanning to remediation tracking and reporting. Work with IT and infrastructure teams to ensure timely patching and configuration hardening, providing risk-based guidance on vulnerabilities.
- Design and enhance the security posture of office and corporate networks, including firewall management, network segmentation, DNS security, and monitoring for unusual traffic.
- Manage email security measures to protect against phishing, spoofing, and malware. Maintain anti-spam and anti-phishing configurations, ensuring strict enforcement of SPF, DKIM, and DMARC policies.
- Oversee DNS security controls to block malicious domains and prevent data exfiltration. Manage web security gateways and content filtering to enforce acceptable use policies and protect against web threats.
- Handle daily administration of enterprise security platforms, including configuration management and vendor engagement. Ensure effective operation and integration of tools for clear visibility across the enterprise.
- Serve as a security partner to IT and infrastructure teams, providing guidance on new tools and projects. Support the broader security program through risk assessments and policy development.
Requirements
- Proven experience in a corporate security role, with hands-on responsibility for protecting systems, endpoints, and networks. Strong understanding of the enterprise threat landscape and risk management controls.
- Experience with SSPM tools (e.g., Adaptive Shield, AppOmni) and knowledge of SaaS misconfiguration risks. Ability to communicate findings and drive remediation with stakeholders.
- Experience with vulnerability scanning platforms (e.g., Qualys, Tenable) and familiarity with prioritization frameworks. Ability to work with IT for effective remediation.
- Technical expertise in email security controls and experience with platforms like Proofpoint or Mimecast. Capability to investigate email threats and phishing incidents.
- Experience with protective DNS solutions and web security gateways. Understanding of DNS attack techniques and detection methods.
- Knowledge of corporate network security principles and experience with vendors like Palo Alto Networks or Fortinet.
- Proven ability to manage and maintain security platforms effectively. Comfort with configuring integrations and managing alert workflows.
- Familiarity with frameworks like NIST CSF and ISO 27001, and understanding of how security controls align with compliance requirements.
- Strong communication skills to convey technical risks to diverse audiences. Ability to work collaboratively across teams to achieve security objectives without hindering productivity.
Benefits
- A hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique.
- Reasonable accommodation provided to individuals with disabilities to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment.
- Diversity, equity, inclusion, and belonging (DEIB) initiatives that improve the workforce, enhance trust with partners and customers, and drive business success.
Additional details
- Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.
- It has come to our attention that fraudulent and fictitious job opportunities are being circulated on the Internet. Prospective candidates are being contacted by certain individuals, mainly through telephone calls, emails and correspondence, claiming they are representatives of Anaplan. The main purpose of these correspondences and announcements is to obtain privileged information from individuals.
- Anaplan does not: Extend offers to candidates without an extensive interview process with a member of our recruitment team and a hiring manager via video or in person. Send job offers via email. All offers are first extended verbally by a member of our internal recruitment team whenever possible and then followed up via written communication. All emails from Anaplan would come from an @anaplan.com email address. Should you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Anaplan, please send an email to people@anaplan.com before taking any further action in relation to the correspondence.
- Candidate data processed during our recruitment activities is handled in accordance with our Candidate Privacy Notice. This may include the use of artificial intelligence or automated tools to assist our team in evaluating qualifications.