Security Engineer III

Anaplan

Los Angeles (CA)

On-site

USD 163,000 - 220,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Anaplan is seeking a Security Engineer III to join the Security Operations team. You will design, build, and improve capabilities to detect, investigate, and respond to threats at scale, bridging engineering and operations.

Own SSPM, endpoint vulnerability management, and office/network security while collaborating with IT and infrastructure. You’ll administer security tooling, enforce policies (SPF, DKIM, DMARC), and guide risk-aware decisions across enterprise projects.

Qualifications

  • Experience in enterprise security functions protecting corporate systems, endpoints and networks.
  • Practical knowledge of SaaS Security Posture Management tooling and common misconfiguration risks.
  • Hands-on experience with vulnerability scanning and management platforms (e.g., Qualys, Tenable, Rapid7).
  • Deep technical knowledge of email security controls (SPF, DKIM, DMARC) and enterprise email platforms.
  • Experience deploying protective DNS and web security solutions and proxies.
  • Knowledge of firewall policy management, IDS/IPS, network segmentation, NAC and Wi-Fi security.
  • Ability to administer and tune security platforms in production environments.
  • Familiarity with NIST CSF, CIS Benchmarks and ISO 27001.
  • Strong cross-functional communication to translate security risks for diverse audiences.

Responsibilities

  • Drive SSPM rollout and remediation across SaaS apps and engage with owners to close gaps.
  • Own endpoint vulnerability lifecycle from discovery to remediation tracking and reporting.
  • Design and improve security posture for office and corporate networks including firewall and DNS controls.
  • Administer and optimize email security configurations, SPF/DKIM/DMARC enforcement.
  • Manage DNS and web security controls to block threats and exfiltration.
  • Oversee day-to-day security tooling administration and ensure alert fidelity.
  • Collaborate with IT and infrastructure teams on security deployments and risk assessments.

Skills

Enterprise Security
SaaS Security
Endpoint Vulnerability
Email Security
DNS/Web Security
Network Security
Tooling Administration
Security Frameworks
Communication

Job description

At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.

What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.

Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.

Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebratingour wins – big and small.

Supported by operating principles of being strategy-led, values -based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!

As a Security Engineer III embedded within the Security Operations team, you will design, build, and continuously improve the technical capabilities that underpin how we detect, investigate, and respond to threats. You will work at the intersection of engineering and operations — turning security problems into scalable, automated solutions.

Your Impact
  • SaaS Security Posture Management (SSPM): Drive the rollout and ongoing management of the company’s SSPM program, identifying and remediating misconfigurations across SaaS applications. Triage and prioritize findings, translate them into actionable remediation plans, and work closely with application owners and IT to close gaps and track resolution.
  • Endpoint Vulnerability Management: Own the endpoint vulnerability management lifecycle, from scanning and discovery through to prioritization, remediation tracking, and reporting. Collaborate with IT and infrastructure teams to ensure timely patching and configuration hardening across the endpoint estate, and provide risk-based guidance on outstanding vulnerabilities.
  • Office & Corporate Network Security: Design, maintain, and continuously improve the security posture of office and corporate network environments. This includes firewall policy management, network segmentation, DNS security controls, wireless security, and monitoring for anomalous traffic or lateral movement within the corporate network.
  • Email Security: Administer and optimize email security controls to protect the organization from phishing, spoofing, malware delivery, and business email compromise. Maintain and tune anti-spam, anti-phishing, and sandboxing configurations, and ensure strong enforcement of SPF, DKIM, and DMARC policies.
  • DNS & Web Security: Manage DNS security controls including protective DNS filtering and response policy zones to block malicious domains and prevent data exfiltration. Administer web security gateways and content filtering solutions to enforce acceptable use policies and protect users from web-based threats, both on-network and when roaming.
  • Security Tooling Administration: Take ownership of the day-to-day administration of enterprise security platforms, including configuration management, policy tuning, license management, and vendor engagement. Ensure tooling is operating effectively, alert fidelity is maintained, and platforms are integrated to provide clear visibility across the enterprise environment.
  • Cross-Functional Collaboration: Act as a key security partner to IT, infrastructure, and enterprise technology teams, providing security guidance on new tooling deployments, system changes, and technology projects. Contribute to the broader security program by supporting risk assessments, policy development, and security awareness initiatives relevant to enterprise systems.
Your Qualifications
  • Enterprise Security Experience: Demonstrable experience working within an enterprise or corporate security function, with hands-on responsibility for protecting corporate systems, endpoints, and networks. A solid understanding of the threat landscape facing enterprise environments and the controls used to manage risk at scale.
  • SSPM & SaaS Security: Practical experience with SaaS Security Posture Management tooling (e.g., Adaptive Shield, AppOmni, Obsidian Security, or Microsoft Defender for Cloud Apps) and a strong understanding of common SaaS misconfiguration risks. Ability to communicate findings clearly and drive remediation across business and technical stakeholders.
  • Endpoint Vulnerability Management: Hands-on experience with vulnerability scanning and management platforms such as Qualys, Tenable, or Rapid7. Familiarity with vulnerability prioritization frameworks (e.g., CVSS, EPSS, CISA KEV) and the ability to work with IT teams to drive timely and effective remediation.
  • Email Security: Deep technical knowledge of email security controls, including SPF, DKIM, and DMARC configuration and enforcement, and experience administering enterprise email security platforms such as Proofpoint, Mimecast, or Microsoft Defender for Office 365. Ability to investigate and respond to email-based threats and phishing incidents.
  • DNS & Web Security: Experience deploying and managing protective DNS solutions (e.g., Cisco Umbrella, Infoblox BloxOne, Cloudflare Gateway) and web security gateways or proxies (e.g., Zscaler, Netskope, Symantec Web Security Service). Understanding of DNS-based attack techniques and how to detect and block them.
  • Network Security: Working knowledge of corporate network security principles, including firewall policy management, IDS/IPS, network segmentation and micro-segmentation, NAC, and Wi‑Fi security. Experience with enterprise network security vendors such as Palo Alto Networks, Fortinet, or Cisco is beneficial.
  • Security Tooling Administration: Proven ability to administer, tune, and maintain security platforms in a production enterprise environment. Comfort with configuring integrations between tools, managing alert workflows, and driving value from security investments through active, hands‑on ownership.
  • Security Frameworks & Standards: Familiarity with relevant security frameworks and standards such as NIST CSF, CIS Benchmarks, and ISO 27001, and an understanding of how enterprise security controls map to compliance and audit requirements.
  • Communication & Collaboration: Strong ability to communicate technical security risks and recommended mitigations to both technical and non‑technical audiences. Comfortable working cross‑functionally with IT, infrastructure, and business teams to deliver security outcomes without impeding productivity.

#LI-SP1

Base Salary Range:

$163,000 - $220,000 USD

Our Commitment to Diversity, Equity, Inclusionand Belonging (DEIB)

We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business. DEIB improves our workforce, enhances trust with our partners and customers, and drives business success. Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader. We believe in a hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique. We hire you for who you are, and we want you to bring your authentic self to work every day!

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment. Please contact us to request accommodation.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Anaplan’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service‑connected disability.

A "recently separated veteran" means any veteran during the three‑year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Voluntary Self-Identification of Disability

Form CC-305 Page 1 of 1 OMB Control Number 1250-0005 Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp .

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability.

Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention‑deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Leader — Application Framework
Senior Product Leader — Application Framework

Anaplan • Minneapolis (MN)

On-site
Customer Success Strategy & Operations, Sr. Manager
Customer Success Strategy & Operations, Sr. Manager

Anaplan • New York (NY)

On-site
USD 154,000 - 209,000
Information Security Engineer, Product
Information Security Engineer, Product

Apto • United States

Remote
USD 120,000 - 150,000
100% insurance premium coverage for medical, dental, and vision
Equipment of your choice
Flexible vacation time and 11 holidays
+2
VP, Financial Planning & Analysis New New York, NY
VP, Financial Planning & Analysis New New York, NY

Madison Logic • New York (NY)

Hybrid
USD 200,000 - 225,000
Hybrid work option
Software Integration Engineer 2 (On-Call) - Linux/Bash/Python/Docker/Kubernetes/IaC/Helm/Promet[...]
Software Integration Engineer 2 (On-Call) - Linux/Bash/Python/Docker/Kubernetes/IaC/Helm/Promet[...]

Captivation-Software • Maryland

On-site
USD 130,000 - 270,000
Up to 20% 401k contribution
HSA contribution
Company-paid medical/dental/vision
+1
Strategic Engagement Lead
Strategic Engagement Lead

Evolver Transformation, Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 140,000 - 210,000
Staff IT Systems Engineer
Staff IT Systems Engineer

Obsidian Security • Palo Alto (CA)

Hybrid
USD 203,000 - 224,000
Competitive compensation
Equity and 401k
Healthcare coverage
+3
Data Analytics & Visualization Engineer
Data Analytics & Visualization Engineer

C3EL • Scott Air Force Base (IL)

On-site
USD 110,000 - 150,000
Enterprise Account Executive - San Francisco Bay Area - HYBRID
Enterprise Account Executive - San Francisco Bay Area - HYBRID

Obsidian Security • Palo Alto (CA)

On-site
USD 125,000 - 176,000
Competitive compensation with equity
Comprehensive healthcare
Flexible paid time off
+2
Technical Requirements Systems Engineer(Mid/Senior)(Hybrid) - Java/JavaScript/AWS
Technical Requirements Systems Engineer(Mid/Senior)(Hybrid) - Java/JavaScript/AWS

Captivation Software • Maryland

Hybrid
USD 130,000 - 270,000
401k up to 20%
HSA contribution
Full medical/dental/vision
+1