Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
EY

Senior Cloud Access Security

EY

. Triage SaaS alerts in Microsoft Defender portal incident/alert queues and attach context (user, app, IP, activity type).

Posted 10/7/2026full-timeBengaluru • IndiaSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in SaaS security, incident investigation, and risk management, with a strong focus on monitoring and triaging alerts in Microsoft Defender. Proficient in analyzing Cloud Apps and implementing effective policies to mitigate risks associated with unsanctioned applications.

Highest-signal resume keywords
SaaS Security ConceptsIncident Investigation SkillsCloud Technology ExperienceAPI Connector UnderstandingDefender Portal Familiarity

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
SaaS Risk ManagementIncident TriageData Exfil IndicatorsOAuth Permission AbuseCloud Discovery MonitoringPolicy TuningRoot Cause AnalysisEvidence CaptureRunbook AdherenceRisky User Behavior Analysis
Tools & Technologies
Microsoft DefenderITSM SystemsCloud Access Security Broker (CASB)API-Based VisibilityLog-Based Ingestion
Industry Keywords
Shadow ITSaaS Identity Risk PatternsAnomalous Data AccessHigh-Risk ApplicationsCloud Apps

Tech Stack

Tools & technologies
CloudITSM

About the role

Key responsibilities & impact
  • Triage SaaS alerts in Microsoft Defender portal incident/alert queues and attach context (user, app, IP, activity type).
  • Monitor Cloud Discovery findings and flag newly discovered high-risk / unsanctioned apps (Shadow IT) for review.
  • Maintain ticket updates, evidence capture, and shift handoffs; follow runbooks for SaaS incidents.
  • Lead investigations for suspicious SaaS activity, risky OAuth apps, and anomalous data access.
  • Pivot across Cloud Apps entities/activities to scope impact, identify root cause, and recommend containment actions.
  • Tune policies to reduce false positives, define sanctioned versus unsanctioned workflows, and produce monthly SaaS risk reports.

Requirements

What you’ll need
  • Familiarity triaging security alerts in the Defender portal and working in ITSM systems.
  • Strong SaaS security concepts: risky user behavior, data exfil indicators, and admin activity red flags.
  • Demonstrated understanding of how Cloud Apps connects to SaaS (API-based visibility and controls).
  • Strong incident investigation skills in Defender portal workflows for Cloud Apps.
  • Demonstrated knowledge of SaaS identity risk patterns and OAuth permission abuse.
  • Working understanding of API connector behavior and constraints.
  • Minimum 3+ years of Cloud technology, specifically in CASB or Security engineering roles (preferred).
  • Awareness of Cloud Discovery log-based / API-based ingestion concepts (syslog/FTP pipelines) at a high level.
  • Ability to combine CASB and web security operations into one role while maintaining strong SaaS risk visibility and policy tuning discipline.