Motive Logo

Motive

InfoSec SaaS Security Lead

Reposted Yesterday
Be an Early Applicant
Easy Apply
Remote
Hiring Remotely in Pakistan
Senior level
Easy Apply
Remote
Hiring Remotely in Pakistan
Senior level
The Security Analyst will monitor security alerts, investigate incidents, conduct malware analysis, respond to threats, and manage security tools while also providing documentation and mentoring.
The summary above was generated by AI

Who we are:

Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. For the first time ever, safety, operations and finance teams can manage their drivers, vehicles, equipment, and fleet related spend in a single system. Combined with industry leading AI, the Motive platform gives you complete visibility and control, and significantly reduces manual workloads by automating and simplifying tasks.

Motive serves nearly 100,000 customers – from Fortune 500 enterprises to small businesses – across a wide range of industries, including transportation and logistics, construction, energy, field service, manufacturing, agriculture, food and beverage, retail, and the public sector.

Visit gomotive.com to learn more.

About the Role:

We are looking for a SaaS Security & Compliance Engineer to join our Information Security team. Our environment is 100% SaaS-based with many interconnected systems (e.g., CRM, billing, HRIS, collaboration, support, finance tools), all tied together through our identity provider and integrations.

This role is less about traditional code-review AppSec and more about:

  • Securing how we configure, connect, and use our SaaS platforms
  • Owning key SaaS/identity security controls (SSO, MFA, RBAC, logging, DLP, CASB, SaS Security Posture Management (SSPM), etc.
  • Making sure our SaaS environment is audit-ready for SOC 2, ISO 27001 and customer security reviews

You will sit in InfoSec but work closely with IT, Engineering, Enterprise Systems and other system owners to keep our SaaS stack secure and compliant.

What You'll Do:1. SaaS Security Architecture & Configuration
  • Work with IT to build and maintain an inventory of SaaS applications, including data sensitivity, owners, and integrations.
  • Define and maintain baseline security configurations for key SaaS tools (e.g., password policies, session settings, IP/device restrictions, sharing controls).
  • Review and approve new SaaS apps and integrations from a security perspective:
    • Data flows (what data, where it goes, which region)
    • Access model (who can use it, how they log in)
    • Integration security (API tokens, webhooks, scopes, secrets)
  • Work with app owners to remediate misconfigurations and close security gaps in SaaS platforms.
2. Identity & Access Management for SaaS
  • Partner with IT/Platform to standardize SSO/MFA across as many SaaS apps as possible.
  • Help design and enforce role-based access control (RBAC) and least privilege for critical applications.
  • Support user lifecycle management across SaaS:
    • Onboarding/offboarding flows
    • Group-based access
    • Periodic access reviews and certifications
  • Monitor for and reduce “shadow IT” and unmanaged accounts.
3. SaaS Security Monitoring & Incident Response
  • Work with SIEM/CASB/SSPM/DLP tools (or equivalent) to:
    • Ingest and correlate SaaS audit logs (IdP, CRM, collaboration tools, etc.)
    • Tune alerts for suspicious logins, unusual data access, risky configurations, and anomalous behavior.
  • Participate in the security incident process for SaaS-related events:
    • Triage alerts, validate impact, and coordinate containment with system owners and vendors.
    • Document incidents, root causes, and follow-up actions.
  • Help implement data protection controls in SaaS:
    • DLP policies (e.g., for PII, payment data, other sensitive data)
    • Sharing restrictions (public links, external sharing, downloads).
4. Compliance & Audit (SaaS-Focused Controls)
  • Own/co-own SaaS-related controls for SOC 2, ISO 27001, and similar frameworks, such as:
    • Access control, authentication, and authorization
    • Change management and configuration management for SaaS apps
    • Logging, monitoring, and incident response
    • Vendor management and third-party risk
  • Collect and maintain audit-ready evidence:
    • Screenshots of configs, exported reports, access review results, SIEM/CASB reports, DLP policies, tickets.
  • Support internal and external audits by walking auditors through:
    • How our SaaS security controls are designed
    • How they operate day-to-day
    • How we monitor and improve them.
5. Enablement, Documentation & Process Improvement
    • Create and maintain clear documentation:
      • SaaS security standards and configuration guides
      • Playbooks for onboarding new SaaS apps and integrations
      • Runbooks for common SaaS security tasks and incidents
    • Provide lightweight, targeted guidance to system owners:
      • Here’s how to configure this SaaS app securely
      • Here’s the checklist before you connect a new integration
    • Identify manual or repetitive tasks and suggest opportunities for automation (e.g., scripts, SSPM integrations, workflow tools).
What We Are Looking For:
  • 3–6 years of experience in Information Security, IT Security, or a related technical role, with clear exposure to SaaS-heavy environments.
  • Hands-on experience administering or securing SaaS platforms (e.g., Google Workspace / Microsoft 365, Salesforce, HRIS, ticketing/support, collaboration tools).
  • Strong understanding of identity-centric security:
    • SSO, MFA, SAML/OIDC, SCIM
    • RBAC and least privilege
    • Group-based and role-based access models.
  • Experience working with at least some of:
    • IdP (e.g., Okta, Azure AD, Google)
    • CASB / SSPM / DLP / SIEM / or equivalent SaaS monitoring tools.
  • Familiarity with security and compliance frameworks such as SOC 2, ISO 27001 (or similar).
  • Ability to read and interpret SaaS security documentation, admin guides, and audit logs.
  • Strong written and verbal communication; able to explain SaaS security risks and controls to non-security stakeholders.

Creating a diverse and inclusive workplace is one of Motive's core values. We are an equal opportunity employer and welcome people of different backgrounds, experiences, abilities and perspectives. 

Please review our Candidate Privacy Notice here.

UK Candidate Privacy Notice here.

The applicant must be authorized to receive and access those commodities and technologies controlled under U.S. Export Administration Regulations. It is Motive's policy to require that employees be authorized to receive access to Motive products and technology. 

#LI-Remote

Top Skills

Crowdstrike
Dlp
Edr
Elastic
Firewalls
Ibm Qradar
Ids/Ips
Microsoft Defender Atp
Microsoft Sentinel
Sentinelone
SIEM
Splunk

Similar Jobs at Motive

6 Hours Ago
Easy Apply
Remote
Pakistan
Easy Apply
Junior
Junior
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Join Motive as a Designated Support Engineer to provide high-level technical support and build customer relationships. Responsibilities include troubleshooting, issue resolution, and documentation, while collaborating with various teams to enhance customer experience.
Top Skills: APIsData DogFleet Maintenance SystemsHardware DevicesPythonSQLTransportation Management Systems
Yesterday
Easy Apply
Remote
Pakistan
Easy Apply
Mid level
Mid level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
The Manager of the Winback Team leads a team focused on customer reactivation and retention through strategic problem-solving and relationship-building. Responsibilities include managing operations, coaching staff, reporting team progress, and collaborating across departments to enhance processes.
2 Days Ago
Easy Apply
In-Office or Remote
2 Locations
Easy Apply
Senior level
Senior level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Lead a team of Commercial Account Managers to achieve revenue targets by expanding and retaining accounts between SMB and Mid-Market. Responsibilities include pipeline management, coaching, and strategic planning.

What you need to know about the Delhi Tech Scene

Delhi, India's capital city, is a place where tradition and progress co-exist. While Old Delhi is known for its rich history and bustling markets, New Delhi is defined by its modern architecture. It's clear the region places a strong emphasis on preserving its cultural heritage while embracing technological advancements, particularly in artificial intelligence, which plays a central role in shaping the city's tech landscape, fueled by investments in research and development.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account