CoStar Group
Overview
CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the world’s real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives. We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers. We’ve continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors. We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers, our employees, and investors. By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate.
Responsibilities
Program & Strategy
Build the enterprise SaaS Security program: charter, operating model, RACI, roadmap, control framework mapping to ISO 27001, and KPIs.
Stand up a single source of truth for SaaS inventory (shadow IT included), integrating procurement, SSO/IDP, network/DNS/forward proxy, CASB/SSE, SSPM, and expense data.
Define SaaS risk tiering and baseline control requirements by data classification and business criticality.
Architecture & Engineering
Implement and operationalize SSPM and extend existing capabilities in CASB/SSE: continuous posture assessment, misconfiguration detection, and auto‑remediation pipelines.
Engineer governed OAuth/consent patterns across IDP and key platforms (e.g., Salesforce, Microsoft 365/Entra ID, Workday, Atlassian, and Others).
Define and enforce SSO/MFA mandates, SCIM provisioning, tenant segmentation, conditional access, DLP for SaaS, and API logging/telemetry standards.
Establish secure configuration baselines and policy‑as‑code (e.g., Terraform/OPA/CLI automations) for major SaaS platforms.
Detection & Response
Integrate SaaS signals (SSPM/CASB, platform event logs like Salesforce Event Monitoring, M365, Okta/Entra) into SIEM/SOAR with detection content for OAuth abuse, anomalous consent, data exfiltration, Admin drift, and risky API usage.
Author and exercise SaaS IR playbooks: token theft response, consent rollback, key rotation, scope reduction, app quarantine, containment & comms, forensics & lessons learned.
Governance, Risk & Compliance Partnership
Codify SaaS security standards and exception management with GRC; embed control checks into procurement/vendor risk and IT change processes.
Align to SOX ITGC, privacy (e.g., GDPR/CCPA), regulatory audits, and customer assurance (SOC 2/ISO) evidence.
Enablement & Change Management
Drive business adoption: curated enterprise app catalog, secure patterns, training for Admins and app owners, and migration plans for risky patterns.
Publish dashboards and metrics for leadership (coverage, high‑risk apps, misconfig posture, incident MTTR, consent trends).
Qualifications
Basic Qualifications
Bachelor’s Degree required from an accredited, not for profit university or college.
A track record of commitment to prior employers.
8+ years in security with 3+ years specializing in SaaS security across large enterprises (5k+ employees).
Deep expertise in OAuth 2.0/OIDC, SAML, SCIM, JWT/PKCE, token hygiene/rotation, consent governance, and least‑privilege scopes.
Hands‑on with one or more major SaaS ecosystems at scale: Salesforce (Connected Apps, Shield, Event Monitoring), Microsoft 365/Entra ID, Google Workspace, ServiceNow, Workday, Slack, Atlassian.
Operationalizing SSPM and/or CASB/SSE; integrating IDP signals into SIEM/SOAR; building detections and automations.
Strong grasp of NIST 800‑53/CSF, ISO 27001, CIS Controls v8, CSA CCM, and mapping to SaaS controls.
Incident response experience for SaaS/OAuth/token compromise scenarios.
Scripting/automation (e.g., Python, PowerShell, or Node), and IaC/policy‑as‑code experience.
Preferred Qualifications & Skills
Prior leadership of a SaaS/OAuth security initiative from zero‑to‑one in a complex enterprise.
Experience with DLP, data classification, eDiscovery/legal hold in SaaS.
Familiarity with SOX ITGC and privacy‑by‑design in SaaS workflows.
Certifications: CISSP, CCSP, CCSK, vendor accreditations (e.g., Salesforce Security & Privacy AP, Okta/Entra certs).
Evidence of thought leadership (runbooks, talks, open‑source/policy‑as‑code contributions).
Benefits
Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
Life, legal, and supplementary insurance
Virtual and in‑person mental health counseling services for individuals and family
Commuter and parking benefits
401(K) retirement plan with matching contributions
Employee stock purchase plan
Paid time off
Tuition reimbursement
On‑site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes
Access to CoStar Group’s Diversity, Equity, & Inclusion Employee Resource Groups
Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks
We welcome all qualified candidates who are currently eligible to work full‑time in the United States to apply. However, please note that CoStar Group is not able to provide visa sponsorship for this position.
CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug‑free workplace and perform pre‑employment substance abuse testing.
#J-18808-Ljbffr
Responsibilities
Program & Strategy
Build the enterprise SaaS Security program: charter, operating model, RACI, roadmap, control framework mapping to ISO 27001, and KPIs.
Stand up a single source of truth for SaaS inventory (shadow IT included), integrating procurement, SSO/IDP, network/DNS/forward proxy, CASB/SSE, SSPM, and expense data.
Define SaaS risk tiering and baseline control requirements by data classification and business criticality.
Architecture & Engineering
Implement and operationalize SSPM and extend existing capabilities in CASB/SSE: continuous posture assessment, misconfiguration detection, and auto‑remediation pipelines.
Engineer governed OAuth/consent patterns across IDP and key platforms (e.g., Salesforce, Microsoft 365/Entra ID, Workday, Atlassian, and Others).
Define and enforce SSO/MFA mandates, SCIM provisioning, tenant segmentation, conditional access, DLP for SaaS, and API logging/telemetry standards.
Establish secure configuration baselines and policy‑as‑code (e.g., Terraform/OPA/CLI automations) for major SaaS platforms.
Detection & Response
Integrate SaaS signals (SSPM/CASB, platform event logs like Salesforce Event Monitoring, M365, Okta/Entra) into SIEM/SOAR with detection content for OAuth abuse, anomalous consent, data exfiltration, Admin drift, and risky API usage.
Author and exercise SaaS IR playbooks: token theft response, consent rollback, key rotation, scope reduction, app quarantine, containment & comms, forensics & lessons learned.
Governance, Risk & Compliance Partnership
Codify SaaS security standards and exception management with GRC; embed control checks into procurement/vendor risk and IT change processes.
Align to SOX ITGC, privacy (e.g., GDPR/CCPA), regulatory audits, and customer assurance (SOC 2/ISO) evidence.
Enablement & Change Management
Drive business adoption: curated enterprise app catalog, secure patterns, training for Admins and app owners, and migration plans for risky patterns.
Publish dashboards and metrics for leadership (coverage, high‑risk apps, misconfig posture, incident MTTR, consent trends).
Qualifications
Basic Qualifications
Bachelor’s Degree required from an accredited, not for profit university or college.
A track record of commitment to prior employers.
8+ years in security with 3+ years specializing in SaaS security across large enterprises (5k+ employees).
Deep expertise in OAuth 2.0/OIDC, SAML, SCIM, JWT/PKCE, token hygiene/rotation, consent governance, and least‑privilege scopes.
Hands‑on with one or more major SaaS ecosystems at scale: Salesforce (Connected Apps, Shield, Event Monitoring), Microsoft 365/Entra ID, Google Workspace, ServiceNow, Workday, Slack, Atlassian.
Operationalizing SSPM and/or CASB/SSE; integrating IDP signals into SIEM/SOAR; building detections and automations.
Strong grasp of NIST 800‑53/CSF, ISO 27001, CIS Controls v8, CSA CCM, and mapping to SaaS controls.
Incident response experience for SaaS/OAuth/token compromise scenarios.
Scripting/automation (e.g., Python, PowerShell, or Node), and IaC/policy‑as‑code experience.
Preferred Qualifications & Skills
Prior leadership of a SaaS/OAuth security initiative from zero‑to‑one in a complex enterprise.
Experience with DLP, data classification, eDiscovery/legal hold in SaaS.
Familiarity with SOX ITGC and privacy‑by‑design in SaaS workflows.
Certifications: CISSP, CCSP, CCSK, vendor accreditations (e.g., Salesforce Security & Privacy AP, Okta/Entra certs).
Evidence of thought leadership (runbooks, talks, open‑source/policy‑as‑code contributions).
Benefits
Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
Life, legal, and supplementary insurance
Virtual and in‑person mental health counseling services for individuals and family
Commuter and parking benefits
401(K) retirement plan with matching contributions
Employee stock purchase plan
Paid time off
Tuition reimbursement
On‑site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes
Access to CoStar Group’s Diversity, Equity, & Inclusion Employee Resource Groups
Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks
We welcome all qualified candidates who are currently eligible to work full‑time in the United States to apply. However, please note that CoStar Group is not able to provide visa sponsorship for this position.
CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug‑free workplace and perform pre‑employment substance abuse testing.
#J-18808-Ljbffr