- Partner with Engineering, DevOps, and Product across projects, providing security input at any phase of design or build.
- Guide secure design and code review for web and mobile applications, and help manage core AppSec tooling.
- Help triage and remediate application-level vulnerabilities with engineering teams.
- Contribute to cloud security posture across the AWS environment using CNAPP and AWS-native tooling.
- Build automation and internal tooling, primarily in Python, that reduces manual work for the security team.
- Contribute to security log pipelines, SIEM detections, and endpoint security controls.
- Embed security checks, such as scanning and secrets detection, into CI/CD pipelines in partnership with DevOps.
- Contribute to secure development and infrastructure standards and playbooks.