- Own Cloud Security Posture Management including Kubernetes and container security strategies, network policies, and environment hardening.
- Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure.
- Collaborate with Platform Engineering to institutionalize secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.
- Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
- Evaluate and secure infrastructure-as-code across all environments.
- Execute incident response duties, encompassing forensic investigation and facilitation of blameless post-mortem analyses.
- Elevate security standards within Engineering through rigorous design reviews, collaborative pairing, and technical mentorship.
- Oversee bug bounty triage and maintain engagement with external security researchers.
AWSPythonKubernetes+3 more