- Lead security reviews for architecture, code, and security-sensitive changes.
- Evaluate risks in AI-powered products such as prompt injection, unsafe tool use, and identity failures.
- Threat model new capabilities to identify trust boundaries and abuse cases before implementation.
- Perform hands-on testing, including developing proofs of concept and assessing exploitability.
- Build scalable security guardrails, automated checks, and reusable controls.
- Strengthen engineering capability by pairing with engineers and documenting security guidance.
- Influence risk decisions by communicating technical findings to engineers, leaders, and executives.