- Build a recurring product security review program through threat modeling, high-risk area audits, code review, and safe proof-of-concepts.
- Improve application security testing with static analysis, dependency and secrets scanning, and dynamic testing.
- Triage findings from HackerOne, scanners, penetration tests, audits, customers, and internal research; reproduce issues, assess impact, track remediation, and verify fixes.
- Automate security alert ingestion, deduplication, enrichment, prioritization, and routing.
- Improve dependency scanning and build workflows to assess upgrades, stage pull requests, run checks, and route remediation safely.
- Partner with service owners and Infrastructure to inventory application secrets and implement rotation paths, runbooks, and automation.
- Work with Infrastructure to improve AWS security detection, secure defaults, access patterns, guardrails, and remediation.
- Partner with Security & Trust on assessments and audits, technical context, documentation, and engineering training.
- Coordinate security incident investigation, containment, remediation, root-cause analysis, and follow-up improvements.
PythonTypeScript