- Own security configuration for identity, access policies, third-party app governance, and DLP.
- Build, tune, and maintain detections and response playbooks using a detection-as-code pipeline.
- Harden cloud footprint, Kubernetes clusters, and CI/CD pipelines through Infrastructure as Code reviews.
- Manage endpoint security estate including MDM configuration, hardening, and EDR telemetry.
- Lead end-to-end security incident investigations including forensics, root cause analysis, and remediation.
- Conduct threat models and security architecture reviews for internal systems.
- Collaborate with Protocol Security, DevOps, and Engineering to influence security-first operations.
Kubernetes