- Write production code and build security tooling and middleware for platform services.
- Review engineering design documents for product features and architecture changes.
- Build and tune detections as code, add telemetry sources, and reduce alert noise.
- Develop reusable Go security libraries and middleware, and drive adoption across services.
- Own security initiatives such as Kubernetes and cloud hardening, application security in CI, or detection engineering.
- Deliver control automation and audit evidence for SOC 1, SOC 2, OCC, and other regulatory workstreams.
- Expand Kubernetes, container, and supply-chain security, including image scanning, signing, admission policies, and runtime protection.
- Participate in incident response and the security on-call rotation.
- Help launch and triage the bug bounty program and expand DLP coverage and policies.
- Turn tabletop exercises and resilience testing into concrete fixes.
AWSKubernetesGo+1 more