- Own end-to-end security reviews across smart contracts (Solidity), backend services (Go, TypeScript, Python), and frontend surfaces, producing written findings at the quality level of a top external audit firm, published and used as the internal standard
- Build and ship an agentic security CI/CD pipeline: agent-driven review that runs autonomously against every PR and release candidate, reasons about changes in context, and gets smarter with each deployment
- Design and maintain specialised AI-powered code reviewers tuned to specific vulnerability classes and surfaces, Solidity-aware, protocol-aware, and calibrated to the actual patterns Polygon's products surface
- Triage and manage the bug bounty program: read incoming submissions daily, reproduce valid findings, separate signal from noise, assign severity, and route confirmed issues to engineering with enough context to fix them correctly, using custom AI workflows to maintain rigor at volume
- Follow through on remediation: review proposed fixes, close out resolved findings, and push back where a fix addresses symptoms rather than root cause
- Embed across engineering teams at all stages, sprint planning, design review, feature freeze, post-launch, as a working partner, not a sign-off function
- Lead the team's AI security practice by example: build custom prompt chains, Claude Code workflows, and Codex integrations tailored to specific security tasks, then demo and share them so the whole team's baseline rises
PythonArtificial IntelligenceTypeScript+1 more