- Manage end-to-end vulnerability management, including pen tests, CSPM/CWPP tooling, and MTTR risk reporting.
- Perform application security tasks such as SAST, DAST, SCA, secret scanning, threat modeling, and secure code review.
- Secure AI/LLM integrations, RAG pipelines, and API providers by implementing guardrails and evaluating new features.
- Maintain cloud infrastructure security in Azure/AKS and GCP, covering IAM, network segmentation, encryption, and IaC scanning.
- Build security automation via CI/CD gates, detection-as-code, and SOAR tooling.
- Manage detection and response across endpoints, cloud, and application layers.
- Map technical controls to compliance frameworks like NIST 800-53, SOC 2, FedRAMP, and CMMC.
PythonGCPKubernetes+3 more