- Lead the DevSec team, managing performance and growth through 1:1 mentorship and coaching.
- Define and execute the end-to-end security roadmap, prioritizing by risk and driving adoption.
- Perform hands-on security engineering, including threat modeling, secure SDLC, and infrastructure/cloud posture management.
- Develop automation and AI-driven tooling to support company security goals and secure LLM-assisted development.
- Assess security posture using frameworks like CIS Controls and translate findings into actionable engineering plans.
- Interface with compliance needs such as SOC 2, PCI-DSS, and ISO 42001.
- Lead blameless post-mortems for security incidents and present findings to senior management.
AWSPythonKubernetes+1 more