- Drive threat modeling for new features, integrations, and architectural changes.
- Own secure code review for high-risk areas including authentication, session management, and cryptographic flows.
- Expand and tune the AppSec tooling stack to reduce false positives.
- Design and evolve the secure software development lifecycle (SSDLC) and security sign-off processes.
- Manage the responsible disclosure and bug bounty program end-to-end.
- Coordinate remediation of external audit and pentest findings with engineering teams.
- Partner with engineering leads to implement secure-by-default patterns and libraries.
- Threat model blockchain-integrated components such as wallet flows and signing infrastructure.