- Run internal penetration tests and vulnerability scans against Python and Java services.
- Coordinate third-party pentests, scope engagements, and oversee remediation of findings.
- Work with engineers on code reviews and threat modeling to improve the security library.
- Manage SAST/DAST tooling and oversee dependency management and license compliance.
- Enforce AWS cloud security including IAM, SCPs, EKS, RDS, and S3.
- Own the architecture and security of Auth0 implementations and API authorization.
- Define and implement guardrails for AI/LLM initiatives and model pipeline security.
AWSPythonDjango+4 more