Minimum of 6 years of experience in Application Security and/or Software Development, with at least 3 years in Application Security Minimum of 2 years of experience in consulting services or internal security roles requiring effective communication with both technical teams and executive leadership Development and/or application architecture design background with understanding of secure implementation practices for cryptography, input validation techniques to prevent injection attacks, and exception management Development experience in JavaScript, shell, Python, Java, C++, PHP, or C# Comprehensive hands-on experience using generative AI in automated workflows Direct hands-on experience in application security service offerings, including application threat modeling, architecture reviews, and AppSec/DevSecOps program assessments Experience with application security controls, architectures, requirements, and industry standards Operational DevSecOps experience Excellent writing, communication, and time management skills Bachelor’s degree in a relevant discipline or equivalent experience