5+ years of experience in Application or Product Security, preferably in a SaaS or cloud-native environment. Strong understanding of web app and API security, microservices, and containerized architectures. Experience integrating security tooling into modern CI/CD workflows. Proficiency with SAST, DAST, IaC scanning, and container security platforms. Skilled in secure coding and code review for at least one major language (Python, Java, Go, JavaScript). Familiarity with AWS security, Kubernetes security, and DevSecOps best practices.