2+ years in application security, DevSecOps, or software development with hands-on experience securing code and applications Deep understanding of SAST, SCA, DAST, IaC security, and secrets detection Application security workflow expertise Competitive analysis experience Independent operator AI/LLM systems experience preferred Product management fundamentals Startup mindset