Embed security into the SDLC Partner closely with engineering teams Review security controls for new features, services, and architectural changes Run threat modeling sessions Identify threats, attack paths, misconfigurations, and insecure design patterns Collaborate with engineers to ensure systems follow secure-by-design principles Perform security-focused code reviews Provide clear, actionable guidance on secure coding patterns and best practices Assess application and system architectures from a security perspective Perform manual and automated web application security testing Operate, tune, and improve AppSec tooling Integrate and automate security checks within CI/CD pipelines Identify gaps in tooling and recommend or introduce improvements Measure the maturity and effectiveness of the AppSec program Track and report security metrics Drive continuous improvements based on findings, audits, and industry best practices Support engineering teams during application security incidents or vulnerability disclosures Contribute to triage, impact assessment, and root cause analysis Ensure lessons learned are fed back into design, tooling, and processes Enable engineers through training, documentation, and hands-on guidance Create and maintain secure coding guidelines, checklists, and internal resources Act as a trusted security partner