Responsibilities
- Partner with development, operations, and other teams to integrate strong security practices into every phase of the software development lifecycle.
- Proactively recognize security gaps and execute improvements without direct supervision.
- Deploy, oversee, and streamline processes for identifying and tracking system vulnerabilities.
- Classify and resolve security flaws detected via internal scanning, external penetration testing, and public bug bounty programs.
- Lead threat modeling sessions, review code, and evaluate system designs to promote secure engineering practices.
- Work closely with technical teams to deliver practical security guidance and support resolution of identified risks.
- Build and operationalize a proactive threat detection function, incorporating automation where feasible.
- Improve system logging related to security events to support monitoring and investigation.
- Integrate and maintain tools for static and dynamic code analysis within development workflows.
- Ensure security tools function effectively and consistently within continuous integration and delivery pipelines.