Requirements
- 4–10 years of experience in information security, with depth in application security architecture, cloud security (AWS), or security pre-sales/solutioning.
- Strong understanding of web application frameworks, cloud-native architectures, and SaaS security models.
- Proven ability to communicate complex security topics clearly and concisely—both in writing and in live customer conversations.
- A builder’s mindset: you default to creating playbooks, templates, and repeatable processes rather than solving problems one-off.
- Experience driving automation or process improvement in a security operations or GTM context.
- Comfort working across time zones and adapting to shifting schedules when customer needs require it.
- Self-directed, low-maintenance, and energised by fast-paced, high-growth environments
- Cloud security architecture and operations, with hands-on depth in AWS (IAM, VPC, KMS, CloudTrail, GuardDuty, Security Hub).
- Web application security fundamentals: OWASP Top 10, secure SDLC, API security, and encryption standards (TLS, AES-256, key management).
- Working knowledge of SaaS security models, multi-tenant architecture, and shared responsibility frameworks.
- Familiarity with security questionnaire and trust center platforms (e.g., Loopio, Responsive, SafeBase) and GRC tools (e.g., Drata, Vanta).
- Ability to read and interpret security documentation, penetration test reports, SOC 2 audit reports, and architecture diagrams.
- Comfort with process automation concepts—scripting, workflow builders, or no-code/low-code tools to reduce manual, repetitive work.
- Executive-level communication: ability to distill complex security topics into clear, confident narratives for technical and non-technical audiences alike.
- Cross-functional influence: skilled at building alignment across Security Engineering, Legal, Product, Sales, and Customer Success without formal authority.
Nice to Have
- CISSP (Certified Information Systems Security Professional)
- AWS Security Specialty or AWS Solutions Architect
- CISM (Certified Information Security Manager)
- CompTIA Security+ or equivalent foundational certification