About the Role
Responsibilities
- Conduct regular security assessments and code reviews to identify vulnerabilities and ensure compliance with security standards.
- Develop and maintain threat models for products, understanding potential threats and devising strategies to mitigate them.
- Integrate security practices into the software development lifecycle, ensuring that security is considered at each stage of development.
- Identify, assess, and coordinate the remediation of vulnerabilities within products. This includes staying up-to-date with the latest security threats and trends.
- Implement and maintain security tools and automation systems to streamline security processes for product security
- Participate in incident response activities, helping to manage and mitigate security incidents related to the product.
- Provide training and guidance to development teams on best practices in secure coding and product design.
- Ensure products comply with relevant industry security standards and regulations.
- Work closely with engineering, product management, and other teams to ensure security is a key consideration in all aspects of product development and deployment.
- Stay abreast of the latest security research, technologies, and methods to continuously improve product security.
- Conduct risk analysis to understand the impact of potential security threats and develop risk management strategies.
- Develop and enforce security policies and procedures related to product development and maintenance.
Requirements
- Experience working in AWS and with Terraform
- Has strong understanding of information security, including a broad range of exposure to cloud infrastructure, systems analysis and application development, vulnerability scanning, policies and procedures, and audits.
- Experience with cloud computing environments including infrastructure as code, containers and functions.
- Strong knowledge of CWE top 25 and OWASP top 10 vulnerabilities
- Understanding of MITRE ATT&CK matrix
- Experience with code development and can read and understand source code in several programming languages such as Ruby, PHP, Go, JS, Python.
- Automated and Manual Web, Mobile and Traditional application pentesting experience
- Experience with scripting and building automations leveraging tools such as Python and tools such as Claude Code
- Experience l