Responsibilities
- Perform security assessments of internally built software applications
- Verify data flow integrity and traceability across systems
- Design and implement security controls for application protection
- Ensure secure handling and management of secrets
- Implement data loss prevention measures for AI and large language models
- Co-lead readiness evaluations for highly regulated production environments
- Conduct threat modeling exercises to identify potential risks
- Validate system hardening measures against security baselines
- Map controls to compliance frameworks including SOC 2, contracts, and regulations
- Define and enforce corporate and service identity architecture
- Manage corporate identity using Entra ID
- Oversee workload identity via AWS IAM and GitHub OIDC
- Establish and maintain GitHub security configurations
- Implement GitHub Advanced Security features such as CodeQL and SAST
- Configure and monitor Dependabot for dependency vulnerability detection
- Enforce secret scanning to prevent exposure of credentials
- Implement branch protection rules and deployment environment safeguards
- Develop standards for security tool integration across the development lifecycle
- Standardize static application security testing using CodeQL and Semgrep
- Set policies for software composition analysis with Dependabot and Snyk
- Implement container image scanning using Trivy and ECR scanning tools
- Define policy enforcement for infrastructure as code with OPA, Sentinel, and tfsec
- Establish secure AWS configurations focusing on identity and access management
- Enforce least privilege principles in IAM policies
- Ensure comprehensive logging and audit trail requirements are met
Work Arrangement
Hybrid — available in New York City, Boston, Chicago, Carmel, San Francisco, or remotely within the US