Responsibilities
- Integrate security seamlessly into cloud infrastructure and CI/CD workflows, ensuring secure configurations are the default choice for all development teams.
- Develop and manage AI-powered security agents that continuously identify, assess, and resolve vulnerabilities in code, dependencies, containers, and infrastructure-as-code templates.
- Implement and govern secure software development lifecycle practices, including threat modeling and secure coding standards, with automated security checks embedded directly into pipelines.
- Enforce security policies using integrated tools such as SAST, SCA, DAST, secrets detection, and IaC scanning as mandatory pipeline stages.
- Secure internal agentic systems by mitigating risks like prompt injection, misuse of tools or model context protocols, data leakage, over-autonomous behavior, and third-party supply chain threats.
- Align agentic system protections with recognized standards including OWASP Top 10 for LLM Applications and MITRE ATLAS.
- Lead efforts to identify and remediate high and critical severity vulnerabilities in platform components and container images, meeting compliance and contractual obligations.
- Automate vulnerability remediation processes to reduce manual effort and accelerate response timelines.
- Collaborate with engineering units to strengthen security in Azure Kubernetes Service deployments, covering identity management, access controls, network isolation, and secrets handling.
- Support compliance initiatives such as SOC 2 and ISO 27001 by providing security controls and evidence, and automate evidence collection using intelligent agents.
- Establish and maintain security runbooks, detection rules, and incident response protocols, and develop agents that execute them efficiently.
- Elevate team security expertise through active code reviews, collaborative coding sessions, and practical, developer-oriented guidance.
- Advance the organization's agentic operating model by building reusable security-focused agent capabilities, prompts, and tooling for enterprise-wide adoption.
- Ensure security tooling keeps pace with evolving cloud-native architectures and development practices.
- Drive continuous improvement in security automation, reducing toil and increasing coverage across the development lifecycle.
Compensation
Competitive salary and benefits package commensurate with experience
Work Arrangement
Hybrid or remote options available based on location and role requirements
Team
Embedded within the platform engineering team, collaborating closely with R&D, security, and compliance functions
Security Automation & AI Integration
- Leverage AI-driven agents to enable continuous, autonomous security coverage across the development pipeline, replacing periodic manual reviews with real-time protection.
- Build self-operating tools that detect and fix security issues in source code, dependencies, containers, and infrastructure configurations without human intervention.
Compliance & Evidence Management
- Support audits and compliance programs by generating verifiable security evidence and implementing automated monitoring of control effectiveness.
- Use agentic systems to streamline data collection for SOC 2, ISO 27001, and cyber insurance requirements.
Available for qualified candidates where permitted by local regulations