Responsibilities
- Develop and carry out automated and manual security regression testing
- Lead threat modeling efforts for both current and upcoming system features
- Execute offensive security exercises that simulate adversarial tactics
- Discover genuine security flaws using in-depth platform knowledge and awareness of OWASP Top 10 risks
- Create and manage test suites focused on high-risk application pathways
- Ensure resolved security issues do not reappear in future releases
- Embed security testing into continuous integration and delivery workflows
- Set testing coverage goals for key security domains such as authentication, access controls, APIs, and data handling
- Facilitate formal threat modeling for existing system elements
- Lead threat modeling for new capabilities and infrastructure changes
- Map out potential attack vectors, misuse scenarios, and system trust boundaries
- Convert identified threats into actionable test procedures
- Transform threat insights into enforceable security specifications
- Develop plans to counter identified threats through design and controls
- Integrate threat modeling as an ongoing phase in the development cycle
- Carry out hands-on and tool-assisted security evaluations that mimic real-world attacks
- Focus efforts on exploitable, high-severity flaws rather than hypothetical issues
- Assess whether vulnerabilities can be exploited and their potential business impact
- Work closely with development teams to replicate reported security problems
- Collaborate with engineers to rank remediation tasks by risk
- Verify that fixes effectively resolve identified security weaknesses
- Regularly evaluate the system against the OWASP Top 10 vulnerability categories
- Leverage deep understanding of the product to detect subtle, context-dependent flaws
- Move beyond static and dynamic analysis tools to expose logic errors and abuse opportunities
- Examine new functionalities and modifications for potential security exposures