Responsibilities
- Develop and run security regression tests to validate ongoing system integrity
- Lead threat modeling efforts for both current systems and new feature development
- Conduct hands-on offensive security testing that simulates real-world attack scenarios
- Discover genuine security flaws using in-depth platform knowledge and awareness of OWASP Top 10 risks
- Maintain long-term security of existing and new system functionality by proactively uncovering vulnerabilities
- Design and manage test suites that cover key security-sensitive workflows
- Ensure fixed security issues do not reappear in future releases
- Embed security regression checks within continuous integration and deployment pipelines
- Set and track test coverage goals for high-risk areas such as authentication, APIs, and data handling
- Facilitate formal threat modeling sessions for system components and architectural changes
- Map out potential attack vectors, misuse cases, and system trust boundaries
- Convert identified threats into actionable test cases, security controls, and mitigation strategies
- Integrate threat modeling into the full product development lifecycle
- Carry out manual and automated security assessments that reflect real attacker tactics
- Focus efforts on discovering high-severity, exploitable vulnerabilities with tangible impact
- Assess the practical exploitability and business consequences of discovered flaws
- Collaborate with engineering groups to replicate problems, prioritize fixes, and confirm resolutions
- Regularly evaluate the system against the OWASP Top 10 web security categories
- Leverage deep understanding of the product to expose subtle, context-dependent weaknesses
- Move beyond automated scanning tools to detect logic errors and abuse scenarios
- Review proposed product changes for potential security implications
- Verify that all modifications include threat modeling and are protected by regression tests
- Serve as a security checkpoint while supporting teams with practical guidance and tools
- Promote efficient security practices without introducing excessive process delays
- Partner with engineering, architecture, and platform operations teams to strengthen security outcomes
Responsibilities
- Building and executing security regression testing
- Driving threat modeling across existing and new functionality
- Conducting targeted offensive security activities (Red Team–style testing)
- Identifying real vulnerabilities based on a deep understanding of our platform and the OWASP Top 10 Web Application Security Risks
- Ensure that both existing functionality and new changes remain secure over time, and that real vulnerabilities are discovered before customers do.
- Security Regression Testing Design and maintain security regression test suites covering critical application flows
- Ensure vulnerabilities, once fixed, are permanently prevented from recurring
- Integrate security regression into CI/CD pipelines
- Define coverage targets for security-critical areas (auth, access control, APIs, data flows)
- Threat Modeling Lead structured threat modeling sessions for: Existing system components New features and architectural changes
- Identify attack surfaces, abuse cases, and trust boundaries
- Translate threats into: Test cases Security requirements Mitigation plans
- Ensure threat modeling becomes a continuous lifecycle activity
- Offensive Security / Red Team Activities Perform manual and automated security testing simulating real attacker behavior
- Focus on high-impact vulnerabilities, not theoretical findings
- Validate exploitability and business impact
- Partner with engineering teams to: Reproduce issues Prioritize fixes Validate remediation
- OWASP Top 10–Driven Vulnerability Discovery Continuously assess the platform against OWASP Top 10 categories
- Use deep product knowledge to find non-obvious, context-specific vulnerabilities
- Go beyond tooling (DAST/SAST) to uncover logic flaws and abuse paths
- Security Assurance for Product Changes Review new features and changes for security risks
- Ensure all changes are: Threat-modeled Covered by regression tests
- Act as a security gatekeeper without becoming a bottleneck: Enable teams with guidance and tooling Avoid heavy process overhead
- Collaboration & Enablement Work closely with: Engineering teams Architecture SRE / Platform teams
- Contribute to secure-by-design practices