Design, build, and implement Just-in-Time (JIT) access controls and Privileged Access Management (PAM) workflows.
Conduct platform permission reviews and implement a least-privilege access model.
Ensure 100% of production access requests and approvals are captured in audit logs.
Lead the implementation, tuning, and operation of security tools in the CI/CD pipeline.
Develop custom SAST rules for high-risk flaw patterns detection.
Deploy IDE plugins and automated PR checks with engineering collaboration.
Conduct manual security code reviews for high-risk features.
Design, build, and maintain automation for vulnerability management.
Engineer automated workflows for vulnerability triage and management.
Develop and maintain security automation scripts, tools, and services.
Build high-fidelity SIEM correlation rules and automated response playbooks with SecOps.
Implement and maintain data encryption strategies for PHI in compliance with HIPAA.
Manage cryptographic key lifecycle and administer key management systems.
Design secure cloud network architectures and network segmentation strategies.
Lead the remediation of cloud security findings.
Implement and manage a centralized security control plane.
Design and implement Data Loss Prevention (DLP) policies.
Enforce security configurations and hardening standards for operating systems.
Manage and tune endpoint security solutions including EDR/XDR.
Lead threat modeling sessions and conduct secure design reviews.
Act as an embedded security partner for product and platform teams.
Develop and manage security programs for emerging risks.