Conduct threat modeling and security design reviews for new features, services, and architectural changes.
Perform secure code reviews and provide feedback focusing on authentication, authorization, input handling, secrets management, and data protection.
Deploy and maintain security tooling across the development lifecycle including SAST, SCA, DAST, secret scanning, IaC scanning, and CI/CD security guardrails.
Support infrastructure and environment security, including AWS resource hardening and Terraform-managed infrastructure reviews.
Contribute to incident response for security events.
Drive vulnerability triage and prioritization across teams and report metrics.
Partner with sales and legal on customer and vendor questionnaires, RFP security sections, and trust-and-safety inquiries.
Support SOC 2, ISO 27001, PCI 4.0, and other compliance audit cycles.
Monitor and respond to alerts from endpoint, cloud, and application security tools.
Execute recurring user access reviews and IAM hygiene tasks.