Lead application and infrastructure security assessments, code reviews, and penetration tests to identify and mitigate security issues.
Drive the implementation of penetration testing as part of the Secure SDLC.
Work collaboratively with engineering teams to identify security gaps, propose fixes, and guide their resolution.
Lead the creation and implementation of a scalable threat modeling process, integrating it into the product lifecycle.
Evaluate and implement new security tools and technologies to enhance application security processes.
Build strong relationships with product and engineering teams to advocate for secure coding practices and vulnerability remediation.
Conduct penetration tests on cloud-based applications, infrastructure, and services (AWS, Azure, GCP) to identify security gaps.
Minimum qualifications:
Degree in Computer Science or other Technical discipline
7+ years in penetration testing and offensive security practices.
Excellent verbal and written communication skills, with the ability to clearly articulate vulnerabilities and advocate for their remediation in high-pressure environments.
Solid understanding of the Software Development Life Cycle (SDLC) and embedding security early in development.
Proven experience leading and integrating threat modeling into the SDLC.
Hands-on experience in source code reviews and threat modeling.
Strong understanding of common attack vectors, network protocols, and web application security principles.
Strong knowledge of cloud security frameworks and standards such as AWS Well-Architected Framework, MITRE ATTCK Cloud Matrix, CSA Cloud Controls Matrix (CCM) and CIS Benchmarks.
Perform security testing on cloud-native services like AWS Lambda, API Gateway, Kubernetes (EKS/GKE/AKS), and containerized workloads.
Preferred qualifications:
Proficiency with penetration testing tools and frameworks (e.g., Burp Suite, SQLMap).
Hands-on expertise in bug bounties and Capture The Flag (CTF) competitions.
Relevant certifications, such as OSCP, OSCE, OSWE, or AWS Certified Security, are highly preferred.
Experience with mobile application security testing using tools like Drozer, MobSF, Frida, apktool, dex2jar, and jadx.
A self-driven mindset with the ability to take initiative and effectively communicate with diverse internal teams.