Engage with internal business teams on projects to assess for security risk and help deliver secure solutions via threat modeling, code review, penetration testing, and enforcing secure development lifecycle
Assist with the implementation and execution of the application security program with the business and engineering teams
Provide guidance on security architecture related to cloud computing products and services
Test web applications for common vulnerabilities including input validation, broken access controls, session management, cross-site scripting, SQL injection and web server configuration issues
Utilize security information and event management for real-time analysis of security alerts generated by our cloud infrastructure and applications
Actively participate in Incident Management, Change Management, Security Policy Management and Security Incident Response
Perform secure code reviews and implement security in all the phases of SDLC.
Perform SAST, DAST, Internal Penetration testing on the Applications and the Infrastructure.
Lead SOC2 and PCI Compliance programs
3+ years of industry experience with a proven track record of end-to-end audit prep / compliance ownership in one or more of the following: SOC 2, PCI, HIPAA, ISO 2001
3+ years experience in Application/Product security role.