- Design and implement security controls across applications, cloud infrastructure, internal systems, and development environments
- Conduct architecture reviews, threat modeling, code reviews, and security assessments for new products and features
- Identify, prioritize, and remediate vulnerabilities across the technology stack
- Embed security into the software development lifecycle through secure coding standards, automated testing, and developer tooling
- Build and improve detection, monitoring, incident response, and vulnerability management capabilities
- Partner with engineering and infrastructure teams to strengthen cloud, container, network, identity, and access security
- Lead or support the investigation and remediation of security incidents
- Develop reusable security tooling, automation, documentation, and technical guardrails
- Evaluate third-party technologies, integrations, and vendors for potential security risks
- Support customer security reviews, enterprise diligence, and technical compliance requirements
- Help establish security policies and controls aligned with frameworks such as SOC 2, ISO 27001, HIPAA, or PCI DSS
- Mentor engineers and promote shared ownership of security across the organization
Requirements
- 5+ years of experience across security engineering, application security, cloud security, infrastructure security, or related disciplines
- Strong software engineering or systems engineering foundation
- Proficiency in languages such as Python, Go, Java, JavaScript, TypeScript, or Rust
- Experience securing cloud-native applications and infrastructure on AWS, GCP, or Azure
- Knowledge of common application and infrastructure vulnerabilities, attack techniques, and mitigation strategies
- Experience with threat modeling, secure design reviews, penetration testing, or vulnerability research
- Familiarity with identity and access management, secrets management, encryption, and network security
- Experience building security automation and integrating controls into CI/CD pipelines
- Ability to communicate technical risks and recommendations to engineering teams and business stakeholders
- Strong judgment around risk prioritization, remediation, and balancing security with execution speed
- Experience in venture-backed startups, security-sensitive industries, or rapidly scaling technology companies
Core Competencies
Demonstrates expertise in security engineering, application security, and cloud security, with a strong foundation in software engineering. Proficient in threat modeling, vulnerability management, and integrating security controls into development processes.
Highest-signal resume keywords
- Security Engineering
- Cloud Security
- Python Programming
- Threat Modeling
- Vulnerability Management
ATS Optimization Keywords
Hard Skills
- Application Security
- Infrastructure Security
- Secure Coding Standards
- Penetration Testing
- CI/CD Integration
- Vulnerability Research
- Incident Response
- Security Automation
- Risk Prioritization
- Technical Compliance
Soft Skills
- Communication
- Judgment
- Mentoring
Certifications & Qualifications
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
Industry Keywords
- Security Controls
- Cloud-Native Applications
- Security Assessments
- Technical Guardrails
- Security Policies
Tools & Technologies
- AWS
- GCP
- Azure
- Identity Management
- Secrets Management
- Encryption
- Network Security