15 days ago
Cambridge, MA, USASenior
Responsibilities
- Partner with engineering and product teams to define and operationalise security requirements across the full software development lifecycle.
- Own or co-own secure-by-default standards, patterns, guardrails, and risk-exception governance.
- Lead threat modelling for new features and architectural changes and translate findings into engineering work.
- Drive SAST/DAST adoption and quality through tool tuning, severity calibration, and developer-facing triage guidance.
- Support product teams adopting LLMs, SLMs, and MCP technologies.
- Review code and communicate security issues clearly to developers.
Requirements
- Hands-on product or application security experience embedded across a modern software development lifecycle.
- Ability to review code and communicate security issues clearly, primarily in a C# ecosystem, with exposure to Java or Python.
- Strong knowledge of the OWASP Top 10 and practical mitigation patterns.
- Experience implementing or improving SAST/DAST processes, including tool tuning, triage workflows, and reducing signal to noise.
- Working understanding of cloud and container security fundamentals, ideally with AWS and Docker.
Benefits
- Permanent employment based in Cambridge with flexible hybrid working and attendance in the office once every two weeks.
- Monthly wellbeing allowance and generous paid time off.
- Investment in learning, development, and career progression.
- Private health insurance.
