2 hours ago
Responsibilities
- Design, build, and operate reusable security platforms, shared services, reference architectures, and automated policy-as-code controls for infrastructure, containers, and service meshes.
- Build and maintain secrets management, certificate lifecycle, workload identity, zero-trust, and service mesh security capabilities across multi-cloud environments.
- Integrate SAST, DAST, SCA, ASPM, CSPM, and DSPM tooling into engineering pipelines and workflows.
- Implement security architecture and operational controls for LLM applications, RAG pipelines, and agentic AI systems, including protections against prompt injection, model abuse, data exfiltration, and agent trust-boundary violations.
- Architect and operate AWS-native security controls including IAM, SCPs, GuardDuty, Security Hub, Inspector, Macie, Control Tower, Secrets Manager, and KMS.
- Run cloud security posture, data security posture, detection, alerting, and automated response programs at enterprise scale.
- Embed threat modeling, runtime protection, security frameworks, libraries, and controls into SDLC, CI/CD, web application, API, mobile, and cloud-native engineering workflows.
- Develop security guidance, architectural blueprints, documentation, and strategy input while partnering with engineering and AI platform teams.
Requirements
- 15+ years of progressive, hands-on cybersecurity experience building and operating enterprise-scale security systems.
- Deep practitioner-level AWS expertise, including IAM, VPC, GuardDuty, Security Hub, Macie, Inspector, Control Tower, Secrets Manager, and KMS.
- Proven experience delivering SDLC security architecture, CI/CD integrations, developer tooling, SAST/DAST/SCA deployments, and runtime security in production.
- Hands-on production experience with service mesh architectures, mTLS, workload identity, traffic policy, and zero-trust enforcement using Istio, Envoy, Linkerd, or equivalent.
- Demonstrated experience implementing security controls for LLM applications, RAG systems, and agentic AI pipelines in enterprise production environments.
- Operational experience running CSPM and DSPM programs, including finding triage, remediation velocity, and posture improvement metrics.
- Ability to influence engineering teams without formal authority, contribute to security strategy, and communicate through authoritative technical documentation and executive-level summaries.
- Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience.
- Preferred qualifications include large-scale multi-cloud e-commerce or travel technology experience, agentic AI security and red-teaming, security-as-a-platform development, prior people leadership or tech lead experience, and CISSP, CCSP, CSSLP, AWS Security Specialty, or GCP Security Engineer certification.
- Experience applying PCI-DSS, SOC 2, GDPR, and ISO 27001 as a practitioner is preferred.
Benefits
- Medical, dental, and vision coverage.
- Paid time off and an Employee Assistance Program.
- Wellness and travel reimbursement.
- Travel discounts and International Airlines Travel Agent Network membership.
