2 hours ago
Responsibilities
- Drive shift-left security practices and embed security requirements and controls throughout the software development lifecycle.
- Integrate, maintain, and improve security tooling and automation across CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and software supply chain protections.
- Configure, tune, and triage security tools and vulnerability management platforms to improve signal quality and remediation workflows.
- Identify, assess, and remediate application security risks across supported services and components in partnership with cross-functional stakeholders.
- Conduct threat modeling, security code reviews, and system design reviews covering low-level design, API design, and data modeling.
- Safely integrate and operate AI/ML-enabled solutions that improve security outcomes.
- Enable developers through secure development guidance, standards, and playbooks and influence secure engineering decisions.
- Reduce vulnerability backlogs and improve remediation SLAs through automation, tool tuning, and operational improvements.
Requirements
- Bachelor’s degree in Computer Science or a related technical field, or equivalent related professional experience.
- 5+ years of relevant professional experience in application security, product security, DevSecOps, or security engineering.
- Experience supporting modern CI/CD pipelines, cloud-native services, and secure software delivery across multiple services or domains.
- Practical experience with software supply chain security, including SBOMs, signing or attestation, secure build pipelines, SAST, DAST, and SCA.
- Experience operating and tuning vulnerability management and security tooling platforms and integrating them with CI/CD pipelines, ticketing systems, and developer workflows.
- Experience with modern programming languages such as Java or Python for automating security outcomes.
- Preferred experience applying AI/ML and agentic AI techniques to vulnerability management, including autonomous triage, prioritization, classification, enrichment, or AI-assisted security tooling.
- Familiarity with AI-driven systems, AI/ML security implications such as the OWASP LLM Top 10, and basic penetration testing concepts.
- Demonstrated success enabling developers on secure development practices and influencing secure engineering decisions.
- Strong communication skills and the ability to explain complex security topics to technical and non-security audiences.
- Proven impact reducing vulnerability backlogs and improving remediation SLAs.
Benefits
- Medical, dental, and vision coverage.
- Paid time off and an Employee Assistance Program.
- Wellness and travel reimbursement.
- Travel discounts and International Airlines Travel Agent Network (IATAN) membership.
