About the job
Key Responsibilities
Security in the SDLC
Lead the implementation and enforcement of DevSecOps practices within CI/CD pipelines, including SAST, DAST, SCA, and more.
Integrate automated security tools into development workflows to minimize manual security checks.
Collaborate with development teams to conduct secure code reviews and perform threat modeling.
Vulnerability & Risk Management
Oversee vulnerability detection, prioritization, and remediation across both infrastructure and applications.
Manage the security tooling stack effectively.
Create and maintain a comprehensive risk register, tracking remediation Service Level Agreements (SLAs).
Penetration Testing, Crowd Testing & Incident Response
Coordinate or lead internal and external penetration testing initiatives.
Manage crowd testing campaigns to identify vulnerabilities.
Develop and uphold an incident response playbook while supporting incident investigations.
Compliance & Governance
Assist in ensuring compliance with SOC 2, ISO 27001, GDPR, and other relevant data protection frameworks.
Establish and enforce security policies, standards, and developer training programs focused on security.
Leadership & Collaboration
Serve as the primary security Subject Matter Expert (SME) for the engineering organization.
Mentor developers in secure coding practices and foster a security-first engineering culture.
Engage with external auditors, clients, and executive leadership regarding the organization's security posture.

