Conduct penetration testing across web applications, mobile applications, and APIs.
Execute secure code reviews to identify and remediate vulnerabilities in application code, scripts, and configurations.
Configure, optimize, and manage results from SAST, DAST, SCA, IaC, and container scanning tools.
Drive DevSecOps initiatives, emphasizing security automation within CI/CD pipelines.
Enhance the security posture of Kubernetes, container runtimes, and the underlying infrastructure.
Contribute to security architecture design and conduct risk reviews for applications, cloud environments, and infrastructure.
Lead threat modeling, risk assessments, and end-to-end vulnerability management.
Promote security awareness by establishing and delivering training sessions and best-practice workshops.
Partner with development, DevOps, and infrastructure teams to guarantee secure design and delivery.
Act as a trusted security advisor, translating complex technical risks into actionable recommendations for non-technical stakeholders.
Participate in incident response, conduct post-incident reviews, and ensure lessons learned are implemented.
Stay continuously updated on emerging threats, modern attack vectors, and innovative security technologies.
Desired Candidate Profile
7–12 years of professional experience in information security roles.
Proven hands-on expertise in web, mobile, and API penetration testing.
Proficiency with application and infrastructure security tooling (SAST, DAST, SCA, IaC, and container scanning).
Deep understanding of DevSecOps principles, CI/CD pipeline security, and security automation frameworks.
Strong knowledge of cloud security best practices, specifically within AWS and Azure.
Solid grasp of Kubernetes, Docker, container runtime security, and secure architecture design principles.
Proficient scripting skills (e.g., Python, Bash) to build and automate security workflows.
Strong analytical and problem-solving mindset.
Excellent communication and stakeholder management skills, with the ability to articulate technical risks clearly to non-technical audiences.
Highly collaborative approach when working with development, DevOps, product, and leadership teams.
Passion for continuous learning and championing a company-wide culture of security.