Responsibilities
- Create and manage a full application security program that supports business goals and complies with industry best practices.
- Establish and maintain secure coding guidelines, security policies, and application security procedures.
- Deliver training on application security and data privacy topics to software development teams.
- Analyze source code for security flaws, risky patterns, exposed secrets, and issues related to AI-generated code.
- Investigate, validate, and assist in fixing security flaws such as SQL injection, cross-site scripting, and authorization flaws found via automated scanning or manual review.
- Oversee application security workflows, including task management, issue tracking, and collaboration with development and operations teams.
- Support and improve the organization’s responsible disclosure and vulnerability reporting process.
- Work with developers to apply strong encryption, hashing, and secure handling of cryptographic keys.
- Engage with engineering teams to conduct threat modeling, map potential attack vectors, and evaluate system weaknesses.
- Lead responses to application security breaches, coordinating with security operations and engineering to resolve issues quickly and communicate effectively.
- Advise on security and privacy measures for cloud platforms, software development, and connected IoT devices.
- Carry out periodic risk assessments on applications to detect vulnerabilities and new threat vectors.
- Study emerging cybersecurity threats and propose effective countermeasures when needed.
- Conduct offensive security testing and validation of software systems, including internal AI models and services.
- Utilize cloud-based security tools to detect and protect large language model integrations with proper security controls.
Responsibilities
- Create and manage a full application security program that supports business goals and complies with industry best practices.
- Establish and maintain secure coding guidelines, security policies, and application security procedures.
- Deliver training on application security and data privacy topics to software development teams.
- Analyze source code for security flaws, risky patterns, exposed secrets, and issues related to AI-generated code.
- Investigate, validate, and assist in fixing security flaws such as SQL injection, cross-site scripting, and authorization flaws found via automated scanning or manual review.
- Oversee application security workflows, including task management, issue tracking, and collaboration with development and operations teams.
- Support and improve the organization’s responsible disclosure and vulnerability reporting process.
- Work with developers to apply strong encryption, hashing, and secure handling of cryptographic keys.
- Engage with engineering teams to conduct threat modeling, map potential attack vectors, and evaluate system weaknesses.
- Lead responses to application security breaches, coordinating with security operations and engineering to resolve issues quickly and communicate effectively.
- Advise on security and privacy measures for cloud platforms, software development, and connected IoT devices.
- Carry out periodic risk assessments on applications to detect vulnerabilities and new threat vectors.
- Study emerging cybersecurity threats and propose effective countermeasures when needed.
- Conduct offensive security testing and validation of software systems, including internal AI models and services.
- Utilize cloud-based security tools to detect and protect large language model integrations with proper security controls.