Overview In this role you shape how security is integrated across the organization, guiding both strategic direction and hands-on implementation. You will lead threat modeling, secure SDLC efforts, and AI/LLM security initiatives, collaborating with engineering, GRC, legal, and privacy. You translate research into actionable guidance, own complex escalations, and build security programs that developers embrace. This is a chance to influence risk posture at scale and mentor teams while aligning with regulatory requirements.
Compensation / Benefits- annual incentive bonus
- country-specific benefits
- accommodation for disabilities
- equal opportunity employer
- hiring process accommodation
- well-being and happiness focus
Responsibilities- Provide strategic and tactical security guidance that informs leadership decisions
- Research emerging threats and malware techniques and translate findings into actionable guidance
- Own high-skill escalations requiring deep expertise
- Design and evolve the secure software development lifecycle with threat modeling and design reviews
- Integrate SAST, DAST, SCA, and secrets detection into CI/CD in developer-friendly ways
- Build and run security champions programs with developer alignment
- Track effectiveness with metrics and clearly communicate risk to technical and non-technical audiences
- Lead security reviews and threat modeling for AI-powered features (LLMs, RAG, vector databases, agentic workflows)
- Evaluate AI tools/APIs for security risk and changes to attack surfaces in SDLC
- Define internal standards for building AI-integrated applications responsibly
- Use AI-powered security tooling and stay fluent in evolving AppSec tools
- Design innovative solutions to protect confidentiality, integrity, and availability at scale
- Collaborate cross-functionally to ensure controls meet regulatory requirements (HIPAA, FedRAMP)
Key requirements- 7+ years in application security or security-focused software engineering
- Experience with threat modeling (STRIDE, PASTA) on distributed systems
- Strong knowledge of web app and API security and remediation
- Hands-on experience embedding SAST, DAST, SCA, and secrets scanning into workflows
- Coding ability (Python, Java, Go, TypeScript) to review code and automate tasks
- Experience in regulated environments with compliance requirements
- Ability to write clear security findings and communicate to senior leadership
- Strong collaboration ethos
- strong collaboration
- clear communication
- curiosity
- SAST
- DAST
- SCA