Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in applications and weaknesses in secure coding practices
Assess discovered vulnerabilities and recommend risk-mitigating solutions, leveraging automation to improve the efficiency of both testing and remediation processes
Communicate findings, risks, and recommendations to stakeholders, while documenting delivery and implementation progress against defined service-level agreements (SLAs) and business metrics
Lead AI security initiatives, including threat modeling production LLM stacks for autonomy and prompt injection risks, and auditing third-party models and APIs to secure the software supply chain
Attend and participate in product and application projects. This includes interacting with business units and technical teams to understand what is coming and how their projects can be more secure from the beginning
Collaborate with architects and development teams to drive secure design practices, leveraging established security standards, configurations, and frameworks
Fully define and follow a security review process to ensure an automated and repeatable process is managed
Regularly monitor the security community for public-facing security issues, as well as to learn new tactics that can be used in testing
Train developers and junior application security engineers on weaknesses to avoid
Perform other duties as assigned
Wherever it Leads, Whatever it Takes® - No matter how remote, complex, or unexpected. Our commitment never wavers
Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit
Lift others up - We lead with empathy and strive to improve the lives of those around us
Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact
Raise the bar - We don’t settle for industry standards, we redefine them