Deep AWS security expertise - you've architected multi-account strategies, written SCPs, and hardened production environments
Experience with Kubernetes security in production - not just tutorials, you've secured real clusters running real workloads
Strong infrastructure-as-code skills - Terraform, CloudFormation, or Pulumi - you think in code, not console clicks
Experience with CSPM/CNAPP platforms (Wiz, Prisma Cloud, or similar) - deploying, tuning, and driving remediation
Understanding of network security at the cloud level - VPCs, security groups, transit gateways, PrivateLink
You've designed tenant isolation for multi-tenant SaaS - data segregation, compute isolation, network boundaries
5+ years of professional experience in cloud security, infrastructure security, or platform/SRE engineering with a strong security focus
Experience with Snowflake security - schema-level isolation, access controls, data sharing governance
Familiarity with container runtime security (Falco, SentinelOne Cloud Workload Protection, or similar)
Offensive cloud security skills - you've exploited misconfigurations and understand the attacker's perspective
Experience building compliance-ready infrastructure (SOC 2, ISO 27001, FedRAMP)
You've handled cloud security incidents - forensics, containment, and root cause analysis in AWS
Contributions to open source infrastructure security tools