Have experience securing production infrastructure, cloud environments, APIs, developer platforms, or multi-tenant SaaS products
Can write code and are comfortable reading application, infrastructure, and deployment code
Understand authentication, authorization, secrets, IAM, logging, audit trails, incident response, and secure deployment pipelines
Independently prioritize and drive your day-to-day as the first dedicated security hire
Prefer practical improvements over heavy processes
Are low-ego, direct, curious, and willing to learn from others
Care about developer experience and believe security should be easy to adopt
Have experience with email infrastructure, transactional email, sender reputation, domain verification, SPF, DKIM, DMARC, webhooks, or abuse prevention
Have secured cloud infrastructure using tools like AWS, Terraform, Kubernetes, Cloudflare, or similar systems
Have experience with open source security, GitHub organization hardening, package publishing, dependency review, or supply-chain security
Have helped a company prepare for SOC 2, ISO 27001, GDPR, enterprise security reviews, or customer trust processes without turning engineering into a compliance machine
Have built security observability, alerting, detection pipelines, or incident response workflows
Have worked closely with Trust & Safety, anti-abuse, fraud, or platform integrity teams
Have experience designing security systems for high-scale developer products