Strong computer science and security fundamentals — deep understanding of operating systems, networking, compilers and the JVM, distributed systems, application security, cloud-native security, and supply chain security. Both breadth and depth
Expert-level Java, with hands-on depth in the JVM, ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, and performance profiling and tuning. Plus working proficiency in Python or Go
Substantial production experience with RASP, SAST, DAST, IAST, SCA, image security, and code scanning — enough to design a capability, integrate the engine, build the platform around it, and take it to scale independently
Real offensive and defensive experience. You understand the root causes, exploitation paths, detection logic, bypass techniques, and fixes for common web, API, and microservices vulnerabilities — and can design from both the attacker's and defender's point of view
Fluency with LLMs and AI Agents, including a considered view on model capability limits, agent architecture, tool calling, context engineering, evaluation methods, and how AI is reshaping both security engineering and the attack surface
Strong engineering execution paired with product instinct — able to lead the design and delivery of security products, platform modules, and SDKs/Agents while balancing security outcomes against performance overhead, integration cost, and long-term operability
Exceptional ownership, cross-team communication, and the persistence to move security governance, rule enforcement, and remediation through to a clear result
Security engineering experience at a top-tier internet company, cloud provider, or leading security vendor
You've led the build of a DevSecOps platform, application security platform, RASP, code scanning platform, or cloud-native security platform
Background in security product development, SDK/Agent engineering, vulnerability research, red team exercises, or purple team work
Shipped AI + Security work — security copilots, intelligent rule generation, automated analysis, or remediation recommendation systems