5+ years in security engineering with demonstrated depth in Application and AI security — threat modeling, SAST/DAST, secure code review, and vulnerability management
Proficiency in Python and strong understanding of web application security (OWASP Top 10, API security, auth/authz patterns)
Hands-on experience with application security tooling — Semgrep, Burp Suite, Nuclei, or equivalents
Familiarity with AI/ML security risks — prompt injection, model abuse, agentic attack surfaces, or LLM supply chain risk
Transformative AI fluency — actively uses AI tools to accelerate security work and build automation
Experience in fintech or with financial data security requirements
Familiarity with SOC 2, NIST CSF, or similar compliance frameworks
Cloud security experience (AWS preferred) — IAM, container security, ECS/EKS
Relevant certifications: OSCP, BSCP, CSSLP, CISSP, or equivalent
Detection engineering and incident response experience
Additional offensive security experience — red teaming, bug bounty, or broader penetration testing beyond web/API surfaces