Design and improve isolation mechanisms for multi-tenant workloads (containers, sandboxing, execution environments)
Strengthen boundaries between customers, workloads, and internal systems
Identify and mitigate risks in distributed, dynamic compute environments
Secure and harden containerized workloads and orchestration systems (e.g., Kubernetes or similar)
Improve workload isolation, scheduling boundaries, and runtime protections
Evaluate tradeoffs in multi-tenant execution models
Build and maintain systems for securely managing secrets, tokens, and credentials
Improve rotation, auditing, and access controls
Reduce secret sprawl and integrate secure patterns into developer workflows
Secure cloud environments across providers (AWS, GCP, etc.) with a focus on consistency and portability
Improve network boundaries, service segmentation, and access controls
Embed security into infrastructure-as-code and deployment systems
Work closely with product and infrastructure teams to design secure systems from the ground up
Review architecture and code for security risks and provide actionable guidance
Identify patterns in risks and drive cross-cutting improvements
Builder mentality, you design and implement, not just review
Pragmatic approach to security in fast-moving environments
Comfortable working deeply with engineers and influencing system design