Чем предстоит заниматься
Own product and application security across Merge's platform: APIs, integrations, agent tooling, and AI-powered features
Conduct security reviews, threat modeling, and code reviews with a focus on application-layer vulnerabilities (OWASP Top 10, injection, auth flaws, insecure deserialization, etc.)
Drive vulnerability identification and remediation across the full SDLC, from design through deployment
Build and mature our application security program, including SAST/DAST tooling, security testing in CI/CD, and developer security guidance
Utilize AI to test the resiliency of our applications and systems
Own and operate our bug bounty program end to end: triage, response, remediation, and researcher communication
Partner with Engineering to embed secure design patterns and security review into how we ship software
Support infrastructure and cloud security as needed, with a focus on how it intersects with our product surface