Experience: Minimum 6+ years in Security Engineering, Security Architecture, or a dedicated Security Research role focused on solution validation and vendor management
Technical Depth: Deep understanding of modern cloud security principles (e.g., AWS/Azure/GCP security models, Kubernetes/containers, network segmentation, IaC scanning, least privilege, identity-centric security, confidential computing)
Programming and Automation - Strong scripting / programming skills (e.g., Python, Go, or similar) for automating PoCs, building test harnesses, and integrating tools via APIs and CI/CD pipelines
Solutions Expertise: Proven, hands-on experience with the architecture, deployment, and testing of two or more enterprise-grade security tools (e.g., SIEM/SOAR platforms, Endpoint Detection and Response (EDR), Vulnerability Management, Secrets Management)
PoC Proficiency: Demonstrated ability to plan and execute complex technical Proof-of-Concepts, including setting up test environments and defining quantitative success metrics
Soft Skills: Exceptional analytical skills with the ability to translate complex technical findings into clear business risk and strategic recommendations. Strong written and verbal communication
Experience in Cloud or Cloud-Heavy companies
Experience in a compliance-focused industry (e.g., finance, healthcare, or cloud infrastructure) and familiarity with frameworks such as ISO 27001, SOC 2, or GDPR
Advanced professional certifications such as CISSP, CCSK or relevant cloud certifications (e.g., AWS/GCP/Azure Security Specialty)
Experience contributing to security standards, open-source tools, talks, or publications
Threat-to-Solution Mapping: Proactively analyze customer expectations, regulatory/compliance drivers, and threat models to define precise functional and non-functional requirements for new security solutions
Market Analysis & Scouting: Conduct thorough market scans to identify cutting-edge security products, platforms, and vendors across key domains (e.g., CSPM/CNAPP, DLP, IAM/IGA, EDR/XDR, data security, Kubernetes security, and AI/ML security)
Vendor Due Diligence: Evaluate potential vendors based on technical capability, security posture, integration requirements, roadmap, data residency/compliance, and support quality, and shortlist candidates for the PoC phase