Keep sensitive data inside explicit boundaries
Trace how customer data, credentials, derived artifacts, and delivery outputs move through SaaS applications, workers, data pipelines, review tools, logs, storage, and third parties. Build controls that make tenant isolation, access, retention, deletion, quarantine, and delivery decisions enforceable and auditable rather than dependent on convention.
Give people and AI systems only the authority they need
Design identity, authorization, and credential systems for employees, contractors, customers, services, and AI-assisted workflows. You might build just-in-time access, scoped tool contracts, approval boundaries, safe execution environments, or protections against prompt injection, confused-deputy behavior, and data exfiltration.
Secure how the company and its people operate
Design security into employee onboarding and offboarding, devices, accounts, contractors, vendors, support access, and sensitive human workflows. On the Dissolution side, that includes identity verification, approval boundaries, segregation of duties, document and credential handling, consequential actions, exception paths, and an audit trail that shows who did what and why.
Make the secure path the easiest path
Build paved roads that catch important problems early without creating a security queue. This could include high-signal code and architecture review, secrets and sensitive-data detection, reusable authorization patterns, dependency and cloud controls, release checks, incident tooling, or automated evidence that serves both engineers and customer trust.
•
Establish Sunset’s company-wide security program, current attack surface, highest-consequence risks, and prioritized roadmap
•
Threat-model product, data, AI, cloud, workforce, vendor, delivery, and human operational workflows, then stay involved through implementation and verification
•
Build and improve controls for identity, authorization, tenancy, sensitive data, credentials, logging, secure execution, and customer delivery
•
Define and verify workforce-security requirements for accounts, endpoints, onboarding, offboarding, contractors, vendors, training, and access reviews
•
Work with Dissolution Operations to secure identity checks, approvals, segregation of duties, documents, money or asset-related actions, exceptions, and evidence of human decisions
•
Find vulnerabilities through code review, architecture review, testing, production evidence, and attacker-minded investigation
•
Lead the security side of incidents and exercises, including containment, recovery, learning, and durable remediation
•
Create secure defaults, tooling, and review triggers that let product, machine learning, data, and platform teams move independently
•
Maintain the security control framework and evidence for customer reviews and SOC 2, while keeping each control with an accountable operating owner
•
Work with leadership on risk acceptance and with legal, compliance, and privacy partners on decisions outside the engineering function
•
Use AI tools deeply for security analysis and engineering while treating generated findings, code, and conclusions as evidence to verify
•
Sunset’s most consequential security risks are visible, owned, and being reduced in a deliberate order
•
At least one high-risk technical or human-operational boundary is materially safer because of a control you designed, implemented with its owner, and verified
•
Engineers adopt reusable security capabilities that reduce dependence on case-by-case review
•
Employees, contractors, and operational teams have clear access, approval, escalation, and evidence requirements for consequential work
•
Access, vulnerabilities, incidents, sensitive-data handling, vendor risk, and control evidence become easier to understand and act on
•
Product and AI capabilities expand within explicit authority, isolation, monitoring, and recovery boundaries
•
Customer trust evidence becomes faster to produce because it reflects real, current controls