Staff-level product security judgment. You have the depth to operate independently across complex product security challenges—typically developed through 8+ years of experience—and the range to extend into adjacent areas such as cloud security. You don’t just find vulnerabilities; you design systems that prevent entire classes of them.
Engineering roots. You’ve shipped production code, built meaningful software or automation recently, and are strong in at least one backend or automation language such as Go, Python, Java, or TypeScript. You see security as an engineering problem, not a compliance checklist.
Product security depth. You understand authentication and authorization—including OAuth, OIDC, SAML, JWT, RBAC, and ReBAC—as well as API security, threat modeling, secure code review, vulnerability testing, and multi-tenant SaaS handling sensitive data. You can move from an architecture diagram into the implementation path that matters.
Cloud security fluency or aptitude. You have working knowledge of cloud security concepts such as IAM, network architecture, workload isolation, secrets, and logging—or a demonstrated ability to develop that expertise quickly.
Offensive validation instincts. You can reproduce vulnerabilities, conduct targeted dynamic testing, build proof-of-concept exploits, and distinguish exploitable risk from theoretical concern.
Demonstrated influence. You’ve helped engineering teams understand, prioritize, remediate, and verify material security risks.
Tooling ownership. You’ve owned security tooling or automation beyond deployment, including integration, tuning, triage, maintenance, and evaluation.
AI-augmented security engineering. You use AI as a force multiplier to develop depth in unfamiliar domains, expand your coverage, and move with greater speed. You validate its output against first principles and remain accountable for every technical and security decision.
Based in the Bay Area and able to work from our San Francisco office three days per week.