🔐 Deep understanding of application security, cloud security, and modern threat landscapes, including common vulnerabilities and attack techniques (OWASP Top 10, MITRE ATT&CK, etc.).
💻 Strong software engineering background with experience writing production-grade code or automation (Python, Typescript, or similar).
☁️ Hands-on experience securing cloud-native infrastructure, especially AWS, including IAM, networking, and containerized workloads.
⚙️ Experience building or integrating DevSecOps pipelines, including SAST, DAST, IaC scanning, and container security tooling.
📊 Experience designing security telemetry pipelines using tools such as SIEM platforms, observability systems, or data lakes.
🧪 Experience running or participating in penetration testing, threat modeling, or architectural security reviews.
🤝 Proven ability to collaborate effectively with engineering, DevOps, and product teams to drive secure design decisions.
📢 Excellent communication skills and the ability to clearly explain complex security risks and trade-offs to both technical and non-technical stakeholders.
📡 Strong understanding of SaaS architectures, distributed systems, and internet-facing platforms.
🧱 Experience developing security frameworks aligned with CIS benchmarks, NIST, or SOC2 / PCI / HIPAA compliance requirements.
🧠 Experience building security detections, threat intelligence pipelines, or runtime protection mechanisms.
🐳 Hands-on experience with Kubernetes, container security, and infrastructure-as-code (Terraform, Ansible).