• Education: Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or a related technical field.
• Experience: 8+ years of software engineering experience with a strong focus on security implementation — auth systems, compliance controls, or platform security.
– Expert-level knowledge of authentication and authorization patterns (OAuth 2.0, OIDC, JWT, SAML).
– Hands-on experience with AWS Cognito, IAM, KMS, and Secrets Manager.
– Strong backend development skills (Python, Java, or TypeScript) — this is a hands-on engineering role, not a pure advisory one.
– Working knowledge of common compliance frameworks (SOC 2, ISO 27001, GDPR) and how to translate them into engineering controls.
– Familiarity with secure CI/CD patterns and supply-chain security (SBOM, dependency scanning).
• Engineering Excellence: Track record of shipping production-grade security components. Comfortable being a coding security engineer, not just a reviewer.
• Domain Context: (Preferred) Experience in regulated industries (insurance, finance, healthcare) or multi-tenant SaaS.