AI-native. You use AI tools daily in security work — triaging findings, threat modeling, reviewing agent-authored code, drafting detections and policy. You have opinions about where AI sharpens security and where it creates new risk. This is unlikely to be a good fit if you’re skeptical of AI tools or prefer to do everything by hand.
Deep across most of the stack. You have real, hands-on expertise in at least three of appsec, cloud, compliance, and response — not surface familiarity, but the kind of depth where you’ve built and owned controls in each — and the range to pick up the fourth fast. This is unlikely to be a good fit if you only want to work one narrow lane and hand off the rest.
A builder and a leader-in-training. You’re energized by shaping a practice and leveling it up — taking it from informal to instrumented — and by setting standards that make the engineers around you better, even before you have a title that says “manager.” This is unlikely to be a good fit if you only want to be heads-down with no interest in growing a function or the people on it.
A pragmatic risk-prioritizer. You ship the control that reduces the most risk for the least friction, and you’re comfortable saying “not now” to a real-but-low risk. This is unlikely to be a good fit if you treat every finding as equally urgent or chase a perfect posture over a shippable one.
A hands-on engineer. You write the script, build the pipeline, configure the AWS guardrail, ship the detection. This is unlikely to be a good fit if your security experience is policy, audits, and slide decks without building the controls yourself.
A strong collaborator. You work shoulder-to-shoulder with delivery teams and Cloud & DevOps, bringing them along rather than throwing findings over the wall. This is unlikely to be a good fit if your instinct is to gatekeep, block, and police rather than enable.
Payments- and marketplace-minded. You care that real customers and pros and real money flow through this platform, and you reason about risk in those terms. This is unlikely to be a good fit if you think about security in the abstract, detached from the business it protects.