Security Engineering & Operations
• Design, implement, and maintain security controls across cloud, on-premises, and SaaS environments
• Deploy, configure, and manage security tools such as SIEM, EDR, IDS/IPS, vulnerability scanners, and DLP platforms
• Monitor security alerts and telemetry, investigate suspicious activity, and respond to incidents in accordance with defined SLAs
• Tune detection rules and correlation logic to reduce false positives and improve signal quality
• Perform root-cause analysis on security events and implement corrective, preventative actions
• Maintain and continuously improve security architecture diagrams, network segmentation, and control documentation
• Participate in, and where appropriate lead, incident response efforts across the full lifecycle: detection, containment, eradication, and recovery
• Triage alerts, contain active threats, and coordinate cross-functional recovery activities
• Develop, test, and maintain incident response playbooks, runbooks, and communication procedures
• Conduct post-incident reviews and blameless retrospectives, and drive follow-through on recommended improvements
• Serve in an on-call rotation to support after-hours security incidents as needed
Vulnerability & Risk Management
• Perform recurring vulnerability scanning, penetration test coordination, and risk assessments across infrastructure and applications
• Validate findings, assess business risk and exploitability, and prioritize remediation with asset owners
• Conduct threat modeling and security architecture reviews for new systems and major changes
• Track remediation through to closure and report on residual risk to stakeholders
Cloud & Application Security
• Secure cloud infrastructure (AWS, Azure, and/or GCP) and containerized/orchestrated environments (Docker, Kubernetes)
• Implement and maintain IAM policies, secrets management, and least-privilege access models
• Partner with engineering teams to embed security scanning (SAST, DAST, SCA, container scanning) into CI/CD pipelines
• Review application designs, architecture, and code for security risks; provide actionable remediation guidance
• Deploy, configure, and tune Web Application Firewalls (WAF) to protect public-facing applications and APIs
• Develop and maintain WAF rule sets and policies to mitigate OWASP Top 10 risks, bot traffic, and DDoS attempts
• Analyze WAF logs and blocked/allowed traffic to identify attack patterns and reduce false positives/negatives
• Partner with application teams to onboard new services behind the WAF and validate rule coverage before go-live
Compliance & Governance Support
• Assist with audits and compliance initiatives
• Collect and organize audit evidence, and help maintain security policies, standards, and documentation
• Support vendor risk assessments and third-party security reviews
• Help maintain the organization’s risk register and control mapping
Collaboration & Enablement
• Work closely with IT, DevOps, and product teams to design and implement secure solutions
• Provide practical, risk-based security guidance that enables delivery rather than blocking it
• Contribute to security awareness and training initiatives, including phishing simulations and onboarding content
• Act as a security point of contact and subject-matter resource for engineering and business teams