Improve application security guardrailsTune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams.
Improve cloud and IaC security guardrailsHelp identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale.
Drive vulnerability managementImprove how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.
Drive cloud misconfiguration managementHelp teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows.
Run practical threat modellingFacilitate lightweight threat-modelling sessions for new products, features, services and architectural changes.
Build automation and toolingCreate or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.
Support secure architecture decisionsProvide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.
Partner with engineering teamsWork closely with product, platform and software engineering teams to embed security into design, delivery and operational practices.
Support incidents and lessons learnedProvide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance.
Mentor othersCoach security engineers and engineering teams on practical security approaches. Depending on team structure, this may include line management of one or two security engineers.