• Work closely with the product and engineering teams to review new features and suggest new features that improve security.
• Drive S-SDLC in our cycles and review security acceptance criteria and threat modeling.
• Guide and train the team to cover security checks and security best practices.
• Perform pre-deployment and post-deployment security penetration tests.
• Plan and execute regular web, mobile, and cloud security assessments and pen tests.
• Work closely with the Infrastructure teams to identify security issues through red teaming activities.
• Define, implement, and monitor infrastructure security measures.
• Contribute to the security roadmap & backlog.
• Assess security tools and integrate tools as needed.
• Incident Response & Research.
• Follow new security news, trends, tools, and incidents and drive needed changes.
• Support in managing our Bug-bounty program and security channels.
• Conduct vulnerability research against company assets.
• Work on understanding and improving our security logging and monitoring solutions.
• Coordinate company-wide response to security incidents till remediation.
• Vulnerability management for production/staging environments.
• Actively mentor members of the security team.