Source description
About the role
12+ years of experience in product security, application security, or a related engineering discipline.
Proven track record of defining and driving security programs at scale across complex, multi-platform environments.
Hands-on experience architecting and implementing security solutions and processes in production environments, enabling engineering teams to build and ship securely at scale.
Expert-level knowledge of web and mobile application security, including OWASP Top 10, API security, and mobile threat vectors (iOS and Android).
Deep hands-on experience with the full AppSec toolchain: SAST, DAST, IAST, SCA, secrets scanning, and runtime protection.
Strong command of cloud security architecture and controls, particularly in AWS environments.
Experience leading or heavily influencing the security architecture of distributed, microservices-based systems.
Experience in developing and implementing security solutions
Demonstrated ability to build strong cross-functional relationships and influence engineering culture without direct authority.
Exceptional communication skills — you can distill complex security risk into clear, actionable language for engineers, executives, and non-technical stakeholders alike.
Experience operating in regulated industries (e.g. financial services, fintech, healthcare).
Plus: Hands-on certifications such as OSCP, GWAPT, GPEN, CISSP, or equivalent — and/or public code/research. Share your GitHub or any public security work with us!
Plus: Experience building or scaling Product Security programs in high-growth startup environments.
Plus: Familiarity with security tools including Burp Suite, or Kali Linux.
More at Greenlight
