Source description
About the role
Strong communicator with the ability to lead technical architecture discussions and drive technical decisions, while effectively communicating with non-technical audiences. Deep familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, IAM, and others (knowledge of GCP and/or Azure is a plus). Proven ability to establish credibility and build trust with engineers and operational staff; confident yet humble. Hands-on experience with microservices and associated orchestration tools, such as ECS, EKS, Nomad, and Istio, with an understanding of the operational and security implications of these technologies. Excellent understanding of both human and non-human identity management, as well as common enterprise and consumer authentication standards and use cases. Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools such as Doppler and HashiCorp Vault. Passionate about learning new technologies; while you're not expected to know everything, you should demonstrate the ability and willingness to learn when necessary. Prior experience developing security services for products or enterprise platforms, ideally using Python, Node.js , TypeScript, or .NET. Proficiency in writing automation scripts in more than one language, with prior experience automating security processes in cloud or SaaS environments. Strong understanding of cryptography and key management use cases. Experience overseeing vulnerability and threat management at the infrastructure, platform, and application levels. Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement; prior oversight of bug bounty platforms or managed penetration testing services is a plus. Ability to balance a high-level view of security strategy with attention to detail, ensuring thoroughness in execution. Expertise with event management and Security Event Management (SEM) solutions, including data modeling for building event detection and alerting capabilities. Practical experience investigating incidents and performing threat hunting, with familiarity using common incident response tools and processes. Prior expertise with workforce security solutions, including zero-trust models and enterprise browsers.
More at TechQuarter
