Tech Stack
AWSAzureCloudCyber SecurityGoGoogle Cloud PlatformJavaScriptJenkinsNode.jsPythonSDLCTerraform
About the role
- Lead and oversee client engagements, ensuring quality and client satisfaction.
- Engage hands-on in projects, from pipeline automation to vulnerability remediation.
- Conduct code-level security reviews and automate CI/CD workflows.
- Guide clients on secure SDLC, DevSecOps strategy, and CI/CD security practices.
- Perform threat modeling engagements utilizing the PASTA methodology.
- Mentor consultants and security champions; develop reusable playbooks and frameworks.
- Collaborate with the Technical Director on solution design and practice growth.
Requirements
- Strong software development background or proven scripting/automation experience with a security focus.
- Preference for former developers, security champions, or DevOps engineers who transitioned into security roles.
- 8+ years in application security, DevSecOps, or secure software development.
- Valued prior consulting, client-facing, or leadership experience.
- Proficiency in coding/scripting languages like Python, Go, or JavaScript/Node.js.
- Experience with CI/CD platforms such as GitHub Actions, GitLab CI, Jenkins, or Azure DevOps.
- Familiarity with security tools (SAST, DAST, SCA, etc.) and cloud security (AWS, Azure, GCP).
- Understanding vulnerabilities (OWASP Top 10, CWE) and practical remediation techniques.
- Knowledge of Infrastructure as Code (Terraform, Helm) and threat modeling, with PASTA experience a plus.
- Strong verbal and written communication; capable of engaging with developers, security teams, and executives.
- Problem-solving mindset and the ability to build trusted client relationships.