01Responsibilities
Provide deep technical hands-on Experience in security engineering, with a focus on design, strategy and implementation of secure solutions.Have strong understanding of security policies, standards, and reference architecture, and expertise in threat modelling, threat detection, control mapping, vulnerability analysis and control engineering risk identification.Are experienced in designing and building reusable security patterns and or solutions.Essential Skills:
12+ years of experience in Security Engineering with strong expertise in Secure Software Development.Proven experience with Secure-by-Design, DevSecOps, and Security Automation practices (SAST, DAST, IAST).Skilled in designing and implementing enterprise Security Guidelines, Standards, and Practices.Hands-on experience in Secure Design Reviews, Threat Modelling (STRIDE / STRIDE-LM), Secure Code Reviews, and Risk Management.Experience authoring and reviewing security assessments, Security Zone Models, Data Flow Diagrams, Control Objectives, and Residual Risk analysis.Strong understanding of Security Reference Architectures, Security Patterns, and Security Zone Models applied to solution design and reviews.Experience assessing solutions using a Technology Criticality / Risk Rating framework to right-size security controls.Ability to identify control gaps, raise and manage risks, and align solutions to enterprise security policies, standards.Hands-on experience securing Docker, Containers, and Kubernetes environments.Experience with Cloud Security (AWS/Azure), including Cloud Reference Architectures, Workload Placement Patterns, and Native Cloud Service Security Assessments.Experience partnering with Penetration Testing teams to explore and map exploit and attack paths.Familiarity with AI systems (GenAI, LLMs, RAG, AI Agents) and their security considerations, including AI threat modelling and secure AI design.Experience leveraging AI-assisted security tooling (e.g .