Minimum 3 years of cybersecurity engineering experience
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, or a related field preferred; equivalent work experience and relevant certifications may be considered in lieu of a degree
Hands-on application security experience with SAST, DAST, SCA, secure code review, API security, WAF tuning, threat modeling, CI/CD security, and secrets management using tools such as Doppler, Semgrep, Snyk, Burp Suite, OWASP ZAP, Cloudflare, HashiCorp Vault, or equivalent
Proficient in at least one programming or scripting language with the ability to read, write, and exploit code in a security context; Python, JavaScript, PHP, Golang, or Rust preferred
Working knowledge of AI security risks and controls, including prompt injection, indirect prompt injection, model abuse, data leakage, agentic workflow vulnerabilities, OWASP LLM Top 10, MITRE ATLAS, and emerging AI security tooling
Practical cloud and infrastructure security experience across DigitalOcean, AWS, GCP, Kubernetes, IAM, CSPM, IaC scanning, container security, zero-trust/SASE architectures, and security tooling such as EDR, SIEM, CASB, SWG, DLP, IDS/IPS, and PAM
Strong understanding of security frameworks and control models, including NIST CSF, CIS Controls, PCI DSS, Cyber Defense Matrix, ISO 27001, OWASP, and MITRE ATT&CK.
Experience securing applications, APIs, cloud platforms, CI/CD pipelines, Kubernetes environments, data platforms, and modern engineering ecosystems using technologies such as JavaScript, PHP, PostgreSQL, Kafka, NeonDB, GitLab, Python, Snowflake, dbt, Fivetran, Databricks, Tableau, Informatica, Kestra, or related technologies
Authorized to work in the United States without the need for current or future sponsorship