Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, Engineering, or related field.
10+ years of experience in application security, secure software engineering, DevSecOps, security architecture, or related cybersecurity roles.
Deep expertise in secure code review, vulnerability detection, threat modeling, exploitability analysis, and secure SDLC practices.
Experience with performing vulnerability and penetration test readouts/walkthroughs with stakeholders.
Hands-on experience with SAST, SCA, DAST, secrets scanning, API security testing, container security, infrastructure-as-code scanning, and developer workflow integrations.
Experience integrating security capabilities into SDLC pipeline tooling: Jenkins, GitHub Actions, GitHub Enterprise, Atlassian, developer portals, source-control workflows, and DevSecOps toolchains.
Practical experience using LLMs or AI models for code review, software engineering, vulnerability research, security analysis, or developer productivity use cases.
Understanding of prompt engineering and optimization, RAG, model evaluation, AI guardrails, human-in-the-loop review, prompt/model versioning, and vendor/open-source model trade-offs.
Experience designing or maintaining evaluation harnesses, benchmark suites, regression tests, validation pipelines, and test orchestration workflows.
Strong understanding of concepts: OWASP, CWE, CVSS, NIST SSDF, AI security risks, regulated source-code handling, auditability, and vendor/model governance.