Product & Solution Security
Supporting and consulting our product lines in implementing required product and solution security practices Acting as the primary security point of contact for product teams during development, project execution, and service operations Reporting to the Product / Technical Lead and the Product & Solution Security Officer Providing specialized knowledge in secure architecture and design to help product teams create and operate secure applications and services Bringing a strong application-security perspective by understanding the application stack end to end, including frontend, backend, APIs, data, identity, infrastructure, and cloud layers Providing strong AWS security expertise to improve the security posture of cloud-native applications and services Supporting security assessments, threat modeling, risk analysis, and remediation planning throughout the software lifecycle
Cybersecurity Compliance & GRC
Supporting the implementation of Cybersecurity Compliance programs across multiple product teams Defining compliance-by-design approaches and integrating security and compliance controls directly into engineering workflows Supporting audits and certification programs including: ISO 2700, SOC2 and Internal security and compliance assessments
Shift-Left Security & DevSecOps
Driving the organization's Shift-Left Security strategy, enabling teams to identify and address security issues early in the development lifecycle Defining and implementing secure development practices, policies, standards, and guardrails Working closely with development teams to embed security controls into CI/CD pipelines Supporting implementation of: ake care of secure coding practices, software supply chain security, dependency and container security, Infrastructure as Code (IaC) security, Cloud Security Posture Management (CSPM), and vulnerability and risk management processes
AI Security & Agentic Development Lifecycle (AI-DLC)
Promoting self-service security capabilities and security automation across engineering teams Contributing to the design of the Building X Agentic AI Framework operating model Defining security requirements, governance standards, and control frameworks for AI-assisted development Conducting risk assessments, threat modeling, and security reviews for AI-enabled product development workflows Collaborate with platform, architecture, and development teams to embed Security-by-Design and Compliance-by-Design principles into the AI Development Lifecycle (AI-DLC) Support alignment with emerging AI security and governance standards (e.g., ISO 42001)