You will be responsible for:
- Designing secure systems and conducting threat modeling for new and existing features.
- Identifying and mitigating security risks in architecture, applications, and infrastructure.
- Performing security assessments, audits, and ensuring compliance with standards like ISO27001, PCI-DSS, and GDPR.
- Integrating security best practices into CI/CD pipelines and development workflows.
- Improving Secure Development Lifecycle (SDLC) practices within R&D and Product units.
- Providing guidance and mentorship to development teams on secure coding and security principles.
- Collaborating with engineering, product, and DevOps teams to embed security into all aspects of development.
- Reviewing tools and processes to detect security threats and enhance security posture.
- Communicating security risks and recommendations to technical and non-technical stakeholders.
You should apply if you have:
- 8+ years of experience in Information Security.
- Strong expertise in security architecture, threat modeling, and vulnerability assessments.
- Hands-on experience securing web/mobile applications, cloud environments (AWS, GCP, Azure), and networks.
- Deep knowledge of authentication, encryption, authorization, and security frameworks like OWASP and NIST.
- Experience in DevSecOps, SSDLC, and secure software development.
- Excellent communication and collaboration skills.
- Proven leadership and mentorship
*We operate in a flexible hybrid work model.
for more details.