About The Role
You work alongside the development teams rather than auditing them from outside. That means reviewing architecture proposals before they are built, reviewing code before it ships, and maintaining the automated security scanning in the build pipeline. A large part of the role is turning recurring problems into checks or libraries so the same class of bug stops reaching production.
What you will do
- Review code and designs for security consequences
- Own the scanning pipeline and keep its noise down
- Turn each recurring finding into a guardrail
What they ask for
- Reads and writes production code in at least one language
- Knows the common vulnerability classes by mechanism, not by name
- Has shipped a fix somebody else had to maintain
Nice to have
- Threat modelling
- Semgrep or CodeQL rules
- Open source contributions