We are looking for someone who has 6-8 years in application and cloud security, with a track record at principal or senior-lead level, still hands-on
Threat modeling as a working practice (STRIDE, attack trees, abuse cases) across microservices, APIs, CI/CD and IAM
Detection engineering on AWS: GuardDuty, Security Hub, CloudTrail, custom detections
you know the difference between an alert and a signal
Prevention built into delivery: IaC guardrails (Terraform / CloudFormation), SAST/DAST wired into pipelines, container and Kubernetes security
The ability to walk an engineering team through why, not just what
Desired Skills
vulnerability management programs (Wiz, Qualys), CDN edge security (CloudFront, Cloudflare, Akamai WAF, bot management, cache poisoning), AWS Security Specialty.