Lead secure-by-design initiatives for AWS-hosted applications. Combine AppSec expertise with hands-on development and cloud-native architecture to enable scalable security design patterns, proactive threat modeling, and secure SDLC practices for microservices, APIs, and serverless workloads.
Key Responsibilities :
- Design and implement application security frameworks for AWS-hosted services.
- Drive secure-by-design principles across the SDLC, including threat modeling and architecture reviews.
- Develop reusable security design patterns for microservices, APIs, containers, and serverless functions.
- Provide security guidance for MAST, SAST, DAST, and IaC scanning tools.
- Embed security controls into CI / CD pipelines using AWS CodePipeline, Terraform, and GitHub.
- Support incident response, forensic analysis, and post-incident reviews.
- Partner with engineering, DevOps, and cloud architecture teams to align security with business goals.
- Mentor developers on secure coding practices and architectural decisions.
- Participate in enterprise architecture forums and contribute to security governance.
Required Qualifications :
8+ years in Application Security, Software Engineering, or Security Architecture.3+ years of hands-on experience with AWS services (IAM, KMS, VPCs, CodePipeline, Terraform).Strong understanding of SSDLC, microservices architecture, and CI / CD workflows.Proficiency in Python, Java, or Go for secure coding and automation.Familiarity with OWASP Top 10, STRIDE, and CWE Top 25 threat models.Security certifications such as GDSA, GCAD, GWEB, or AWS Solutions Architect.Preferred Skills :
Experience with container security, serverless protection, and runtime controls.Knowledge of DevSecOps tooling, secrets management, and cloud-native security platforms.Strong documentation and playbook creation skills for audit, incident response, and architecture reviews.Exposure to zero-trust principles, API security, and secure infrastructure provisioning.(ref : hirist.tech)