-
8+ years of cybersecurity experience, with deep hands-on expertise in Application Security, product security, penetration testing, or security engineering.
-
Experience conducting threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.
-
1-3 years of AI Security experience, with AI/ML security, adversarial testing of AI systems, or applied AI research with a security focus.
-
Strong knowledge of web, mobile, API, and cloud-native security, including OWASP guidance and business-logic risks.
-
Strong understanding of authentication and authorization technologies, including OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.
-
Hands-on DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.
-
Practical knowledge of Docker, Kubernetes, microservices, and cloud security.
-
Demonstrated experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.
-
Understanding of AI threats such as prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks.
-
Familiarity with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices.
-
Programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language.
-
Strong written and verbal communication skills, with the ability to influence technical and non-technical stakeholders.