🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Role & responsibilities - Act as a hands-on Cybersecurity SME for products, applications, cloud platforms and software services. - Lead Threat Modeling, Threat & Risk Assessment (TRA) and cybersecurity risk assessments. - Perform security architecture and design reviews and provide security-by-design recommendations. - Drive Secure SDLC / SSDLC and DevSecOps practices across software development teams. - Guide implementation and governance of SAST, DAST, SCA, SBOM and security testing tools. - Provide technical guidance on AWS/Azure Cloud Security and cloud-native application security. - Assess and guide remediation of vulnerabilities across applications, cloud infrastructure and containers. - Provide hands-on guidance on Docker and Kubernetes security, including RBAC, secrets, network policies, security contexts and container image security. - Coordinate penetration testing and security assessments and track remediation to closure. - Develop cybersecurity standards, secure baselines, procedures and technical guidelines. - Support compliance with OWASP, NIST, ISO 27001/27002 and applicable healthcare/medical-device cybersecurity standards. - Work closely with Architecture, Engineering, DevOps, QA and Product teams to resolve security issues. - Provide technical mentoring and act as a cybersecurity authority for distributed engineering teams. Preferred candidate profile - 8+ years of experience in Cybersecurity, Application Security, Product Security, Cloud Security, Software Engineering or related areas. - 5+ years of hands-on experience in Product Security, Application Security or Security Architecture. - Strong hands-on experience in Threat Modeling, TRA, Security Architecture and Secure SDLC. - Practical experience securing AWS and/or Azure cloud environments. - Robust hands-on understanding of Docker, Containers and Kubernetes Security. - Experience with SAST, DAST, SCA, SBOM and vulnerability management. - Strong knowledge of OWASP Top 10, NIST and ISO 27001/27002. - Demonstrated ability to independently analyze security problems, recommend controls and drive technical remediation. - Strong Individual Contributor / hands-on technical ownership capability; this is not primarily a people-management role. - Healthcare, medical-device or other regulated product cybersecurity experience is preferred. - Certifications such as CISSP, CSSLP, CCSP, CEH, Azure Security Engineer or CKS are an advantage. - Candidates with primarily SOC, GRC, IAM/PAM, vulnerability-management or managerial experience without strong Product/Application, Cloud and Container Security exposure may not be suitable. .