Job Description
Job Summary:
This role involves ensuring the security of cloud-based networking and security products through rigorous assessments and secure design practices. You will collaborate with engineering teams to embed security throughout the software development lifecycle and leverage advanced tooling to identify and resolve vulnerabilities. Your work will directly contribute to protecting critical infrastructure and customer data.
Key Responsibilities:
- Perform application and product security assessments for SaaS and on-prem DNS/DHCP solutions across microservices and containerized architectures
- Drive threat modelling for new and existing features, documenting abuse cases and prioritized mitigations
- Plan, execute, and analyze penetration tests, leveraging standard frameworks and AI-assisted tooling to accelerate test design and reporting
- Evaluate and tune SAST, DAST, SCA, and container security tools (e.g., Coverity, CodeQL, SonarQube, Contrast) to reduce noise and improve signal quality
- Partner with development teams to review designs and code changes, define secure coding patterns, and integrate security stories into agile backlogs
- Define and validate security controls for authentication, authorization, encryption, secrets management, and secure network communication
- Collaborate with cloud platform teams (AWS, GCP, Azure) to assess and harden Kubernetes, containers, and CI/CD pipelines, including policy-as-code
- Apply AI and automation tooling (e.g., code analysis assistants, LLM-assisted triage) to correlate findings, reduce false positives, and generate remediation guidance responsibly
- Lead security root-cause reviews for product issues and translate lessons learned into patterns, guardrails, and developer education
- Deliver targeted secure coding, OWASP Top 10/API, and threat modelling training for engineering and DevOps teams
Must-Have Skills:
- 5+ years of Application Security or Product Security experience
- Vulnerability Assessment (VA) & Penetration Testing (PT)
- Threat modelling (STRIDE preferred)
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Manual Web Application Penetration Testing
- Burp Suite
- OWASP ZAP (ZAP Proxy)
- Python OR Go OR Shell Scripting
- Security Automation
- Cloud Security AWS OR Azure OR GCP
- ISO 27001 OR NIST
- Strong communication and stakeholder management skills
Industry Experience:
Experience in securing cloud-native environments and familiar with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPR is preferred
ABOUT AKRAYA
Akraya is an award-winning IT staffing firm consistently recognized for our commitment to excellence and a thriving work environment. Most recently, we were recognized Stevie Employer of the Year 2025, SIA Best Staffing Firm to work for 2025, Inc 5000 Best Workspaces in US (2025 & 2024) and Glassdoor's Best Places to Work (2023 & 2022)!
Industry Leaders in Tech Staffing
As Talent solutions provider for Fortune 100 Organizations, Akraya's industry recognitions solidify our leadership position in the IT staffing space. We don't just connect you with great jobs, we connect you with a workplace that inspires!
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
