← Back to jobs
San Francisco, CA, USA
No related jobs found
DAY-TO-DAY RESPONSIBILITIES
REQUIRED SKILLS
1. Threat Modeling
• Understanding of architectural trust boundaries, attack surfaces, and data flows.
• Familiarity with structured threat modeling frameworks (e.g., STRIDE, PASTA).
2. Triage & Policy Management
• Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10).
• Ability to interpret vulnerability scoring matrices and map findings to strict remediation SLAs.
3. Vulnerability Reproduction
• Proficiency in reading and writing code in at least two core languages (C++, Go, Java, Python).
• Ability to set up local test harnesses, mock dependencies, and build minimal PoCs.
4. Automated / Agentic Fixer QA
• High attention to detail during code reviews (spotting hallucinations, regressions, off-by-one errors).
• Understanding of secure coding standards (input validation, boundary checking, safe memory access).
NICE-TO-HAVES
• Experience conducting threat model reviews for large distributed / microservice systems.
• Ability to translate abstract system designs into concrete threat scenarios.
• Experience managing vulnerability queues and reviewing compliance exception requests.
• Familiarity with automated static/dynamic scanning tools.
• Practical experience with fuzz testing, unit test frameworks, and sandbox execution.
• Debugging complex runtime or logic errors across service boundaries.
• Experience debugging and prompt-tuning automated code generation tools.
Bachelor's degree
No related jobs found
← Back to jobs