The role
Zero-trust architecture, identity, and hardening work on systems that are already in production and cannot be taken offline to be fixed.
What the work looks like
Threat modelling a client's platform, then doing the work rather than writing a report about it: identity and entitlement design, secrets and key management, supply-chain controls in the build pipeline, and closing the findings you raised yourself.
What we expect
Strong applied background in IAM and cloud security, comfort reading and writing application code rather than only reviewing it, and experience with at least one regulated environment — PCI, HIPAA, or an equivalent. You should be able to explain a risk to a CTO in one paragraph and to an engineer in one diff.
What we do not do
We do not sell audits. Every finding we raise, we are expected to help fix, which means the work is judged on whether the system got safer rather than on the length of the document.
Apply for this role
An engineer reads every application. Expect a reply either way.