- Develop and maintain an Engineering Platform Cybersecurity Maturity Framework for consistent security assessment across platforms
- Conduct security reviews of CICD pipelines, build systems, artifact repositories, runtime infrastructure, and developer tooling
- Perform threat modelling and security gap analysis to identify vulnerabilities and systemic risks
- Establish secure architecture patterns and engineering standards for enterprise engineering platforms
- Define and implement security baselines using Policy as Code and automated security controls
- Partner with platform owners to remediate security gaps related to access controls, configuration security, and artifact integrity
- Integrate vulnerability management, SBOM, software provenance, and code signing practices into engineering workflows
- Prioritize security gaps according to business risk, regulatory impact, and operational criticality
- Develop actionable security roadmaps that balance immediate remediation with long-term improvements
- Embed Secure by Design and DevSecOps practices into engineering platforms
- Advise platform owners, technology stakeholders, and security leadership on platform security risks
- Translate technical security risks into clear business impacts and remediation recommendations
- Track maturity scores and report security posture, roadmap progress, risks, and improvement outcomes
- Represent platform security initiatives in governance and risk forums
- Continuously improve security frameworks in response to emerging threats, technologies, and regulatory expectations
- Promote cybersecurity awareness, engineering excellence, and knowledge sharing across technology teams
Qualifications:
- Proven Cybersecurity experience (7-11 years) within large-scale regulated or similarly complex enterprise environments
- Deep technical knowledge of engineering platforms including CICD systems, build tools, artifact repositories, runtime environments, and developer tooling
- Strong DevSecOps experience including secure pipeline design and automated security control implementation
- Experience integrating security scanning tools into software delivery pipelines
- Strong knowledge of Service Mesh, Cryptography, Network Security, and Application Security
- Strong Vulnerability Management and Risk Management experience
- Experience conducting Threat Modelling, Platform Security Assessments, and Gap Analysis
- Experience developing Cybersecurity Maturity Models, Frameworks, and Security Roadmaps
- Knowledge of Policy as Code and automated security guardrails
- Understanding of SBOM, Software Provenance, Code Signing, and Software Supply Chain Security
- Strong stakeholder management skills with the ability to influence senior leadership
- Ability to drive security improvements across federated engineering and technology teams
- Excellent communication skills with the ability to translate technical risks into business impact
- Hands-on knowledge of AWS, Azure, GCP, and Kubernetes security is desirable
- Professional certifications such as CISSP, CISM, CCSK, or CCSP are advantageous
- Experience with regulatory engagement and global technology environments is preferred
Required Skills:
- Application Security (application security framework/ threat modelling/ Secure SDLC/ DevSecOps/Application Security Architecture Review)
- Python-Cybersecurity