Posted on: 09/10/2026
Security Strategy & Roadmap:
- Owns the end-to-end security capability roadmap - covering vulnerability classes, detection methods, and verification techniques - and continuously reviews the competitive landscape across both commercial and open source security tools to keep the product's approach current.
- Selects and embeds the security testing frameworks and methodologies the product aligns to, tracking emerging attack classes and testing techniques and deciding when and how they should be incorporated into the product.
- Owns the product's overall security thesis and represents it externally to stakeholders, customers, and the wider community, while also setting the security requirements for the harness itself.
Detection Quality & Measurement:
- Owns detection quality across all specialist analysis lenses, ensuring consistency and reliability of results.
- Designs and curates the benchmark corpus - a structured set of seeded and labelled vulnerabilities used to validate detection performance.
- Owns the measurement methodology and safeguards the integrity of all published detection figures.
- Adjudicates whether findings are genuine, setting and maintaining the triage standard used across the team.
- Runs the standing evaluation program benchmarking competing tools and techniques against the corpus.
- Reviews external contributions and changes to the harness for potential security impact before they're merged.
Responsibilities :
- Takes detection specs from the security team and ships them as versioned lenses and rule packs, with a prompt registry and a way for customers to add their own.
- Implements chunking that cuts at function boundaries and packs by real token counts, using the tree-sitter call graph, to the senior engineer's design.
- Builds read-only retrieval over Confluence, ADRs and design docs that keeps the source permissions and cites what it used.
- Builds the reviewer feedback loop (labels stored against fingerprints, suppression, precision reporting) and the exports to GRC and ASPM tools.
Tech Stack :
- Model runtime & prompt engineering, diff-based scanning & fingerprinting, tree-sitter / code parsing, RAG / retrieval systems, Git/GitHub/GitLab automation, Jira/CI-CD integrations, credential management, SBOM/SCA/secrets scanning, KEV/EPSS feeds, observability & tracing, release engineering (containers, signed builds), GRC/ASPM tooling.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1677744