• Own application and cloud infrastructure security across Cloudflare, GCP, and Vercel, including our edge workers, data stores, and the routing path that handles every request.
• Stand up vulnerability scanning (across our codebase and cloud infrastructure), triage findings, and drive remediation in partnership with engineering teams.
• Investigating, triaging and remediating responsible disclosure vulnerabilities that come through our bug bounty programs.
• Lead threat modeling for new product surfaces - the API, SDKs, dashboards, and agentic workloads - and make sure security is part of the design from the start.
• Build out incident response and disaster recovery, including runbooks, tabletop exercises, and on-call expectations as the company scales.
• Partner with our IT and compliance lead on frameworks such as SOC 2, HIPAA, GDPR, CCPA/CPRA, ISO 27001, ISO 277001, and ISO 42001 contributing the engineering pieces required to support those programs.