●Bachelor's degree in Computer Science, Cyber Security, or any related fields.
● At least 2 years of hands-on application security experience, ideally in product‐based or SaaS
companies working directly with engineering teams.● Good understanding of OWASP Top 10, API Security Top 10, and common authorization flawsincluding BOLA, BFLA, and privilege escalation.● Experience in manually testing web apps, APIs, and Android apps, manual code reviews(beyond just running tools).● Familiarity with OAuth2, OIDC, JWT, and typical misconfigurations in providers such as Keycloakand Firebase.● Experience integrating and tuning SAST/DAST (and optionally SCA/IAST) tools within CI/CDpipelines.● Exposure to cloud‐native security: Kubernetes, containers, service mesh (Istio mTLS andpolicies), and IAM concepts across at least one major cloud provider.● Experience with Cloudflare WAF, perimeter security scanning, and/or red‐team testing is aplus.● Familiarity with AI/LLM security risks (e.g., OWASP LLM Top 10).● Practical experience implementing guardrails, prompt validation, output filtering, or othersafety controls in production AI features, or assessing insecure use of third‐party AI APIs.● Ability to script/automate (e.g., Python, Bash) to streamline testing, data collection, andreporting.● Interest in or experience with building AI based security tools that improve coverage or reducemanual toil.