Information security project management
Security assessment and risk analysis
Audit and compliance management
Assist with the development and implementation of security standards, benchmarks, and baselines.
Conduct security architecture design reviews on all projects
Plan and design robust security architecture for new projects.
Recommend modifications on security architecture for existing projects.
API security
Open source third party libraries security assessment and vulnerability management
Configure web application firewalls, distributed denial of service (DDoS) mitigation, bot mitigation, zero-day attacks mitigation
Software security training and recommendations to the developers
Design, implementation, and modification of existing open-source and internal libraries for security matters
Create scripts that allow scanning code repositories for committed, sensitive information such as passwords, API keys, and many others.
Create Terraform scripts to bootstrap AWS accounts with security infrastructure and other necessary services
Create configurations and deployments scripts for Docker, Kubernetes with scripts, or Terraform scripts
Modify codebase to avert zero-day vulnerabilities
Software security (SAST, DAST), security “shift left” and other security products evaluation, recommendation and implementation, and coordination with security vendors
AWS IAM accounts provisioning, user and roles policies implementation
Implement custom scripts for source code AST security analysis
Mentor, help, and coordinate other teams for security matters (Automation QA, DevOps, TechOps, Developers, Software Architects)