• Coordinated deployment of dependency-scanning and static code analysis tools in CI/CD pipelines to flag vulnerable code and dependencies during development.
• Supervise annual external penetration tests with third-party vendors and in-house security teams.
• Enforce customers’ security SLAs between individual product teams with respect to specific security fixes.
• Triage findings in product code & dependencies, and plan implementation of necessary code-fixes & dependency upgrades.