Additional insights, experience or background in any of the following are also of great value: NIST, ISO 27001, Data Protection & Privacy, Threat Modeling (STRIDE), Static & Dynamic Security Analysis (SAST/DAST), Penetration Testing, Secure Software Architecture & Design, Developer Workflow Governance & Branch Protections, CI/CD Security Gates & Supply Chain Controls, API Security & Identity (OAuth2, OIDC), Microservices, Containers (Docker, Kubernetes), Cloud Security (AWS, Azure, GCP) & Architecture, Agile/DevOps Methodologies, Process Maturity, and related frameworks. The incumbent must have a collaborative, service-oriented mentality, a high sense of ownership, and a strong track record of driving security initiatives to completion They excel at communicating complex risk concepts to engineering teams, providing proactive status updates on architectural reviews and security remediation efforts, and managing production changes responsibly.