- DIdentify, triage, and provide remediation guidance for application vulnerabilities.
- Select, implement, design, or build tools to thwart attacks of all shapes and sizes.
- Improve developer tooling and adoption to build a more robust SSDLC.
- Practice a #OneTeam attitude to help other Toast teams make informed, security-conscious. decisions when building recent software.
- Support and expand the Security Champions program, providing edge security guidance and training.
- Assist incident response teams with application security expertise and tools.
- Think like an attacker to identify weaknesses in application architecture.
In addition:
- Support Cloud and Network Infrastructure Engineerings implementation of edge security solutions.
- Influence the implementation and rule maintenance of our WAF strategy and other edge security solutions.
- Advise on WAF rules and policies to protect against common and emerging threats.
- Conduct regular assessments of our edge security posture and recommend improvements.
- Provide expertise on Content Delivery Networks (CDNs) and their security features.
Do you have the right
ingredients*
(Requirements)
- 5+ years of experience in application security
- Strong knowledge of common web application vulnerabilities and edge-based attack vectors.
- Proficiency in analyzing web traffic patterns and identifying anomalies.
- Knowledge of compliance standards relevant to the financial industry (e.g., PCI DSS, SOC 2).
- Excellent problem-solving skills and ability to think creatively about edge security challenges.
- Strong communication skills, with the ability to explain complex edge security concepts to both technical and non-technical audiences.
- Strong understanding of cloud application architecture and common weaknesses.
Special Sauce(Nonessential Skills/Nice to Haves)
Experience with:
- Understanding of WAF configuration, tuning, and optimization.
- Popular WAF solutions (e.g., AWS WAF, Cloudflare, Akamai, ModSecurity).
- Familiarity with CDN technologies and their security features.
- Cloud and container security technologies and SSDLC tooling (e.g. SAST/DAST/SCA)
- Infrastructure-as-code (IaC) technologies like Terraform to manage cloud security services
- Securing financial technologies