Comfortable using browser developer/code inspection tools to inspect network and session traffic
Able to identify excessive information exposure between backend and frontend and explain the risk clearly
Able to translate security findings into actionable design requirements for the TRD
Solid understanding of session management principles and common pitfalls
Strong written communication skills, with the ability to document vulnerabilities, remediations, and technical requirements clearly for engineering and non-engineering audiences
Experience with Pulumi for infrastructure as code (nice to have)
Python experience (nice to have)
SQL skills (nice to have)
Active or eligible for security clearance (nice to have)