Overview
In this role you will own the secure backend and cloud platform architecture for Nothing, shaping security standards and tooling. You’ll secure CI/CD pipelines, manage vulnerabilities end-to-end, and lead threat modelling across authentication, data protection, and input handling. You will collaborate with mobile, OS and legal teams to meet global regulatory requirements and innovate with AI-assisted security. This is a chance to influence security at scale in a product-centric, design-driven company.
Responsibilities
- Own security lifecycle and secure architecture for backend services and cloud platforms across CI/CD pipelines
- Define secure development standards and integrate SAST, DAST and SBOM tooling
- Lead vulnerability management from discovery to remediation with engineering teams
- Design security testing approaches including penetration testing and fuzzing and develop reusable tools
- Implement network, server-side and data protection measures (API security, WAF, encryption in transit/rest)
- Collaborate with mobile, OS and desktop teams on client-side security strategies
- Work with privacy and legal teams to address global regulatory needs including emergent technologies like AI
- Lead threat modelling for authentication, data protection and input handling; use AI/LLMs to simulate attacks and strengthen defenses
Key requirements
- 6+ years in application security with architecture design for commercial products and production posture
- Deep threat modelling expertise with ability to define methodologies
- Hands-on cloud security across AWS, GCP, Azure and other hyperscalers
- Experience securing backend services at scale with complex architectures
- Proficient in secure SDLC: SAST, DAST, SBOM and prioritising findings
- Experience applying AI/LLMs to security: threat simulation and countermeasure development
- Solid cryptography/identity fundamentals: TLS, OAuth 2.0, SSO and token management
- Production-quality coding in Python, Go, Java and C++
- Ability to own a domain end to end and navigate ambiguity with diverse stakeholders
- strong problem-solving and decision-making
- ability to cut through ambiguity
- cross-functional collaboration
- threat modelling
- cloud security (AWS, GCP, Azure)
- SAST
…
