Establish Boulevard’s dedicated security engineering program, define metrics, processes, and tooling that embed security into our SDLC and engineering culture. Integrate SAST, DAST, and dependency scanning into our CI/CD pipelines to surface issues early, enabling engineers to remediate vulnerabilities before production. Develop measurable success criteria for our security posture. Establish a vulnerability management program which tracks and reports on vulnerability management, CVE resolution rates, and SDLC compliance. Build a deep understanding of Boulevard’s PCI and HIPAA environments, sensitive data flows, and controls. Partner with software, platform, and infrastructure teams to integrate security best practices directly into their workflows making it easy to build secure systems.
Continuously evaluate Boulevard’s security posture against defined metrics and identify opportunities to reduce risk and improve developer experience. Lead and help define a comprehensive security strategy, executing on the tactics to establish a world-class approach to security. Shield from threats, hunt for vulnerabilities, advocate for security awareness, react to incidents when they occur, and assist in compliance activities. Collaborate with compliance and operations teams to automate evidence gathering and strengthen controls across PCI, SOC 2, and HIPAA frameworks. As the company grows, evolve this role into a Security Engineering Lead position building and mentoring a team to scale Boulevard’s security capabilities.