What we typically place
- Application security engineers (SAST / DAST, code review, threat modeling)
- Cloud security engineers (AWS / Azure posture, IAM)
- Detection / response engineers (SIEM tuning, incident playbooks)
- DevSecOps engineers embedded in CI/CD pipelines
- GRC-leaning security engineers for SOC2 / ISO compliance