1. Strong hands on experience in Threat Modeling ,Secure Architecture Review and SAST 2. Deep understanding of application and API security concepts 3. Proficiency with SAST tools (e.g., Checkmarks, Fortify, Veracode, Semgrep) 4. Working knowledge of DAST